# Amazon — Implementing defense-in-depth authorization for MCP tools on Amazon Quick

- Company: Amazon (amazon.com)
- Announced: 2026-09-17T15:30:17+00:00
- Category: not stated
- Coverage: not counted
- Announcement: no
- Group: routine
- Source: https://aws.amazon.com/blogs/machine-learning/implementing-defense-in-depth-authorization-for-mcp-tools-on-amazon-quick/
- Record: https://forck.live/items/11731-implementing-defense-in-depth-authorization-for-mcp-tools-on-amazon-quick
- Subject: Bedrock / Nova

Amazon's guide covers implementing a multi-gate authorization pattern for MCP tools on Amazon Quick, using OpenID Connect JWT claims to enforce role-based and attribute-based access control on each invocation. The pattern evaluates four gates: MFA, geographic restriction, group-to-role mapping, and tool-level permission checks, with Microsoft Entra ID as the identity provider. The walkthrough configures the identity layer and connects Amazon Quick to an existing Amazon Bedrock AgentCore Gateway.

## Evidence

Verbatim from https://aws.amazon.com/blogs/machine-learning/implementing-defense-in-depth-authorization-for-mcp-tools-on-amazon-quick/:

> In this blog post, you implement a multi-gate authorization pattern that evaluates OpenID Connect (OIDC) JSON Web Token (JWT) claims in sequence. The pattern enforces role-based and attribute-based access control on each invocation.

---

Record: https://forck.live/items/11731-implementing-defense-in-depth-authorization-for-mcp-tools-on-amazon-quick
Catalogue: https://forck.live/llms.txt
Current issue: https://forck.live/feed.md
