Amazon Bedrock AgentCore has introduced a new capability, AgentCore Gateway, enabling Claude Desktop to access real-time information through a secure, managed Web Search integration. This enhancement addresses the inherent knowledge cutoff limitations of large language models by allowing them to retrieve current data, such as recent documentation, live pricing, or weather updates.
According to details received by The Chenab Times, the integration leverages Web Search on Amazon Bedrock AgentCore, a feature backed by an extensive Amazon web index. This allows Claude Desktop, when connected to an AgentCore Gateway, to query the web without requiring external API keys or exposing query traffic outside of AWS infrastructure. The setup utilizes JSON Web Token (JWT)-based inbound authentication for secure communication.
Architecture and Security Framework
The architecture is designed to work seamlessly within enterprise AWS environments that often use AWS IAM Identity Center for single sign-on (SSO). To bridge IAM Identity Center with AgentCore Gateway’s JWT authentication, Amazon Cognito acts as a federation layer. It employs the OAuth 2.0 authorization code grant flow, where IAM Identity Center handles user authentication via Security Assertion Markup Language (SAML). Amazon Cognito then issues JWTs, which the AgentCore Gateway validates for each request, ensuring the entire authentication chain remains within AWS and aligns with existing identity governance practices.
Prerequisites for Integration
Implementing this integration requires several prerequisites. Users will need an AWS account with the necessary permissions for creating IAM roles and AgentCore resources. Administrative access to an AWS Organizations management account is needed for configuring AWS IAM Identity Center, which must be preconfigured for SSO. Claude Desktop must be set up with Amazon Bedrock as its inference provider. Additionally, the AWS Command Line Interface (AWS CLI) v2, Python 3.10 or later, and the latest version of the Boto3 SDK are required. The Web Search on Amazon Bedrock AgentCore is currently available in the US East (N. Virginia), Europe (Ireland), and Asia Pacific (Tokyo) AWS Regions.
Configuration Steps
The integration process involves setting up the authentication chain and connecting the AgentCore Gateway to Claude Desktop. Initially, an Amazon Cognito user pool is created to act as the OpenID Connect (OIDC) token issuer for the AgentCore Gateway. This is followed by configuring IAM Identity Center as a SAML application that federates with Cognito, defining attribute mappings for user subject and email. Subsequently, IAM Identity Center is registered as a SAML identity provider within the Cognito user pool.
A Cognito app client with a client secret is then established. This client facilitates the OAuth flow for Claude Desktop, authenticating users through IAM Identity Center and obtaining the JWT for the AgentCore Gateway. The next crucial step is creating an AgentCore Gateway with JWT-based inbound authorization. This involves defining an execution role with appropriate permissions and attaching the managed Web Search connector as a target to the gateway.
Connecting Claude Desktop
Once the AgentCore Gateway is configured and running, users can connect Claude Desktop. This is done through Claude Desktop’s configuration settings, specifically under ‘Connectors and Extensions’. A new server connection is added, identified as ‘websearchtool’. The transport is set to ‘Streamable HTTP’, and the URL points to the AgentCore Gateway resource URL. For authentication, ‘Bring your own client’ is selected, and the previously created Cognito Client ID and Client Secret are entered. The Authorization Server and Scope are also specified, typically using the Cognito domain and ‘openid’ scope respectively.
Upon testing the connection, a browser window opens for authentication via IAM Identity Center. After successful login, a confirmation message appears in the browser, and Claude Desktop registers the MCP server. Once registered, Claude Desktop automatically discovers the WebSearchTool and invokes it when the model requires current web-based information.
Testing and Validation
Users can test the integration by sending a query to Claude Desktop that necessitates real-time web data. A tool execution approval box will appear, indicating that Claude has identified and intends to use the Web Search tool. Options to deny, allow for the current task, or allow once are provided. Upon approval, the web search results are incorporated into Claude’s response, confirming the successful integration and functionality of the Web Search capability.
Clean Up Procedures
To revert the changes and remove the created resources, a specific clean-up process is outlined. This includes deleting the gateway target and the gateway itself from AgentCore, removing the associated IAM policy and role, and then deleting the Cognito application client, identity provider, user pool domain, and finally the user pool. The SAML application created in IAM Identity Center must also be deleted.
This integration offers a secure method for enhancing AI assistants with up-to-date information, keeping all operations within the AWS environment.
The Chenab Times News Desk

