Responses API — AgentCore Gateway server-side tool execution
Allows supported Amazon Bedrock Responses API models to discover tools exposed through an IAM-authenticated Amazon Bedrock AgentCore Gateway, select tools during inference, and have Amazon Bedrock execute selected tool calls server-side and return the results to model context without requiring client-side tool orchestration.
Recorded characteristics
- Function
- Amazon Bedrock invokes model-selected AgentCore Gateway tools server-side. AgentCore Gateway then authorises and routes the invocation to the configured target using its configured execution authority. A Responses API request names an AgentCore Gateway ARN as an MCP tool connector (type mcp, server_label, connector_id = gateway ARN). Amazon Bedrock discovers the tools available from the gateway, presents them to the model during inference, executes tool calls server-side when the model selects them and injects the results back into model context, within a single API call. AWS states multiple tool calls within a single conversation turn are supported and results are streamed to the client. Targets can include Lambda, API Gateway, OpenAPI, Smithy and MCP servers. The effect of an invocation depends on the configured tool: some tools retrieve information, others may cause changes.
- Data access
- Tools and data reachable are those exposed by the configured AgentCore Gateway targets, under the gateway's outbound credentials. Observability: Gateway publishes invocation and usage metrics, vended logs (including request_id, trace_id, span_id) and spans to Amazon CloudWatch for MCP operations performed on the gateway.
- Actions
- Can take actions
- External actions
- Yes
- Human confirmation
- Not established
- Permission basis
- Mixed
- Administrative control
- Selection authority vs execution authority: the model selects the tool; Amazon Bedrock performs the invocation. The Bedrock execution role must hold bedrock-agentcore:InvokeGateway on the gateway (Bedrock only supports gateways with IAM authentication). The gateway can independently allow or deny the call: Policy in AgentCore intercepts traffic through gateways and evaluates each request against Cedar policies (default deny), with IAM-authenticated callers represented as AgentCore::IamEntity principals. Gateway-to-target calls use configured outbound authorisation: gateway service role with SigV4, OAuth (client credentials or authorisation code/user-delegated), API keys, or other documented target mechanisms. Responses connector approval: AWS requires require_approval = "never" for the AgentCore Gateway connector in this documented Responses API integration. This controls the Responses connector's approval behaviour; AgentCore Gateway authorisation and downstream target controls remain separate.
- Default state
- Disabled
- Availability
- Generally available since 24 Feb 2026 in AWS Regions where both the Amazon Bedrock Responses API and AgentCore Gateway are available. Requires explicit setup before use: a Responses API environment and supported model, an IAM-authenticated AgentCore Gateway, configured gateway targets, an IAM role permitted to invoke the gateway, and target credentials/authorisation.
- Licensing
- Billed under Amazon Bedrock and AgentCore pricing; no separate licence documented.
- External model or provider
- Models: those available through the Amazon Bedrock Responses API (examples use OpenAI gpt-oss models). AgentCore Gateway is the managed execution intermediary, recorded under the separate Amazon Bedrock AgentCore product.
- Limitations and uncertainty
- Human confirmation not_established: require_approval = "never" establishes that the documented Responses connector layer provides no Responses-level runtime approval gate. It does not establish that AgentCore Gateway lacks authorisation, that target systems lack confirmation, that developers cannot build an external approval workflow, that IAM controls are absent, or that gateway policies are bypassed. Permission basis mixed: three distinct runtime authority mechanisms are documented (Bedrock execution role IAM permission to invoke the gateway; gateway-side IAM/Cedar policy evaluation; gateway-to-target outbound credentials). Not publicly established: whether invocations cause persistent changes (tool-dependent); universal downstream human confirmation; a universal downstream credential model; maximum server-side tool-call depth or count; arbitrary multi-tool composition; universal attribution to an initiating human; automatic complete CloudTrail coverage of gateway invocations (no current AWS page on AgentCore CloudTrail logging could be retrieved, so any data-event requirement is unconfirmed); uniform downstream logging; native scheduling or event triggering; universal model support across all Bedrock Responses environments. Documentation contradiction: the launch announcement says all Responses API models are supported, while the server-side tool use page says server-side tools are available starting with GPT OSS 20B/120B models, with others coming soon.
Evidence
- Server-side tool use — Amazon Bedrock
Supports: Function · Actions · External actions · Human confirmation · Permission basis · Default state · External model · Primary source
Responses API server-side tool calling; AgentCore Gateway ARN as MCP connector; routes tool calls through the gateway with tool discovery.
Bedrock calls the tool and passes the response back to the model.
Tool calls routed through AgentCore Gateway to targets (Lambda, API Gateway, OpenAPI, MCP servers).
require_approval is required and "has to be never" for the AgentCore Gateway connector.
Bedrock execution role needs bedrock-agentcore:InvokeGateway; only IAM-authenticated gateways supported.
Prerequisites: gateway, configured IAM permissions, gateway ARN.
Server-side tools available starting with GPT OSS 20B/120B models, others coming soon.
- Amazon Bedrock now supports server-side tool execution with AgentCore Gateway
Supports: Function · Availability · Admin controls · Primary source
Bedrock discovers gateway tools, presents them to the model, executes selected calls server-side, injects results; multiple calls per turn.
Generally available 24 Feb 2026 where both Responses API and AgentCore Gateway are available.
Customers retain control through AgentCore Gateway configurations and IAM permissions.
- Core concepts for Amazon Bedrock AgentCore Gateway
Supports: Function · Primary source
Gateway, targets and tools concepts: gateway exposes targets as MCP tools.
- Set up outbound authorization for your gateway — Amazon Bedrock AgentCore
Supports: Permission basis · External actions · Primary source
Outbound auth options: IAM service role with SigV4, OAuth (client credentials, authorization code), API key.
Gateway authenticates to targets with configured outbound credentials.
- Policy in Amazon Bedrock AgentCore: Control Agent Interactions
Supports: Admin controls · Permission basis · Primary source
Policy intercepts gateway traffic and evaluates each request against Cedar policies before tool access.
Gateway-side policy evaluation is a separate authorisation layer from the caller's IAM permission.
- AgentCore generated gateway observability data
Supports: Admin controls · Limitations · Primary source
Gateway metrics, vended logs (request_id, trace_id, span_id) and spans to CloudWatch.
Observability covers gateway MCP operations; downstream logging is not covered.
- Responses API — Amazon Bedrock
Supports: General · Availability · Primary source
Amazon Bedrock provides the OpenAI Responses API on bedrock-runtime and bedrock-mantle endpoints.
Responses API feature support differs between endpoints.