{"slug": "secure-web-search-for-claude-desktop-via-bedrock-agentcore", "title": "Secure web search for Claude Desktop via Bedrock AgentCore", "summary": "Amazon Bedrock AgentCore's Web Search target can give Claude Desktop live web results through an MCP-compatible gateway that keeps all queries inside AWS boundaries, using JWT-based inbound authentication via Cognito and IAM Identity Center instead of external API keys. The setup requires registering an MCP-compatible server at the gateway URL, configuring Claude Desktop's managed MCP server settings with the JWT issuer and audience claims, and creating a Cognito user pool tied to the IAM Identity Center directory. Common failure modes include machine time drift, expired Cognito client secrets, mismatched JWT audience, and misconfigured redirect URIs, all of which cause silent empty results or login loops rather than explicit errors.", "body_md": "# Secure web search for Claude Desktop via Bedrock AgentCore\n\n[Claude](https://promptcube3.com/en/tags/claude/) Desktop running on Amazon Bedrock loses its edge when it can't pull live web results, leaving you stuck with knowledge that may be months or years out of date. If you're relying on that assistant for anything needing current data — API docs, stock prices, news — you're effectively flying blind.\n\nThe fix lands through Amazon Bedrock AgentCore's Web Search target, exposed via an [MCP](https://promptcube3.com/en/tags/mcp/)-compatible gateway that keeps all queries inside AWS boundaries. No external API keys, no cross-boundary egress — the traffic never leaves your network footprint.\n\n## Why route search through AgentCore Gateway\n\nMost teams bolt on third-party search tools because they assume there's no native path inside AWS. That assumption overlooks AgentCore Gateway, which acts as a managed MCP server speaking directly to the Web Search capability. The index backing it spans tens of billions of documents, fully managed, and gated by IAM Identity Center or SAML-compatible IdPs.\n\nMore importantly, the gateway enforces JWT-based inbound auth — each request gets validated before reaching the search target. That means you don’t need to embed tokens in local configs or trust ambient credentials floating around dev machines.\n\n## How the auth chain fits together\n\nEnterprises already on AWS IAM Identity Center get a clean integration point: users authenticate once via SAML, Cognito federates that session into short-lived JWTs, and the AgentCore Gateway consumes those tokens as proof of identity.\n\nSequence-wise:\n\n1. User initiates search from Claude Desktop.\n2. Request hits the gateway endpoint over HTTPS.\n3. Gateway inspects the JWT header and signature against the Cognito-issued key set.\n4. On validation success, it forwards the query to the Web Search target.\n5. Results return through the same path back to Claude Desktop.\n\nNo hardcoded secrets, no long-lived keys stored on disk — just standard OAuth flows wrapped inside AWS infrastructure.\n\n## Setting up the connection\n\nStart by enabling the Web Search target in your AgentCore project. You'll register a new MCP-compatible server pointing at the gateway URL assigned during deployment. From there, configure Claude Desktop’s managed MCP server settings to reference that endpoint along with the required JWT issuer and audience claims.\n\nAuthentication setup involves creating a Cognito user pool tied to your IAM Identity Center directory, then exporting the public keys used for signing incoming tokens. Those values go into the gateway's trust policy so it knows which issuers to accept.\n\n## When this breaks (and how to spot it)\n\nIf the gateway rejects requests, check two things first: time drift on your machine and expired client secrets in Cognito. Both cause silent failures — the search simply returns empty rather than throwing errors. Also confirm the JWT audience matches exactly what the gateway expects; mismatched scopes silently drop payloads.\n\nAnother common snag: misconfigured redirect URIs in the Cognito app client. Even a trailing slash mismatch causes login loops without clear error messages.\n\n## Is it worth adopting?\n\nFor organizations already invested in AWS identity services, yes. The overhead of stitching together separate SSO, search, and gateway layers disappears when everything lives under one IAM-aligned roof. Smaller teams or those outside AWS ecosystems might find lighter-weight options faster, but for compliance-heavy environments where data locality matters, this closes a real gap with minimal moving parts.\n\nJust remember: this isn't plug-and-play. Expect an afternoon of config tuning around token lifetimes, scope mapping, and testing edge cases like revoked sessions mid-conversation. But once wired correctly, you get secure, auditable web access baked into your Claude workflow without touching external APIs.\n\n[Next Bearbits lets you use an AI copilot during the meeting instead of just reading a summary after →](https://promptcube3.com/en/threads/9778/)\n\n## All Replies （0）\n\nWant a live back-and-forth? [Join the global AI chat room](https://promptcube3.com/en/chat/) — login to talk.\n\nNo replies yet — be the first!", "url": "https://wpnews.pro/news/secure-web-search-for-claude-desktop-via-bedrock-agentcore", "canonical_source": "https://promptcube3.com/en/threads/9779/", "published_at": "2026-10-04 17:27:04+00:00", "updated_at": "2026-10-04 17:43:02.836311+00:00", "lang": "en", "topics": ["ai-agents", "agent-protocols", "ai-tools", "ai-infrastructure"], "entities": ["Amazon Bedrock AgentCore", "Claude Desktop", "Amazon Web Services", "AWS IAM Identity Center", "Amazon Cognito", "MCP", "SAML"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/secure-web-search-for-claude-desktop-via-bedrock-agentcore", "markdown": "https://wpnews.pro/news/secure-web-search-for-claude-desktop-via-bedrock-agentcore.md", "text": "https://wpnews.pro/news/secure-web-search-for-claude-desktop-via-bedrock-agentcore.txt", "jsonld": "https://wpnews.pro/news/secure-web-search-for-claude-desktop-via-bedrock-agentcore.jsonld"}}