Amazon Bedrock Agentcore (bedrock-agentcore)

2025-10-15

1 new action, 6 new conditions | 8 updated actions, 5 updated resources

Additions

    Actions
  • CompleteResourceTokenAuth
    • Description:  Grants permission to retrieve access token with OAuth2 for 3LO flow to access external resource
    • Access:  Read
    • Resources: 

      Name: oauth2credentialprovider

      Required: Yes

      Name: token-vault

      Required: Yes

      Name: workload-identity

      Required: Yes

      Name: workload-identity-directory

      Required: Yes

    • Conditions: 

      bedrock-agentcore:InboundJwtClaim/iss

      bedrock-agentcore:InboundJwtClaim/sub

      bedrock-agentcore:InboundJwtClaim/aud

      bedrock-agentcore:InboundJwtClaim/scope

      bedrock-agentcore:InboundJwtClaim/client_id

      bedrock-agentcore:userid

Updates

    Actions
  • CreateBrowser
      Conditions
    • + aws:RequestTag/${TagKey}
    • + aws:TagKeys
  • CreateWorkloadIdentity
      Conditions
    • + aws:RequestTag/${TagKey}
    • + aws:TagKeys
  • DeleteAgentRuntime
      Conditions
    • + aws:RequestTag/${TagKey}
    • + aws:TagKeys
  • GetWorkloadAccessTokenForUserId
      Conditions
    • + bedrock-agentcore:InboundJwtClaim/iss
    • + bedrock-agentcore:InboundJwtClaim/sub
    • + bedrock-agentcore:InboundJwtClaim/aud
    • + bedrock-agentcore:InboundJwtClaim/scope
    • + bedrock-agentcore:InboundJwtClaim/client_id
  • GetWorkloadIdentity
      Conditions
    • + bedrock-agentcore:userid
  • ListWorkloadIdentities
      Resources
    • + apikeycredentialprovider
    • + oauth2credentialprovider
    • + token-vault
    • + workload-identity
    • + workload-identity-directory
  • UntagResource
      Resources
    • + apikeycredentialprovider
    • + oauth2credentialprovider
    • + token-vault
    • + workload-identity
    • + workload-identity-directory
  • UpdateAgentRuntime
      Resources
    • + apikeycredentialprovider
    • + oauth2credentialprovider
    • + token-vault
    • + workload-identity
    • + workload-identity-directory