Add secure Web Search to Claude Desktop with Amazon Bedrock AgentCore Amazon Web Services published a walkthrough for connecting Claude Desktop on Amazon Bedrock to Web Search through Amazon Bedrock AgentCore Gateway, using JWT-based inbound authentication. The setup federates AWS IAM Identity Center with Amazon Cognito over the OAuth 2.0 authorization code grant flow so the gateway validates JWTs on each request, keeping all query traffic inside AWS infrastructure with no external API keys. Web Search on AgentCore is available in us-east-1, eu-west-1, and ap-northeast-1, and requires AWS CLI v2, Python 3.10 or later, and an updated Boto3 SDK. Artificial Intelligence https://aws.amazon.com/blogs/machine-learning/ Add secure Web Search to Claude Desktop with Amazon Bedrock AgentCore Claude Desktop https://claude.com/docs/third-party/claude-desktop/overview on Amazon Bedrock https://aws.amazon.com/bedrock/ provides powerful AI assistance, but without integrated web search, responses are limited to the model’s training knowledge cutoff. When you need current information, such as recent documentation updates, live pricing, or weather updates, the model can’t retrieve it on its own. Amazon Bedrock AgentCore https://aws.amazon.com/bedrock/agentcore/ is a platform to build, connect, and optimize agents at scale, with any framework or model. With AgentCore Gateway https://aws.amazon.com/blogs/machine-learning/introducing-amazon-bedrock-agentcore-gateway-transforming-enterprise-ai-agent-tool-development/ , a capability of Amazon Bedrock AgentCore, you can close this knowledge cutoff gap by connecting Claude Desktop to Web Search https://aws.amazon.com/blogs/machine-learning/introducing-web-search-on-amazon-bedrock-agentcore/ . Web Search is a fully managed, Model Context Protocol MCP -compatible web search capability backed by an Amazon web index that spans tens of billions of documents. All query traffic stays within AWS infrastructure, with no external API keys to manage and no queries leaving your boundary. With Claude Desktop, you can use managed MCP servers https://claude.com/docs/third-party/claude-desktop/extensions managed-mcp-servers-admin to connect to an AgentCore Gateway with the Web Search target enabled. In this post, we walk through the steps to set up this integration and use JSON Web Token JWT -based inbound authentication to secure the communication. Architecture Many enterprises running on AWS use AWS IAM Identity Center https://aws.amazon.com/iam/identity-center/ for single sign-on SSO access to their AWS accounts. In this walkthrough, we use AWS IAM Identity Center as the authentication source for the AgentCore Gateway. With this setup, Claude Desktop on Amazon Bedrock can invoke Web Search through a trusted, enterprise-managed identity flow. This approach aligns with existing organizational identity governance. No separate credentials or third-party identity providers are required. To bridge AWS IAM Identity Center with the AgentCore Gateway JWT-based authentication, we use Amazon Cognito https://aws.amazon.com/pm/cognito/ as a federation layer with the OAuth 2.0 authorization code grant flow. IAM Identity Center handles user authentication through Security Assertion Markup Language SAML https://en.wikipedia.org/wiki/SAML . Amazon Cognito issues JWTs, and the AgentCore Gateway validates them on each request. The entire authentication chain stays within AWS. The following sequence diagram illustrates this authentication flow. Prerequisites To follow along with the steps in this post, you need the following: - An AWS account with permissions to create AWS Identity and Access Management IAM https://aws.amazon.com/iam/ roles and Amazon Bedrock AgentCore resources. - Admin access to your management account in AWS Organizations for AWS IAM Identity Center configuration . - AWS IAM Identity Center preconfigured for SSO access to AWS accounts. - Claude Desktop set up with Amazon Bedrock as the inference provider. - The AWS Command Line Interface AWS CLI v2 installed and configured. - Python 3.10 or later. - The Boto3 SDK updated to the latest version. Web Search on Amazon Bedrock AgentCore is currently available in the US East N. Virginia AWS Region us-east-1 , Europe Ireland Region eu-west-1 , and Asia Pacific Tokyo Region ap-northeast-1 . Verify that your gateway is created in one of these Regions. Configuration The configuration involves setting up the authentication chain AWS IAM Identity Center to Amazon Cognito to JWT and then wiring the AgentCore Gateway into Claude Desktop. We walk through each step in the following section. Step 1: Create an Amazon Cognito user pool In your target AWS account, create an Amazon Cognito user pool that will serve as the OpenID Connect OIDC token issuer for the AgentCore Gateway. Save these values for later steps: - User Pool ID: $USER POOL ID . - Domain :