
What happened
Amazon Bedrock AgentCore Identity launched a Consent portal that handles browser redirects and session binding, storing per-user tokens in its vault.
Why it matters
Previously, customers using the 3LO flow had to build and host their own session binding infrastructure, including a public HTTPS callback and browser session management.
What to watch
The test is whether the managed portal reduces the setup burden enough for administrators to adopt it. One portal is allowed per gateway, and the gateway can't be changed after creation.
WHO IT HITSEnterprise IT administrators who configure OAuth for AI coding assistants, and developers who use IDE and MCP clients such as Kiro, Claude Code, Cursor, and Visual Studio Code, will need to share or use a single portal URL per gateway.
Ask the AI about this article →
Summaries like this, in your inbox every morning.
The Consent portal arrives as enterprises increasingly deploy AI agents that need to act on a user's behalf across services like GitHub and Slack. Previously, the three-legged OAuth flow required customers to build and host their own session binding infrastructure — presenting authorization URLs, hosting public HTTPS callbacks, managing browser sessions, and calling CompleteResourceTokenAuth. That was a significant engineering lift for what is essentially plumbing.
Now, administrators configure the corporate identity provider, gateway targets, execution role, and outbound providers, then share a single portal URL. End users sign in, review available services, and grant consent per provider. The portal handles redirects and session binding, while AgentCore Identity stores tokens in its vault, and subsequent tool calls use the stored token without repeated prompts.
The outcome hinges on whether the managed portal sufficiently reduces that setup burden for administrators. One portal is allowed per gateway, and the gateway can't be changed after creation, so choosing a clear, recognizable gateway name matters because it's visible to end users. Administrators should also watch for refresh token behavior: if no valid refresh token is available, users must return to reauthorize. Configuring providers to issue refresh tokens — for example, enabling user-to-server token expiration for GitHub or token rotation for Slack — is likely to smooth the ongoing experience.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Nuance Labs, a Seattle startup led by ex-Apple researcher Fangchang Ma, closed a $50 million Series A led by L…
Microsoft MVP Kazuaki Asada set Microsoft 365 Copilot to "Allow edits" mode and asked it in plain language to…

Anthropic CEO Dario Amodei said the industry must slow the pace of improving AI models, arguing risk preventio…

Chairman Yoshihisa Kainuma said Minebea Mitsumi has no current plans for deals, choosing instead to focus on b…

AI is gaining ground in weather forecasting, with meteorological agencies and private companies worldwide deve…

OpenAI reportedly agreed to buy smartphone camera software startup Glass Imaging for more than $300 million, p…