Concepts

Glossary

Terms used across the four projects and the Amazon Bedrock AgentCore services they build on, with the meaning each project gives a term where the meanings differ.

The four projects were written by different teams at different times, so the same word can name different things. MCP Gateway names several products. Registry has more than one implementation. LiteLLM plays more than one role. Self-service is a product in one folder and a way of running the workshop in another. Where a project uses a term in its own way, that meaning is listed under the term with a link to the file it comes from.

A

Advisory mode (RBAC)

In the Self-Service platform, scope-based RBAC ships with RBAC_ENFORCE=false: every request is allowed and a would-be denial is logged and counted as a CloudWatch WouldDeny metric until you switch to enforce. (source (opens in new tab))

Agent Registry versus AgentCore Registry

The same AWS service under two names. The workshop calls it AgentCore Registry; the root README and the Blueprint call it AWS Agent Registry. The service-linked role and the GA service namespaces use agent-registry. Issue #29 tracks the Blueprint move from the preview bedrock-agentcore-control APIs, whose support ended on 2026-09-17, to the GA APIs. (source (opens in new tab))

See also: Registry

AgentCore Gateway

The AgentCore service that exposes tools (Lambda, OpenAPI, Smithy, MCP servers) and, in the Blueprint, inference targets behind one authenticated endpoint. It appears as both the LLM Gateway and the Tool Gateway reference implementation. (source (opens in new tab))

See also: Tool Gateway (Tools Gateway), LLM Gateway

AgentCore Identity

Workload identity and token brokerage for agents. Paired with Cognito M2M in the Blueprint to obtain short-lived, audience-bound credentials. (source (opens in new tab))

AgentCore Memory

The managed memory service in AgentCore. The Blueprint uses actor-scoped events with customer-managed KMS keys; the Self-Service canvas exposes it as a Memory node. (source (opens in new tab))

AgentCore Runtime

The managed execution service for agents in Amazon Bedrock AgentCore. The Blueprint contract requires an immutable deployable revision, workload identity, isolation, health, scaling, logs, safe update and rollback. (source (opens in new tab))

Amazon Bedrock Guardrails

A managed Bedrock capability that filters prompts and responses for prompt attacks, harmful content and PII. Used here on tool traffic, not only on model calls.

See also: Interceptor (request and response)

Application Inference Profile

A Bedrock resource that tags model invocations so usage and cost can be attributed per application or tenant. The Blueprint creates them per tenant. (source (opens in new tab))

C

Capability contract

The outcomes and controls that any chosen implementation of a capability must preserve, regardless of product. Alternatives are valid when the contract holds. (source (opens in new tab))

See also: Support envelope

Cedar

An open-source policy language for permit and forbid rules over principals, actions and resources. Three of the four projects express tool authorization in Cedar. (source (opens in new tab))

  • LearnWorkshopModule 3b Part C (optional) creates a Policy Engine and Cedar policies and attaches it in LOG_ONLY mode, because ENFORCE would empty tools/list in that setup. (source (opens in new tab))
  • BuildSelf-ServiceA Policy node in ENFORCE mode builds a permit over the allowed tools against the gateway manifest; forbidden tools are denied by omission and hidden from tools/list. (source (opens in new tab))
  • GovernMCP GatewayOne CfnPolicy per Cedar statement on an AgentCore policy engine in ENFORCE. The principal type is AgentCore::OAuthUser and JWT claims become principal tags. (source (opens in new tab))
  • ScaleBlueprintAgentCore PolicyEngine plus a retained Lambda Cedar wrapper that stays as a rollback control. (source (opens in new tab))

See also: Policy Engine (AgentCore Policy Engine)

Cognito M2M and CUSTOM_JWT

Machine-to-machine OAuth2 client credentials issued by Amazon Cognito, validated by AgentCore Gateway through its CUSTOM_JWT authorizer. The Workshop Tools Gateway, the Self-Service MCP Gateway and the MCP Gateway use CUSTOM_JWT for callers; the Blueprint uses it only between Runtime and the Inference Gateway and secures its Tool Gateway with AWS_IAM. (source (opens in new tab))

F

FAST (Fullstack AgentCore Solution Template)

An open-source starter template for full-stack agents on Amazon Bedrock AgentCore. Module 4 of the workshop deploys a travel agent with it. (source (opens in new tab))

Fast Path (workshop track only)

Track 1 of the workshop: AI/ML engineers jump straight to Module 4 on a pre-deployed platform, about 1.5 to 2 hours. The term belongs to the workshop; the site-level paths use different names. (source (opens in new tab))

G

Golden path

A versioned, supported starting template for a class of agent (task, chatbot, multi-agent, LangGraph, CrewAI) that delivery teams instantiate instead of assembling infrastructure from scratch. (source (opens in new tab))

I

Interceptor (request and response)

A Lambda function that AgentCore Gateway invokes before a tool call (REQUEST) or after it (RESPONSE) to inspect, block or transform the payload. (source (opens in new tab))

See also: Amazon Bedrock Guardrails

L

LiteLLM

An open-source proxy and SDK that gives one OpenAI-compatible interface to many model providers. The root README lists it as a reference choice that may be substituted if the contracts are preserved. (source (opens in new tab))

  • LearnWorkshopThe LLM Gateway of Module 2: LiteLLM Proxy on ECS Fargate with virtual keys and budgets. (source (opens in new tab))
  • BuildSelf-ServiceBring your own LiteLLM proxy in two optional roles: as the MCP gateway for individual agents, and as the agent catalog behind the Registry. AgentCore Gateway and the built-in registry stay the defaults. (source (opens in new tab))
  • ScaleBlueprintLiteLLMModel is the agent client for AgentCore Gateway inference targets. A self-managed LiteLLM gateway is a valid alternative pattern, and the older ECS LiteLLM path is outside the current envelope. (source (opens in new tab))

