AWS has published a reference implementation for connecting Claude Desktop on Amazon Bedrock to its managed Web Search capability through Amazon Bedrock AgentCore Gateway. For organizations using Claude Desktop with Bedrock, the design provides a route to current web results through an enterprise-managed identity flow rather than relying solely on a model’s knowledge cutoff.
The post is an implementation guide, not a Claude Desktop product release. It uses Claude Desktop managed MCP servers to reach an AgentCore Gateway with the Web Search target enabled. AWS describes Web Search as a fully managed, MCP-compatible capability backed by an Amazon web index spanning tens of billions of documents; AWS says query traffic remains within AWS infrastructure and does not require external API keys.
How the identity chain works
AWS’s example begins with IAM Identity Center as the single sign-on source. IAM Identity Center authenticates the user through SAML, while Amazon Cognito serves as a federation layer in an OAuth 2.0 authorization-code flow. Cognito then issues JSON Web Tokens, and the AgentCore Gateway validates those JWTs on each request.
That division matters operationally: the Gateway is configured with a custom JWT authorizer using the Cognito user pool’s OpenID Connect discovery URL and the Cognito application client ID. AWS says this lets Claude Desktop invoke Web Search through a trusted, enterprise-managed identity flow without separate credentials or a third-party identity provider in the illustrated setup.
What administrators configure
The walkthrough has administrators create a Cognito user pool to act as the token issuer, then create a SAML application in IAM Identity Center and assign the users or groups permitted to use Web Search. The Identity Center metadata is registered as a SAML identity provider in Cognito, and a Cognito application client is created with a client secret for Claude Desktop’s OAuth flow.
AWS’s gateway example also creates an IAM execution role. Its policy allows the gateway to retrieve gateway and configuration-bundle information and invoke the managed Web Search tool. The gateway is created with the MCP protocol, a custom JWT authorizer, and the managed Web Search connector target using the gateway’s IAM role. The sample waits for the gateway to reach a READY state before attaching that target.
In Claude Desktop, the guide calls for a Streamable HTTP server connection using the gateway resource URL and a bring-your-own OAuth client. The configuration uses the Cognito authorization server, the openid scope, and a localhost callback on port 53280. On sign-in, the browser redirects the user to IAM Identity Center SSO; successful authentication returns the user to Claude Desktop, according to AWS.
Availability and prerequisites
AWS lists AgentCore Web Search availability in US East (N. Virginia), Europe (Ireland), and Asia Pacific (Tokyo): us-east-1, eu-west-1, and ap-northeast-1. The guide says the gateway must be created in one of those Regions.
The implementation has meaningful setup requirements. AWS lists an account able to create IAM roles and AgentCore resources, administrative access to the AWS Organizations management account for the Identity Center configuration, and an existing Identity Center SSO deployment. It also requires Claude Desktop configured to use Bedrock, AWS CLI v2, Python 3.10 or later, and an up-to-date Boto3 SDK.
Validation and controls
After registration, Claude Desktop discovers the WebSearchTool through the MCP tools/list call and can invoke it when current web information is needed, AWS says. The documented test flow displays the proposed query in an approval dialog, where the user can deny it, allow it once, or allow it for the task. Results are incorporated into the response only after approval.
The pattern is not limited to IAM Identity Center, AWS says: another SAML- or OIDC-compatible identity provider can be used as a Cognito federation source. Organizations following the guide must also clean up the resources they create, including the gateway target and gateway, the IAM policy and role, Cognito client, provider, domain and user pool, plus the Identity Center SAML application.
Source: AWS Machine Learning Blog
Definition. The design connects Claude Desktop to Amazon Bedrock AgentCore Web Search through an MCP gateway protected by Cognito-issued JWTs and IAM Identity Center SSO.
| Component | Role in the documented flow |
|---|---|
| IAM Identity Center | Authenticates users through SAML and controls assigned users or groups. |
| Amazon Cognito | Federates the identity flow, issues JWTs, and supplies the OAuth client configuration. |
| AgentCore Gateway | Provides the MCP endpoint, validates JWTs, and invokes the managed Web Search target. |
| Claude Desktop | Connects to the gateway through Streamable HTTP and requests user approval for searches. |
Key takeaways
- Claude Desktop connects to AgentCore Web Search through an AgentCore Gateway using managed MCP servers.
- IAM Identity Center provides SAML-based sign-in, while Amazon Cognito issues JWTs for the OAuth 2.0 authorization-code flow.
- The gateway validates JWTs with a custom authorizer configured from Cognito’s OpenID Connect discovery URL and application client ID.
- The documented flow requires user approval before a proposed web-search query is used.
- AgentCore Web Search is listed for us-east-1, eu-west-1, and ap-northeast-1, where the gateway must be created.
FAQ
How does Claude Desktop access Web Search in this design?
Claude Desktop uses a Streamable HTTP MCP server connection to an AgentCore Gateway with the managed Web Search target enabled.
Which services handle authentication and token validation?
IAM Identity Center authenticates users through SAML, Amazon Cognito acts as the federation layer and issues JWTs, and the AgentCore Gateway validates JWTs on requests.
Does the documented test flow require approval for searches?
Yes. The guide says Claude Desktop displays the proposed query and lets the user deny it, allow it once, or allow it for the task.
Where is AgentCore Web Search available according to the guide?
AWS lists US East (N. Virginia), Europe (Ireland), and Asia Pacific (Tokyo): us-east-1, eu-west-1, and ap-northeast-1.