Home icon

Manage end-user OAuth consent for AI agents with Amazon Bedrock AgentCore

Machine Learning Blog



This article explains how to use Amazon Bedrock AgentCore's new Consent portal to manage end-user OAuth consent for AI agents accessing external services.

  • Consent portal provides managed web experience and session binding for AgentCore Gateway without building custom infrastructure
  • Users authenticate with corporate identity provider, review available services, and grant consent independently per provider
  • Portal handles browser redirects and session binding while AgentCore Identity securely stores tokens in token vault
  • Particularly useful for IDE and MCP clients like Claude Code, Cursor, and Visual Studio Code
  • Administrator configures corporate IdP, gateway targets, execution role, and shares single portal URL with users
  • End users sign in once and can connect GitHub, Slack, or other providers independently without repeated prompts
  • Consent operations are auditable through AWS CloudTrail for compliance and troubleshooting

The Consent portal eliminates the need for customers to build custom session binding infrastructure while enabling secure, user-specific OAuth token management for AI agents.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Aug 19
2026
Propagate user authorization context in AI agents with Amazon Bedrock AgentCore
Sep 3
2026
Amazon Bedrock AgentCore Identity now offers a managed consent portal
Sep 4
2026
Mass-migrating AI agents to Amazon Bedrock AgentCore
Oct 14
2025
Securing AI agents with Amazon Bedrock AgentCore Identity

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.