Gateway Service
The Gateway service converts REST APIs into MCP tools that AI agents can use. It handles authentication, schema validation, and request routing.
Quick Start
Prerequisites
- AWS CLI configured with appropriate permissions
- An existing Gateway (created via AWS Console or CLI)
- OpenAPI schema for your target API
Deploy a Gateway Target
Step 1: Upload OpenAPI schema to S3
aws s3 cp my-api-openapi.yaml s3://<BUCKET_NAME>/schemas/Step 2: Create credential provider (API Key auth only)
aws bedrock-agentcore-control create-api-key-credential-provider \
--name MyAPICredentialProvider \
--api-key "YOUR_API_KEY" \
--region us-west-2Step 3: Create gateway target
aws bedrock-agentcore-control create-gateway-target \
--gateway-identifier <GATEWAY_ID> \
--name MyAPITarget \
--endpoint-configuration '{"openApiSchema": {"s3": {"uri": "s3://<BUCKET_NAME>/schemas/my-api-openapi.yaml"}}}' \
--credential-provider-configurations '[{"credentialProviderType": "GATEWAY_API_KEY_CREDENTIAL_PROVIDER", "apiKeyCredentialProvider": {"providerArn": "arn:aws:bedrock-agentcore:us-west-2:<ACCOUNT_ID>:api-key-credential-provider/MyAPICredentialProvider"}}]' \
--region us-west-2Step 4: Verify deployment
aws bedrock-agentcore-control get-gateway-target \
--gateway-identifier <GATEWAY_ID> \
--target-identifier <TARGET_ID> \
--region us-west-2Authentication Options
Outbound (Accessing External APIs)
| Target Type | IAM | OAuth 2LO | OAuth 3LO | API Key |
|---|---|---|---|---|
| Lambda function | Yes | No | No | No |
| API Gateway | Yes | No | No | Yes |
| OpenAPI schema | No | Yes | Yes | Yes |
| Smithy schema | Yes | Yes | Yes | No |
| MCP server | No | Yes | No | No |
Inbound (Who Can Invoke Tools)
- IAM: AWS IAM credentials
- JWT: Tokens from identity providers (Cognito, Entra ID)
- No Auth: Open access (use with caution)
Documentation
| Document | Description |
|---|---|
| Deployment Strategies | Credential provider patterns, multi-environment setup, key rotation |
| Troubleshooting Guide | Common errors, diagnosis steps, solutions |
| Deploy Template Script | Automated deployment script |
| Validate Deployment Script | Post-deployment verification |
Common Operations
List Gateway Targets
aws bedrock-agentcore-control list-gateway-targets \
--gateway-identifier <GATEWAY_ID> \
--region us-west-2Update Credential Provider
aws bedrock-agentcore-control update-api-key-credential-provider \
--name MyAPICredentialProvider \
--api-key "NEW_API_KEY" \
--region us-west-2Delete Gateway Target
aws bedrock-agentcore-control delete-gateway-target \
--gateway-identifier <GATEWAY_ID> \
--target-identifier <TARGET_ID> \
--region us-west-2