product updateAmazon Web Services

AWS adds managed Web Search to Claude Desktop via Bedrock AgentCore Gateway in three Regions

TL;DR

AWS published a walkthrough for connecting Claude Desktop on Amazon Bedrock to a managed, MCP-compatible Web Search capability through Amazon Bedrock AgentCore Gateway. According to AWS, the search is backed by an Amazon web index spanning tens of billions of documents, and query traffic stays within AWS infrastructure. Web Search is available in three AWS Regions; pricing is not disclosed in the post.

3 min read
0

AWS has published a step-by-step guide for adding Web Search to Claude Desktop running on Amazon Bedrock. The setup uses Amazon Bedrock AgentCore Gateway as an MCP-compatible bridge, with JWT-based inbound authentication tied to AWS IAM Identity Center. The post is a configuration guide, not a model release. No new Claude model or version is involved.

What AWS announced

Web Search is a fully managed, Model Context Protocol (MCP)-compatible capability within AgentCore Gateway. According to AWS, it is backed by an Amazon web index that spans tens of billions of documents. AWS says all query traffic stays within AWS infrastructure, with no external API keys to manage and no queries leaving the customer's boundary. These are AWS's claims; the post offers no independent verification or index-quality benchmarks.

The feature targets a specific limitation: without search, Claude Desktop responses are bounded by the model's training knowledge cutoff. Examples AWS cites include recent documentation updates, live pricing and weather.

Availability

Web Search on AgentCore is available in three Regions:

  • US East (N. Virginia), us-east-1
  • Europe (Ireland), eu-west-1
  • Asia Pacific (Tokyo), ap-northeast-1

The gateway must be created in one of these Regions. Pricing for Web Search is not disclosed in the post.

Authentication architecture

The walkthrough uses AWS IAM Identity Center as the identity source, with Amazon Cognito as a federation layer:

  1. IAM Identity Center authenticates users over SAML.
  2. Amazon Cognito, configured with the OAuth 2.0 authorization code grant flow, issues JWTs.
  3. AgentCore Gateway validates the JWT on each request.

AWS says no separate credentials or third-party identity providers are required.

Setup steps

The guide covers five steps:

  1. Create a Cognito user pool and a globally unique domain, which serves as the OIDC token issuer.
  2. Create a SAML 2.0 application in IAM Identity Center, with attribute mappings for Subject (persistent format) and Email (basic format), then assign users or groups.
  3. Register IAM Identity Center as a SAML identity provider in the Cognito user pool.
  4. Create a Cognito app client with a client secret, the code OAuth flow, scopes openid, email and profile, and a local callback URL (http://localhost:53280/callback).
  5. Create an AgentCore Gateway with JWT inbound auth, pointing to the Cognito discovery URL and client ID, using a Python Boto3 script that also creates an IAM execution role. The source excerpt cuts off before the Web Search target and Claude Desktop managed MCP server configuration.

Prerequisites include an AWS account with IAM and AgentCore permissions, admin access to the AWS Organizations management account, a preconfigured IAM Identity Center, AWS CLI v2, Python 3.10 or later, an updated Boto3 SDK, and Claude Desktop configured with Amazon Bedrock as the inference provider.

What this means

The main value here is governance, not search quality. Enterprises that already route Claude through Bedrock can add live web retrieval without sending queries to a third-party search API or distributing new API keys. For security teams, that removes a common blocker to enabling web access in desktop assistants.

The setup cost is real. Chaining IAM Identity Center, Cognito, SAML and a JWT-validating gateway is a heavy lift for a search tool, and it requires management-account access. Teams without a preconfigured Identity Center will need more work.

The regional limit of three Regions will exclude some data-residency-sensitive deployments. Missing pricing and index-quality data also make it hard to compare this against established search APIs. Buyers should wait for pricing and independent testing before committing.

Related Articles

product update

Anthropic launches Claude for Government for US civilian agencies in FedRAMP High environment

Anthropic is now offering Claude for Government to US federal and state agencies. The platform has been in open beta since July and runs in a FedRAMP High environment. The launch comes as the company's legal fight with the Pentagon continues.

product update

Pi 1.0 agent harness goes stable; Pi Durable ports it to TypeScript with crash-resumable state

Pi, the minimalist agent harness now under Earendil, has reached version 1.0. A companion release, Pi Durable, ports it to TypeScript and externalizes all stateful components so agents can resume after crashes. Pricing and licensing were not disclosed in the source.

model release

Amazon open-sources Strands Decider 2B, a small decision model built on a Qwen3.5-2B base

Amazon Web Services has released Strands Decider 2B, an open-source model that chooses among pre-decided options and returns a confidence score instead of generating text. It is inspired by TypeSafe's Jev and is small enough to run locally. Amazon says it briefly topped the Jevbench ranking for models of its size.

product update

AWS details ambient agent pattern on Bedrock AgentCore: S3 events trigger jobs, one ask_human tool pauses for approval

AWS published a reference implementation for ambient agents on Amazon Bedrock AgentCore. S3 uploads or scheduled events create jobs that an agent runs, pausing for human input through a single ask_human tool. Each agent turn is capped at the 15-minute Lambda timeout.

Comments

Loading...