{"slug": "add-secure-web-search-to-claude-desktop-with-amazon-bedrock-agentcore", "title": "Add secure Web Search to Claude Desktop with Amazon Bedrock AgentCore", "summary": "Amazon Web Services published a walkthrough for connecting Claude Desktop on Amazon Bedrock to Web Search through Amazon Bedrock AgentCore Gateway, using JWT-based inbound authentication. The setup federates AWS IAM Identity Center with Amazon Cognito over the OAuth 2.0 authorization code grant flow so the gateway validates JWTs on each request, keeping all query traffic inside AWS infrastructure with no external API keys. Web Search on AgentCore is available in us-east-1, eu-west-1, and ap-northeast-1, and requires AWS CLI v2, Python 3.10 or later, and an updated Boto3 SDK.", "body_md": "## [Artificial Intelligence](https://aws.amazon.com/blogs/machine-learning/)\n\n# Add secure Web Search to Claude Desktop with Amazon Bedrock AgentCore\n\n[Claude Desktop](https://claude.com/docs/third-party/claude-desktop/overview) on [Amazon Bedrock](https://aws.amazon.com/bedrock/) provides powerful AI assistance, but without integrated web search, responses are limited to the model’s training knowledge cutoff. When you need current information, such as recent documentation updates, live pricing, or weather updates, the model can’t retrieve it on its own.\n\n[Amazon Bedrock AgentCore](https://aws.amazon.com/bedrock/agentcore/) is a platform to build, connect, and optimize agents at scale, with any framework or model. With [AgentCore Gateway](https://aws.amazon.com/blogs/machine-learning/introducing-amazon-bedrock-agentcore-gateway-transforming-enterprise-ai-agent-tool-development/), a capability of Amazon Bedrock AgentCore, you can close this knowledge cutoff gap by connecting Claude Desktop to [Web Search](https://aws.amazon.com/blogs/machine-learning/introducing-web-search-on-amazon-bedrock-agentcore/). Web Search is a fully managed, Model Context Protocol (MCP)-compatible web search capability backed by an Amazon web index that spans tens of billions of documents. All query traffic stays within AWS infrastructure, with no external API keys to manage and no queries leaving your boundary.\n\nWith Claude Desktop, you can use [managed MCP servers](https://claude.com/docs/third-party/claude-desktop/extensions#managed-mcp-servers-admin) to connect to an AgentCore Gateway with the Web Search target enabled. In this post, we walk through the steps to set up this integration and use JSON Web Token (JWT)-based inbound authentication to secure the communication.\n\n## Architecture\n\nMany enterprises running on AWS use [AWS IAM Identity Center](https://aws.amazon.com/iam/identity-center/) for single sign-on (SSO) access to their AWS accounts. In this walkthrough, we use AWS IAM Identity Center as the authentication source for the AgentCore Gateway. With this setup, Claude Desktop on Amazon Bedrock can invoke Web Search through a trusted, enterprise-managed identity flow. This approach aligns with existing organizational identity governance. No separate credentials or third-party identity providers are required.\n\nTo bridge AWS IAM Identity Center with the AgentCore Gateway JWT-based authentication, we use [Amazon Cognito](https://aws.amazon.com/pm/cognito/) as a federation layer with the OAuth 2.0 authorization code grant flow. IAM Identity Center handles user authentication through [Security Assertion Markup Language (SAML)](https://en.wikipedia.org/wiki/SAML). Amazon Cognito issues JWTs, and the AgentCore Gateway validates them on each request. The entire authentication chain stays within AWS.\n\nThe following sequence diagram illustrates this authentication flow.\n\n## Prerequisites\n\nTo follow along with the steps in this post, you need the following:\n\n- An AWS account with permissions to create [AWS Identity and Access Management (IAM)](https://aws.amazon.com/iam/) roles and Amazon Bedrock AgentCore resources.\n- Admin access to your management account in AWS Organizations (for AWS IAM Identity Center configuration).\n- AWS IAM Identity Center preconfigured for SSO access to AWS accounts.\n- Claude Desktop set up with Amazon Bedrock as the inference provider.\n- The AWS Command Line Interface (AWS CLI) v2 installed and configured.\n- Python 3.10 or later.\n- The Boto3 SDK updated to the latest version.\n\nWeb Search on Amazon Bedrock AgentCore is currently available in the US East (N. Virginia) AWS Region (us-east-1), Europe (Ireland) Region (eu-west-1), and Asia Pacific (Tokyo) Region (ap-northeast-1). Verify that your gateway is created in one of these Regions.\n\n## Configuration\n\nThe configuration involves setting up the authentication chain (AWS IAM Identity Center to Amazon Cognito to JWT) and then wiring the AgentCore Gateway into Claude Desktop. We walk through each step in the following section.\n\n### Step 1: Create an Amazon Cognito user pool\n\nIn your target AWS account, create an Amazon Cognito user pool that will serve as the OpenID Connect (OIDC) token issuer for the AgentCore Gateway.\n\nSave these values for later steps:\n\n- **User Pool ID:**`$USER_POOL_ID` .\n- **Domain** :`<your-unique-prefix>.auth.<region>.amazoncognito.com` .\n- **Audience** :`urn:amazon:cognito:sp:<user-pool-id>` .\n- **ACS URL:**`https://<your-unique-prefix>.auth.<region>.amazoncognito.com/saml2/idpresponse` .\n\n### Step 2: Configure IAM Identity Center SAML application\n\nIn your AWS Organizations management account, create a SAML application that federates with Cognito:\n\n1. Open IAM Identity Center console.\n2. Choose **Applications** ,**Add application** ,**I have an application I want to set up** ,**SAML 2.0** , and then**Next** .\n3. Fill in the following details: \n         \n  1. **Display name** : AgentCore Web Search.\n  2. Select **Manually type your metadata value** .\n    1. **ACS URL** :`https://<your-unique-prefix>.auth.<region>.amazoncognito.com/saml2/idpresponse` .