Products

Amazon Bedrock AgentCore

5 min readintermediateUpdated 28 Sept 2026
1 · In one line

A set of AWS services, called Amazon Bedrock AgentCore, for running AI agents in the cloud, with hosting, memory, sign-in, tool access and monitoring.

1 · What it is

AWS describes AgentCore as a platform for building, deploying and running agents securely at scale. It works with any framework and any foundation model. A framework is a code kit for building agents. A foundation model is the large AI model doing the thinking.

AgentCore is not one product but a toolbox. The pieces are modular, so a team can use one on its own or several together. This page looks at five of them.

Runtime is where the agent lives. Runtime is a serverless hosting service for agents and tools. Serverless means AWS manages the servers for you. Runtime works with many models, including models on Amazon Bedrock and models from Anthropic, Google and OpenAI. Runtime lets agents talk to tools and to other agents over MCP or A2A. Agents can run on microVMs, which are tiny, walled-off virtual computers. Sessions there start on demand, and you pay for the resources the agent actually uses. A long job can run on Instances instead, which support sessions of up to 14 days.

Memory is the agent’s notebook. Short-term memory keeps the turns of one session, so a follow-up question makes sense. If you ask about the weather in Seattle and then say “what about tomorrow?”, the agent knows you still mean Seattle. Long-term memory pulls out useful facts, like a customer who always wants a window seat, and keeps them for next time.

Identity is the key-card desk. Identity is built for agents and automated workloads, and handles identities and stored credentials. It lets people log in with the company account they already use, so nobody has to create a new one. Runtime can also sign in to outside services such as Slack or GitHub, using OAuth or API keys.

Gateway is the switchboard. Gateway gives agents one secure entry point to tools, other agents and models. It wraps a company’s existing web APIs and AWS Lambda functions so they look like MCP tools. An API is a menu of requests one program can send another. Lambda functions are small pieces of code that run on demand. Gateway lets an agent search its tools to find the most fitting one.

Observability is the logbook. Observability tracks numbers like how many sessions ran, how slow replies were, how many tokens were used and how often errors happened. The data uses the OpenTelemetry format, so it can feed other monitoring tools too.

Picture a made-up travel-booking agent. Long-term memory recalls that the traveller likes window seats, a tool behind Gateway looks up flights, and Observability records the steps. AgentCore runs and connects the agent. The answers still come from the model and the code you wrote.

2 · Why it exists

An agent that works on a laptop still needs a lot more before real users can rely on it.

Agents forgetWithout memory, an agent treats each conversation as brand new and knows nothing about earlier ones.
Tools need permissionAn agent that acts for a person has to prove who it is and use that person's access, not a shared master key.
Hard to debugTeams need a record of every step, every tool call and the point where things broke.
3 · How it works

Follow one user request through an agent hosted on AgentCore.

How one request moves through Amazon Bedrock AgentCore A user request is checked by Identity against the company sign-in provider. Runtime, the highlighted step, runs the agent in its own microVM for that session. The agent reads and writes Memory and calls tools through Gateway, which turns APIs and Lambda functions into MCP tools. The reply returns to the user. Observability records traces and metrics from each step in Amazon CloudWatch. ONE USER REQUEST TO AN AGENT HOSTED ON AGENTCORE User request Identity Runtime Reply Memory Gateway Tools Observability book me a flight, window seat who is calling? Okta · Cognito agent code runs in its own microVM answer returned to the user short-term: this chat long-term: prefs APIs, Lambda → MCP adds each tool's login flight search API internal company API traces, latency, tokens and errors from every step, stored in Amazon CloudWatch
Runtime is the centre: each user session gets its own isolated space, and the other services plug into it.
  1. 1 · sign-inIdentity checks who is calling, using a sign-in provider the company already has, such as Okta or Amazon Cognito.
  2. 2 · runRuntime starts the agent in a dedicated microVM, a small isolated virtual machine, just for that user session.
  3. 3 · recallThe agent reads Memory for recent turns and for saved facts, such as a preference from an earlier chat.
  4. 4 · actThe agent calls tools through Gateway, which handles the login each tool needs.
  5. 5 · watchObservability records each step as traces and metrics in Amazon CloudWatch.

You bring the agent code; AgentCore runs and connects it.

4 · Where it's used
WhoWhat they askWhat it works with
Customer support team“Can our support agent remember a customer's past issues when they come back next week?”Long-term memory stored across sessions
Platform engineer“How do we let our agent call internal APIs without writing a custom connector for each one?”APIs and Lambda functions exposed as MCP tools through Gateway
Security team“Can one user's session ever see another user's data?”Session isolation in Runtime
Developer on call“Why did the agent give a slow answer at 3 a.m.?”Traces, latency and error metrics in CloudWatch
5 · What it solves, and what it doesn't
solves
  • It hosts agents built with many frameworks, such as LangGraph, CrewAI and Strands Agents.
  • It keeps each user session in its own microVM and cleans it up afterwards.
  • It turns existing APIs and Lambda functions into tools that agents can call over MCP.
  • It stores short-term and long-term memory so agents can pick up where they left off.
doesn't solve
  • Runtime hosts agent code you bring; it does not write that code for you.
  • Hosting an agent does not grade it; quality is measured by a separate service, AgentCore Evaluations.
  • Its monitoring data is stored in Amazon CloudWatch, another AWS service.
  • A microVM session lasts at most 8 hours; longer jobs need Instances.
6 · Go deeper

Sources used

This explainer is written in original language. The links below support its factual claims.

  1. docsOverview - Amazon Bedrock AgentCore, Amazon Web Services · read 28 Sept 2026
  2. docsHost agent or tools with Amazon Bedrock AgentCore Runtime, Amazon Web Services · read 28 Sept 2026
  3. docsAdd memory to your Amazon Bedrock AgentCore agent, Amazon Web Services · read 28 Sept 2026
  4. docsProvide identity and credential management for agent applications with Amazon Bedrock AgentCore Identity, Amazon Web Services · read 28 Sept 2026
  5. docsAmazon Bedrock AgentCore Gateway: A secure AI gateway for agents, tools, and models, Amazon Web Services · read 28 Sept 2026
  6. docsObserve your agent applications on Amazon Bedrock AgentCore Observability, Amazon Web Services · read 28 Sept 2026