AWS Launches Serverless MCP Proxy on Bedrock AgentCore Runtime for Custom Agent Controls
AWS has released support for custom Model Context Protocol (MCP) proxies on Amazon Bedrock AgentCore Runtime, allowing organizations to implement custom governance and security controls on AI agent tool interactions without modifying upstream MCP servers. The serverless proxy runs on AgentCore Runtime with automatic scaling and built-in observability through CloudWatch and OpenTelemetry.
AWS Launches Serverless MCP Proxy on Bedrock AgentCore Runtime for Custom Agent Controls
Amazon Web Services has released support for custom Model Context Protocol (MCP) proxies on Amazon Bedrock AgentCore Runtime, enabling organizations to add programmable governance and security controls to AI agent tool interactions. The feature addresses production requirements including input sanitization, audit trail generation, and data redaction at the protocol layer.
How the MCP Proxy Works
The proxy runs as a serverless workload on AgentCore Runtime and acts as an intermediary between MCP clients and upstream MCP servers. At startup, the proxy sends a standard tools/list request to the upstream server to discover available tools, then dynamically registers local versions of each tool using FastMCP. Client requests flow through the proxy, which applies custom logic before forwarding to the upstream server.
The architecture consists of three layers: the MCP client, the MCP proxy on AgentCore Runtime, and the upstream MCP server. The upstream server can be hosted on AgentCore Runtime, self-hosted infrastructure, or third-party services. AWS recommends AgentCore Gateway as an upstream server for managed tool discovery, credential management, and policy enforcement.
Infrastructure and Authorization
AgentCore Runtime provides serverless infrastructure with automatic scaling, built-in observability through Amazon CloudWatch and OpenTelemetry, and AgentCore Identity for authentication and authorization. Authorization is enforced independently at each layer: agents authenticate to the proxy using AgentCore Identity, and the proxy authenticates to upstream servers as a standard MCP client.
The proxy implementation uses FastMCP to handle MCP protocol operations. Because the proxy is a standard Python MCP server, developers can insert custom logic before forwarding tool calls or after receiving responses, without replacing the upstream server's native capabilities.
Alternative to Lambda Interceptors
While Amazon Bedrock AgentCore Gateway supports Lambda interceptors for running validation and transformation code on every tool invocation, the MCP proxy pattern is designed for organizations with existing MCP filtering logic tightly coupled to internal libraries or on-premises compliance systems. The serverless proxy approach offers portability across multiple systems and hybrid environments without requiring refactoring into Lambda functions.
Availability
The feature is available now on Amazon Bedrock AgentCore Runtime. AWS has published an open source GitHub implementation to provide a foundation for deploying custom MCP proxies. Pricing follows standard AgentCore Runtime compute and CloudWatch observability costs.
What This Means
This release gives organizations running AI agents on AWS infrastructure a standardized way to implement custom protocol-layer controls without vendor lock-in to Lambda-specific implementations. The serverless proxy pattern is particularly relevant for enterprises migrating existing MCP governance systems to AWS or operating hybrid environments where tool access policies must be portable across multiple platforms. By supporting standard Python MCP servers rather than requiring AWS-specific handlers, the approach preserves code reusability while gaining the operational benefits of managed serverless infrastructure.
Related Articles
Amazon open-sources Strands Decider 2B, a small decision model built on a Qwen3.5-2B base
Amazon Web Services has released Strands Decider 2B, an open-source model that chooses among pre-decided options and returns a confidence score instead of generating text. It is inspired by TypeSafe's Jev and is small enough to run locally. Amazon says it briefly topped the Jevbench ranking for models of its size.
AWS adds managed Web Search to Claude Desktop via Bedrock AgentCore Gateway in three Regions
AWS published a walkthrough for connecting Claude Desktop on Amazon Bedrock to a managed, MCP-compatible Web Search capability through Amazon Bedrock AgentCore Gateway. According to AWS, the search is backed by an Amazon web index spanning tens of billions of documents, and query traffic stays within AWS infrastructure. Web Search is available in three AWS Regions; pricing is not disclosed in the post.
Pi 1.0 agent harness goes stable; Pi Durable ports it to TypeScript with crash-resumable state
Pi, the minimalist agent harness now under Earendil, has reached version 1.0. A companion release, Pi Durable, ports it to TypeScript and externalizes all stateful components so agents can resume after crashes. Pricing and licensing were not disclosed in the source.
AWS details ambient agent pattern on Bedrock AgentCore: S3 events trigger jobs, one ask_human tool pauses for approval
AWS published a reference implementation for ambient agents on Amazon Bedrock AgentCore. S3 uploads or scheduled events create jobs that an agent runs, pausing for human input through a single ask_human tool. Each agent turn is capped at the 15-minute Lambda timeout.
Comments
Loading...