Amazon Web Services · Amazon Bedrock

Responses API — AgentCore Gateway server-side tool execution

Allows supported Amazon Bedrock Responses API models to discover tools exposed through an IAM-authenticated Amazon Bedrock AgentCore Gateway, select tools during inference, and have Amazon Bedrock execute selected tool calls server-side and return the results to model context without requiring client-side tool orchestration.

Recorded characteristics

Function
Amazon Bedrock invokes model-selected AgentCore Gateway tools server-side. AgentCore Gateway then authorises and routes the invocation to the configured target using its configured execution authority. A Responses API request names an AgentCore Gateway ARN as an MCP tool connector (type mcp, server_label, connector_id = gateway ARN). Amazon Bedrock discovers the tools available from the gateway, presents them to the model during inference, executes tool calls server-side when the model selects them and injects the results back into model context, within a single API call. AWS states multiple tool calls within a single conversation turn are supported and results are streamed to the client. Targets can include Lambda, API Gateway, OpenAPI, Smithy and MCP servers. The effect of an invocation depends on the configured tool: some tools retrieve information, others may cause changes.
Data access
Tools and data reachable are those exposed by the configured AgentCore Gateway targets, under the gateway's outbound credentials. Observability: Gateway publishes invocation and usage metrics, vended logs (including request_id, trace_id, span_id) and spans to Amazon CloudWatch for MCP operations performed on the gateway.
Actions
Can take actions
External actions
Yes
Human confirmation
Not established
Permission basis
Mixed
Administrative control
Selection authority vs execution authority: the model selects the tool; Amazon Bedrock performs the invocation. The Bedrock execution role must hold bedrock-agentcore:InvokeGateway on the gateway (Bedrock only supports gateways with IAM authentication). The gateway can independently allow or deny the call: Policy in AgentCore intercepts traffic through gateways and evaluates each request against Cedar policies (default deny), with IAM-authenticated callers represented as AgentCore::IamEntity principals. Gateway-to-target calls use configured outbound authorisation: gateway service role with SigV4, OAuth (client credentials or authorisation code/user-delegated), API keys, or other documented target mechanisms. Responses connector approval: AWS requires require_approval = "never" for the AgentCore Gateway connector in this documented Responses API integration. This controls the Responses connector's approval behaviour; AgentCore Gateway authorisation and downstream target controls remain separate.
Default state
Disabled
Availability
Generally available since 24 Feb 2026 in AWS Regions where both the Amazon Bedrock Responses API and AgentCore Gateway are available. Requires explicit setup before use: a Responses API environment and supported model, an IAM-authenticated AgentCore Gateway, configured gateway targets, an IAM role permitted to invoke the gateway, and target credentials/authorisation.
Licensing
Billed under Amazon Bedrock and AgentCore pricing; no separate licence documented.
External model or provider
Models: those available through the Amazon Bedrock Responses API (examples use OpenAI gpt-oss models). AgentCore Gateway is the managed execution intermediary, recorded under the separate Amazon Bedrock AgentCore product.
Limitations and uncertainty
Human confirmation not_established: require_approval = "never" establishes that the documented Responses connector layer provides no Responses-level runtime approval gate. It does not establish that AgentCore Gateway lacks authorisation, that target systems lack confirmation, that developers cannot build an external approval workflow, that IAM controls are absent, or that gateway policies are bypassed. Permission basis mixed: three distinct runtime authority mechanisms are documented (Bedrock execution role IAM permission to invoke the gateway; gateway-side IAM/Cedar policy evaluation; gateway-to-target outbound credentials). Not publicly established: whether invocations cause persistent changes (tool-dependent); universal downstream human confirmation; a universal downstream credential model; maximum server-side tool-call depth or count; arbitrary multi-tool composition; universal attribution to an initiating human; automatic complete CloudTrail coverage of gateway invocations (no current AWS page on AgentCore CloudTrail logging could be retrieved, so any data-event requirement is unconfirmed); uniform downstream logging; native scheduling or event triggering; universal model support across all Bedrock Responses environments. Documentation contradiction: the launch announcement says all Responses API models are supported, while the server-side tool use page says server-side tools are available starting with GPT OSS 20B/120B models, with others coming soon.

Evidence