See also: LLM Gateway, MCP Gateway

LLM Gateway

Governed access to foundation models with authentication, routing and usage attribution. The root README names AgentCore Gateway inference targets and LiteLLM as reference implementations. (source (opens in new tab))

See also: LiteLLM, AgentCore Gateway

M

MCP (Model Context Protocol)

An open protocol that lets an agent discover and call tools exposed by MCP servers. All four projects use it for tool access; the workshop links the specification from its side navigation. (source (opens in new tab))

See also: MCP Gateway, Tool Gateway (Tools Gateway)

MCP Gateway

A single endpoint that fronts many MCP tool servers so agents connect to one URL. The phrase names four different things in this repository.

  • LearnWorkshopThe open-source MCP Gateway & Registry (Apache-2.0) that Module 3a uses, deployed on Amazon ECS Fargate with Cognito, DocumentDB and Grafana. (source (opens in new tab))
  • BuildSelf-ServiceEither an AgentCore Gateway the platform creates for the selected tools (the default, with Cognito OAuth2) or a customer-run LiteLLM MCP Gateway chosen per agent on the canvas. (source (opens in new tab))
  • GovernMCP GatewayThe project itself: an Amazon Bedrock AgentCore Gateway placed in front of MCP tool servers with JWT authentication, Cedar policies and Lambda interceptors. (source (opens in new tab))
  • ScaleBlueprintThe Tool / MCP Gateway capability, implemented as AgentCore Gateway with AWS_IAM authentication, MCP targets and PolicyEngine integration inside each Workstream cell. (source (opens in new tab))

See also: Tool Gateway (Tools Gateway), Registry, LiteLLM

O

OAM (CloudWatch Observability Access Manager)

CloudWatch cross-account observability. Each Platform and Workstream account creates one OAM source link to the Management sink so logs, metrics and traces can be queried centrally. (source (opens in new tab))

P

Policy Engine (AgentCore Policy Engine)

The AgentCore component that evaluates Cedar policies for each gateway tool call. Attached to a gateway in ENFORCE mode it denies by default; in LOG_ONLY mode it records decisions without blocking. (source (opens in new tab))

See also: Cedar

AWS PrivateLink provides private connectivity through VPC interface endpoints. The two projects that mention it use it in opposite directions.

  • BuildSelf-ServiceAn optional ingress add-on (NLB, VPC endpoint service and security group) shipped as a downloadable CloudFormation template so callers inside a VPC can reach a deployed agent privately. (source (opens in new tab))
  • ScaleBlueprintOutbound: each workload VPC has private-isolated subnets only (no internet gateway, no NAT) and reaches AWS services through required VPC interface endpoints, enforced by SCP-03 and SCP-04. The live-validated Workstream Runtime stack (apps/workload-account/lib/d03-workstream-runtime-memory-stack.ts) sets networkMode PUBLIC; VPC network mode for the Runtime is documented as a follow-on. (source (opens in new tab))

R

Registry

A governed catalog that records ownership, lifecycle state and approval for agents and tools. The root README names AWS Agent Registry as the reference implementation. (source (opens in new tab))

  • LearnWorkshopTwo registries: the open-source MCP Registry in Module 3a, and the AgentCore Registry in Module 3b with a Publisher and Admin approval workflow. (source (opens in new tab))
  • BuildSelf-ServiceA built-in DynamoDB agent registry with an approval workflow, versioning and rollback. A LiteLLM proxy can optionally become the authoritative catalog. (source (opens in new tab))
  • GovernMCP GatewayNone. The gateway governs individual tool calls in the request path and positions itself a layer below platforms that manage which agents and servers exist. (source (opens in new tab))
  • ScaleBlueprintAWS Agent Registry with approved governance records that drive Gateway targets. (source (opens in new tab))

See also: Agent Registry versus AgentCore Registry

S

SCP (service control policy)

An AWS Organizations policy that sets the maximum permissions for accounts in an organizational unit. The Blueprint ships 12; the workshop offers one optional region-fence SCP for self-hosted hardening.

Self-Service versus self-paced

Two different things. Self-Service is the project name for the AgentCore Visual Workflow Platform. Self-paced is the way of running the workshop in your own account instead of at an AWS event. The workshop's deploy script is nevertheless named self-service-deploy.sh and its setup page is titled Self-Paced Setup.

Strands Agents

An open-source agent SDK used to write the agents themselves across the projects.

Support envelope

The exact set of tested implementations, regions and configurations a project stands behind. Replacements and other regions need independent validation. (source (opens in new tab))

See also: Capability contract

T

Tool Gateway (Tools Gateway)

The capability that authenticates MCP discovery and invocation and applies policy per tool call. The root README names AgentCore Gateway as the reference implementation: AWS_IAM in the Blueprint, and a Cognito JWT authorizer in the Workshop, Self-Service and MCP Gateway. (source (opens in new tab))

See also: MCP Gateway, AgentCore Gateway

W

Workshop Studio

The AWS platform that builds and publishes workshops and, at AWS events, provisions a pre-configured account per participant with the scoped WSParticipantRole. (source (opens in new tab))

Workstream cell

The Blueprint unit of scale: an isolated, team-owned execution boundary with its own Runtime, Memory, Tool Gateway, tools, data and pipeline, created from a shared baseline. (source (opens in new tab))