Live
Transactional messaging in Spanner queues simplifies AI agent pipelinesDGX Spark 64 GB adds on‑device AI scaling with built‑in clusteringUsing the Adjudicated Query Pattern with Amazon Quick to Scale Lease Compliance ChecksHow the New DevOps Standard Shapes Delivery Decisions for EngineersGKE adds CPU startup boost via VPA to cut cold‑start latency without over‑provisioningLightweight Kubernetes (K3s) vs Full‑Scale K8s: Architectural Shifts and Operational ImpactRethinking AI Agent Harnesses for Cloud‑Native Kubernetes EnvironmentsSecurely Extending Claude Desktop with Bedrock AgentCore Web SearchTransactional messaging in Spanner queues simplifies AI agent pipelinesDGX Spark 64 GB adds on‑device AI scaling with built‑in clusteringUsing the Adjudicated Query Pattern with Amazon Quick to Scale Lease Compliance ChecksHow the New DevOps Standard Shapes Delivery Decisions for EngineersGKE adds CPU startup boost via VPA to cut cold‑start latency without over‑provisioningLightweight Kubernetes (K3s) vs Full‑Scale K8s: Architectural Shifts and Operational ImpactRethinking AI Agent Harnesses for Cloud‑Native Kubernetes EnvironmentsSecurely Extending Claude Desktop with Bedrock AgentCore Web Search
AWS

Securely Extending Claude Desktop with Bedrock AgentCore Web Search

AI SummaryPowered by AI

Claude Desktop now integrates Amazon Bedrock AgentCore's managed Web Search via a JWT‑secured gateway, eliminating the model's static knowledge cutoff. This gives engineers up‑to‑date results while keeping authentication and traffic fully within AWS.

Claude Desktop on Amazon Bedrock now supports live web results by routing queries through an Amazon Bedrock AgentCore Gateway that exposes the managed Web Search capability. The change removes the model’s static knowledge cutoff and keeps all traffic inside the AWS boundary, which matters to engineers who need up‑to‑date data without managing external API keys or exposing requests to the public internet.

Bedrock AgentCore Web Search Integration

The integration leverages the AgentCore Gateway, a component of Amazon Bedrock AgentCore that can connect any model to external data sources that implement the Model Context Protocol (MCP). By enabling the Web Search target on a managed MCP server, Claude Desktop can forward user prompts to the gateway, which then queries a proprietary Amazon index containing tens of billions of documents. The response is returned to Claude Desktop as part of the model’s answer, providing current information such as recent documentation, pricing, or weather.

Authentication Flow

Enterprise SSO is preserved by using AWS IAM Identity Center as the source of user authentication. Identity Center authenticates users via SAML and hands off the session to Amazon Cognito, which acts as a federation layer. Cognito issues JSON Web Tokens (JWTs) using the OAuth 2.0 authorization‑code grant flow. Each request that the AgentCore Gateway receives includes a JWT, which the gateway validates before invoking the Web Search service. This chain—IAM Identity Center → Cognito → JWT → AgentCore Gateway—keeps the entire authentication process within AWS and eliminates the need for separate credentials or third‑party identity providers.

Implementation Steps

Before building the integration, ensure the following prerequisites are in place:

  • AWS account with permissions to create IAM roles and Bedrock AgentCore resources.
  • Administrative access to the management account for configuring IAM Identity Center.
  • IAM Identity Center already set up for SSO to AWS accounts.
  • Claude Desktop configured to use Amazon Bedrock as its inference provider.
  • AWS CLI v2, Python 3.10 +, and the latest Boto3 SDK installed.
  • Selection of a supported region (us-east-1, eu-west-1, or ap-northeast-1) for the AgentCore Gateway.

The core configuration begins with creating an Amazon Cognito user pool that will serve as the OpenID Connect token issuer. A typical CLI command creates the pool, enables email verification, and disables MFA. After creation, capture the user‑pool ID for later reference. Next, configure a managed MCP server in Bedrock AgentCore, enable the Web Search target, and point the server to the Cognito user pool for inbound JWT validation. Finally, register the MCP server with Claude Desktop’s managed MCP server settings so that the desktop client knows the gateway endpoint and authentication requirements.

Related CloudNinjas coverage: AWS.

What This Means For Practitioners

Practitioners gain a path to augment Claude Desktop with real‑time data while keeping authentication and data flow inside the AWS trust boundary. The JWT‑based inbound check provides a clear security control point that can be audited alongside existing IAM Identity Center policies. Operationally, teams must monitor the health of the Cognito user pool, token expiration settings, and the AgentCore Gateway’s regional availability. Future evaluation should include token rotation practices, scaling considerations for high query volumes, and any additional compliance checks required for the data returned by Web Search.

Originally published atAWS Machine Learning Blog