Enable safe agentic payments with built-in guardrails using Amazon Bedrock AgentCore payments
Machine Learning Blog
This article explains how Amazon Bedrock AgentCore Payments enables AI agents to safely execute financial transactions on behalf of users with built-in security guardrails.
- Agents can access paid resources autonomously using embedded wallets from Coinbase or Stripe
- Per-session spending limits and TTLs enforced at infrastructure layer prevent runaway costs
- End users fund wallets and explicitly delegate spending authority separately
- Developer credentials stored encrypted in AWS KMS token vault, never in agent code
- User payment details never exposed to agent; card data stays with wallet provider
- Four-role IAM pattern separates control plane from data plane operations
- Just-in-time session-scoped tokens issued for each payment transaction
- Full audit trail automatically emitted to CloudWatch and X-Ray
- Service available in preview in US East, US West, Europe, and Asia Pacific regions
AgentCore Payments provides production-ready agentic commerce with deterministic spending controls, user custody of funds, and complete auditability while keeping payment data outside agent systems.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
2026
2026
2026
2026
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.