Manage end-user OAuth consent for AI agents with Amazon Bedrock AgentCore
Machine Learning Blog
This article explains how to use Amazon Bedrock AgentCore's new Consent portal to manage end-user OAuth consent for AI agents accessing external services.
- Consent portal provides managed web experience and session binding for AgentCore Gateway without building custom infrastructure
- Users authenticate with corporate identity provider, review available services, and grant consent independently per provider
- Portal handles browser redirects and session binding while AgentCore Identity securely stores tokens in token vault
- Particularly useful for IDE and MCP clients like Claude Code, Cursor, and Visual Studio Code
- Administrator configures corporate IdP, gateway targets, execution role, and shares single portal URL with users
- End users sign in once and can connect GitHub, Slack, or other providers independently without repeated prompts
- Consent operations are auditable through AWS CloudTrail for compliance and troubleshooting
The Consent portal eliminates the need for customers to build custom session binding infrastructure while enabling secure, user-specific OAuth token management for AI agents.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.