Skip to content
context AI agents

Amazon Bedrock AgentCore Identity adds Private Key JWT authentication with keys in AWS KMS

only one source so far

Amazon Bedrock AgentCore Identity now supports Private Key JWT authentication – agents authenticate using a signed JWT with a key stored in AWS KMS instead of a shared OAuth client secret, improving the security of access to internal APIs.

Amazon Bedrock AgentCore Identity now supports Private Key JWT client authentication. This allows agents to authenticate to the token endpoint of an identity provider using a signed JSON Web Token (JWT) instead of a shared OAuth 2.0 client secret. The public key is registered with the identity provider, while the corresponding private key remains stored in AWS Key Management Service (KMS) and never leaves it – during authentication, AgentCore Identity calls AWS KMS to sign the JWT assertion and then sends the signed assertion to the identity provider, which verifies it using the registered public key.

According to Amazon, this authentication method works with three types of grant flow: machine-to-machine (the agent acts on its own behalf using the client_credentials grant), on-behalf-of (the agent acts on behalf of a specific user by exchanging their existing token according to RFC 8693 or RFC 7523), and user-delegated access (the user grants consent to the agent interactively through the authorization code grant). In all cases, the agent authenticates to the identity provider using a client assertion signed with a key from KMS.

The article also describes the setup process through AWS Management Console: creating an asymmetric signing key in KMS (the example uses the ECC_NIST_P256 specification with the ES256 algorithm), registering the public key with the identity provider, and configuring the credential provider. It also lists the IAM permissions required for the individual steps (kms:CreateKey, kms:PutKeyPolicy, kms:GetPublicKey, potentially kms:GetParametersForImport and kms:ImportKeyMaterial when importing an existing key, and bedrock-agentcore-control:CreateOauth2CredentialProvider).

Details on further setup steps and examples of records in AWS CloudTrail can be found in the source article.

What changed

Why it matters

Shared client secret keys for OAuth authentication are a common security risk – they can be leaked, copied, or mismanaged. By moving the private key into AWS KMS, where it never leaves the service, and using signed JWT assertions instead of a static secret, companies running AI agents on AWS reduce the risk of access to internal APIs being compromised while also gaining an audit trail in AWS CloudTrail to check when and how the agent accessed data.

Two audiences, two different impacts

What this means

01

For individuals

Developers building agents on AWS can use a signed JWT with a key in AWS KMS when configuring authentication to external APIs, instead of managing and rotating a shared client secret.

What to do Developers working with Amazon Bedrock AgentCore can check the documentation to see which signing algorithm (RS256, PS256, ES256) their identity provider requires and configure the KMS key accordingly.
More practical updates →
02

For a business

Companies running AI agents on Amazon Bedrock AgentCore can replace shared OAuth client secret keys, which can be leaked or misused, with authentication based on a private key stored in AWS KMS, reducing the risk of credentials for internal APIs being compromised and making access easier to audit through AWS CloudTrail.

Risks and compliance
What to decide If the company uses Amazon Bedrock AgentCore for agents accessing internal APIs, consider migrating existing OAuth client secret configurations to Private Key JWT with a key in AWS KMS.
More business impacts →
Amazon Bedrock authentication AWS AWS KMS cloud infrastructure JWT

Check the original

Event sources

only one source so far · 1 publisher, 0 independent. We count feeds from the same owner only once.

1
AWS Machine Learning Blog primary source · first detected Authenticate with Private Key JWT using Amazon Bedrock AgentCore Identity