Authenticate with Private Key JWT using Amazon Bedrock AgentCore Identity
Machine Learning Blog
This article announces Private Key JWT client authentication support in Amazon Bedrock AgentCore Identity, allowing agents to authenticate to downstream identity providers using KMS-signed JWT assertions.
- Agents sign JWT assertions with AWS KMS asymmetric keys instead of using shared OAuth secrets
- Supports three grant flows: machine-to-machine, on-behalf-of, and user-delegated access
- Public key registered with identity provider; private key remains secure in AWS KMS
- All signing operations auditable through AWS CloudTrail for compliance
- Compatible with RS256, PS256, and ES256 signing algorithms
- Step-by-step console configuration for creating KMS keys and OAuth clients
Private Key JWT authentication provides a secret-less, auditable authentication method for agents accessing downstream APIs and services.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Apr 30
2026
2026
Configuring Amazon Bedrock AgentCore Gateway for secure access to private resources
Aug 19
2026
2026
Propagate user authorization context in AI agents with Amazon Bedrock AgentCore
Jul 13
2026
2026
Implement on-behalf-of token exchange for multi-tenant agents with Amazon Bedrock AgentCore Gateway
Jul 8
2026
2026
Securing Amazon Bedrock AgentCore Runtime with AWS WAF
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.