AIToday
Amazon AI BlogPublished: Jun 2, 2026, 13:00 JST1 min read

Amazon Bedrock AgentCore Gateway adds OAuth code flow authentication for secure AI agent access to MCP servers

Amazon Bedrock AgentCore Gateway adds OAuth code flow authentication for secure AI agent access to MCP servers

3 Key Points

  1. Amazon Bedrock AgentCore Gateway now supports inbound authorization using OAuth 2.0 authorization code flow, enabling secure identity-verified access between agentic coding assistants (such as Kiro IDE) and Model Context Protocol (MCP) servers.

  2. The authentication mechanism validates each AI assistant request with an identity token from an organization's identity provider (IdP) before allowing access to tools. The Gateway acts as an OAuth resource server, detecting unauthorized requests and directing clients to authenticate via their IdP using PKCE challenge protection.

  3. The guide provides step-by-step configuration for three components: registering an OpenID Connect application with an IdP, enabling JWT-based inbound authorization on AgentCore Gateway, and connecting MCP clients like Kiro IDE to complete the end-to-end OAuth flow.

Ask the AI about this article →

Amazon AI BlogRead Original Article

Get AI news like this every morning

For example, today's edition would include:

  • Aranya raises $11M to turn bare-metal servers into AI clusters in 48 hoursSiliconANGLE AI · 2h ago
  • CBTS launches Forge Agents for custom AI agentsSiliconANGLE AI · 2h ago
  • Phonely launches Alma, voice AI trained on 10M callsSiliconANGLE AI · 2h ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Next articleBroadcom announces Wi-Fi 8, 50G PON, and AI accelerator platforms in late May 2026, linking its AI data center business with edge AI networks.