\n    2. **Audience** :`urn:amazon:cognito:sp:<user-pool-id>` .\n  3. Download the SAML metadata XML file and choose **Submit** .\n  4. After the application is created, edit the attribute mappings and insert the following values: \n           \n    1. Subject, ${user:subject}, Format: Persistent.\n    2. Email, ${user:email}, Format: Basic.\n  5. Assign the users or groups that would have access to Web Search.\n\n### Step 3: Wire SAML IdP into Cognito\n\nBack in the target account, register IAM Identity Center as a SAML identity provider in your Cognito user pool:\n\n### Step 4: Create Cognito app client for Amazon Bedrock AgentCore\n\nCreate an app client with a client secret. Claude Desktop uses this client to initiate the OAuth flow, which authenticates the user through IAM Identity Center and obtains a JWT for the AgentCore Gateway:\n\nNote the **Client ID** and **Client Secret** from the output. These are your application client ID and secret.\n\n### Step 5: Configure AgentCore Gateway with Web Search tool\n\nIn this step, we create a new AgentCore Gateway with [**Inbound Auth Type**](https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway-inbound-auth.html#gateway-inbound-auth-jwt) as **JSON Web Tokens (JWT)**. For this configuration, we use the Cognito user pool ID and application client ID that were created in the prior steps.\n\nRun the following Python script to create the gateway with the required configurations, replacing all placeholders with actual values from your environment.\n\nYou now have an AgentCore Gateway with Web Search tool, with JWT-based inbound authorization.\n\n### Step 6: Configure Claude Desktop\n\nUse the steps in the Claude Desktop configuration documentation to access the configuration window for Claude Desktop with Amazon Bedrock. After you open it, choose **Connectors and Extensions**, then choose **Add server**, and then choose **Blank**.\n\nThe following screenshot shows the configuration window with these options.\n\nEnter the following details:\n\n1. **Name** : websearchtool.\n2. **Transport** : Streamable HTTP.\n3. **URL** : Enter the gateway resource URL for the AgentCore Gateway created in Step 5.\n4. **OAuth** : Bring your own client.\n5. **Client ID** : Enter the client ID for the app client created in Step 4.\n6. **Client Secret** : Enter the client secret for the app client created in Step 4.\n7. **Authorization Server** : Enter`[\"https://<your-unique-prefix>.auth.<region>.amazoncognito.com/oauth2/authorize\"]` .\n8. **Scope** : openid.\n9. **Callback host** :`localhost` .\n10. **Callback port** : 53280.\n\nWhen you’re done, choose **sign in and test**. This should open a browser for you to authenticate, redirecting you to your AWS IAM Identity Center SSO login. Enter your credentials to authenticate. If successful, you should see a message such as, “Authorization complete. You can close this tab and return to Claude.”\n\nBack in Claude Desktop, you should see a successful MCP registration message like in the following image.\n\nClaude Desktop will now discover the WebSearchTool through the MCP tools/list call. It invokes the tool automatically whenever the model needs current information from the web.\n\n## Testing and validation\n\nIn your preferred interface (for example, Chat or Cowork), send a query that requires Claude Desktop to retrieve the latest results. You should see a tool execution approval box, indicating that Claude has successfully discovered the Web Search tool. On approval, you should see the web search results included in the response.\n\nThe dialog shows the query Claude wants to run and offers three options: Deny, Allow for this task, or Allow once. On approval, Web Search results are included in the response.\n\n## Clean up\n\nIf you created resources while following along, perform the following steps to delete them:\n\nFinally, in the IAM Identity Center console in the management account, delete the SAML application you created in Step 2.\n\n## Conclusion\n\nIn this post, we walked through integrating Web Search on AgentCore with Claude Desktop. While this walkthrough uses AWS IAM Identity Center as the identity provider, the same pattern works with any SAML or OIDC-compatible identity provider. You can substitute your existing IdP by configuring it as a federation source in Amazon Cognito. This approach closes the web search gap without introducing third-party dependencies, and all queries stay within your AWS boundary.\n\nTo get started, follow the steps above to set up the integration in your own environment. For advanced gateway configurations, see the [AgentCore Gateway Developer Guide](https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway-using.html). To learn more about Web Search, see the [Web Search](https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway-target-connector-web-search-tool.html) documentation.", "url": "https://wpnews.pro/news/add-secure-web-search-to-claude-desktop-with-amazon-bedrock-agentcore", "canonical_source": "https://aws.amazon.com/blogs/machine-learning/add-secure-web-search-to-claude-desktop-with-amazon-bedrock-agentcore/", "published_at": "2026-10-02 15:46:05+00:00", "updated_at": "2026-10-02 16:07:47.401516+00:00", "lang": "en", "topics": ["ai-agents", "agent-protocols", "ai-tools", "ai-infrastructure", "artificial-intelligence"], "entities": ["Amazon Web Services", "Claude Desktop", "Amazon Bedrock", "Amazon Bedrock AgentCore", "AgentCore Gateway", "AWS IAM Identity Center", "Amazon Cognito", "Model Context Protocol"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/add-secure-web-search-to-claude-desktop-with-amazon-bedrock-agentcore", "markdown": "https://wpnews.pro/news/add-secure-web-search-to-claude-desktop-with-amazon-bedrock-agentcore.md", "text": "https://wpnews.pro/news/add-secure-web-search-to-claude-desktop-with-amazon-bedrock-agentcore.txt", "jsonld": "https://wpnews.pro/news/add-secure-web-search-to-claude-desktop-with-amazon-bedrock-agentcore.jsonld"}}