Claude Desktop on Amazon Bedrock now supports live web results by routing queries through an Amazon Bedrock AgentCore Gateway that exposes the managed Web Search capability. The change removes the model’s static knowledge cutoff and keeps all traffic inside the AWS boundary, which matters to engineers who need up‑to‑date data without managing external API keys or exposing requests to the public internet.
Bedrock AgentCore Web Search Integration
The integration leverages the AgentCore Gateway, a component of Amazon Bedrock AgentCore that can connect any model to external data sources that implement the Model Context Protocol (MCP). By enabling the Web Search target on a managed MCP server, Claude Desktop can forward user prompts to the gateway, which then queries a proprietary Amazon index containing tens of billions of documents. The response is returned to Claude Desktop as part of the model’s answer, providing current information such as recent documentation, pricing, or weather.
Authentication Flow
Enterprise SSO is preserved by using AWS IAM Identity Center as the source of user authentication. Identity Center authenticates users via SAML and hands off the session to Amazon Cognito, which acts as a federation layer. Cognito issues JSON Web Tokens (JWTs) using the OAuth 2.0 authorization‑code grant flow. Each request that the AgentCore Gateway receives includes a JWT, which the gateway validates before invoking the Web Search service. This chain—IAM Identity Center → Cognito → JWT → AgentCore Gateway—keeps the entire authentication process within AWS and eliminates the need for separate credentials or third‑party identity providers.
Implementation Steps
Before building the integration, ensure the following prerequisites are in place:
- AWS account with permissions to create IAM roles and Bedrock AgentCore resources.
- Administrative access to the management account for configuring IAM Identity Center.
- IAM Identity Center already set up for SSO to AWS accounts.
- Claude Desktop configured to use Amazon Bedrock as its inference provider.
- AWS CLI v2, Python 3.10 +, and the latest Boto3 SDK installed.
- Selection of a supported region (us-east-1, eu-west-1, or ap-northeast-1) for the AgentCore Gateway.
The core configuration begins with creating an Amazon Cognito user pool that will serve as the OpenID Connect token issuer. A typical CLI command creates the pool, enables email verification, and disables MFA. After creation, capture the user‑pool ID for later reference. Next, configure a managed MCP server in Bedrock AgentCore, enable the Web Search target, and point the server to the Cognito user pool for inbound JWT validation. Finally, register the MCP server with Claude Desktop’s managed MCP server settings so that the desktop client knows the gateway endpoint and authentication requirements.
Related CloudNinjas coverage: AWS.
What This Means For Practitioners
Practitioners gain a path to augment Claude Desktop with real‑time data while keeping authentication and data flow inside the AWS trust boundary. The JWT‑based inbound check provides a clear security control point that can be audited alongside existing IAM Identity Center policies. Operationally, teams must monitor the health of the Cognito user pool, token expiration settings, and the AgentCore Gateway’s regional availability. Future evaluation should include token rotation practices, scaling considerations for high query volumes, and any additional compliance checks required for the data returned by Web Search.



