
Amazon Bedrock AgentCore Gateway now supports inbound authorization using OAuth 2.0 authorization code flow, enabling secure identity-verified access between agentic coding assistants (such as Kiro IDE) and Model Context Protocol (MCP) servers.
The authentication mechanism validates each AI assistant request with an identity token from an organization's identity provider (IdP) before allowing access to tools. The Gateway acts as an OAuth resource server, detecting unauthorized requests and directing clients to authenticate via their IdP using PKCE challenge protection.
The guide provides step-by-step configuration for three components: registering an OpenID Connect application with an IdP, enabling JWT-based inbound authorization on AgentCore Gateway, and connecting MCP clients like Kiro IDE to complete the end-to-end OAuth flow.
Ask the AI about this article →
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.