Add secure Web Search to Claude Desktop with Amazon Bedrock AgentCore

AWS published a walkthrough for adding Web Search to Claude Desktop on Amazon Bedrock by connecting it to an Amazon Bedrock AgentCore Gateway with the Web Search target enabled, secured with JSON Web Token (JWT)-based inbound authentication.
The post states that Claude Desktop on Amazon Bedrock is limited to the model's training knowledge cutoff without integrated web search, and that AgentCore Gateway can close that gap. Web Search is described as a fully managed, Model Context Protocol (MCP)-compatible capability backed by an Amazon web index spanning tens of billions of documents. According to the post, all query traffic stays within AWS infrastructure, with no external API keys to manage and no queries leaving the customer boundary.
The authentication chain uses AWS IAM Identity Center as the authentication source, Amazon Cognito as a federation layer with the OAuth 2.0 authorization code grant flow, and SAML for user authentication. Cognito issues JWTs and the AgentCore Gateway validates them on each request. The post says the entire chain stays within AWS, requires no separate credentials or third-party identity providers, and aligns with existing organizational identity governance.
The walkthrough covers prerequisites, including an AWS account with permissions to create IAM roles and Amazon Bedrock AgentCore resources, admin access to the AWS Organizations management account, preconfigured IAM Identity Center SSO, Claude Desktop with Amazon Bedrock as the inference provider, AWS CLI v2, Python 3.10 or later, and an updated Boto3 SDK.
Steps include creating an Amazon Cognito user pool and domain, configuring an IAM Identity Center SAML application, registering IAM Identity Center as a SAML identity provider in Cognito, creating a Cognito app client with a client secret, and creating the AgentCore Gateway with JWT inbound auth and the managed Web Search connector target. The final step configures Claude Desktop with a streamable HTTP connector, OAuth bring-your-own-client, localhost callback on port 53280, and the openid scope.
The post states Web Search on Amazon Bedrock AgentCore is currently available in US East (N. Virginia) us-east-1, Europe (Ireland) eu-west-1, and Asia Pacific (Tokyo) ap-northeast-1. It also notes the same pattern works with any SAML or OIDC-compatible identity provider by configuring it as a federation source in Amazon Cognito.
Based on reporting from the original publisher. Visit the source for full context and later updates.
Publisher excerpt
Claude Desktop on Amazon Bedrock is limited to the model's knowledge cutoff without web search. In this post, we walk through connecting Claude Desktop to Web Search using Amazon Bedrock AgentCore Gateway, with JWT-based inbound authentication through AWS IAM Identity Center and Amazon Cognito.