From the source
Lead story
Top stories
Models & availability
Latest
Lead story
Top stories
Models & availability
Latest
From the source
Adds multi-gate authorization for MCP tools enforcing role-based and attribute-based access control.
Amazon's guide covers implementing a multi-gate authorization pattern for MCP tools on Amazon Quick, using OpenID Connect JWT claims to enforce role-based and attribute-based access control on each invocation.
The pattern evaluates four gates: MFA, geographic restriction, group-to-role mapping, and tool-level permission checks, with Microsoft Entra ID as the identity provider.
The walkthrough configures the identity layer and connects Amazon Quick to an existing Amazon Bedrock AgentCore Gateway.
From the source
In this blog post, you implement a multi-gate authorization pattern that evaluates OpenID Connect (OIDC) JSON Web Token (JWT) claims in sequence. The pattern enforces role-based and attribute-based access control on each invocation.
aws.amazon.com