Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

Amazon Bedrock AgentCore vs DIY: a managed AWS platform or an in-house build

Amazon Bedrock AgentCore

AWS platform for building, deploying, and operating AI agents

Build it yourself (DIY)

Building agent connections and controls in-house from open protocols, existing infrastructure, and open-source tools

Short answer

Amazon Bedrock AgentCore is a product: AWS’s managed platform for building, deploying, and operating agents, made of modular services you can use together or independently.⁠Source 1 DIY is not a product: your teams connect and govern agents themselves, on open protocols such as MCP and A2A that leave authorization logic to the implementer.⁠Source 2, Source 3

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
AgentCore Runtime hosts agents written with frameworks such as LangGraph and Google ADK, and can host MCP and A2A servers, open protocols a DIY build can also use.⁠Source 2, Source 4, Source 5
Where they differ
AgentCore runs in AWS Regions.⁠Source 6 A self-hosted edition is not publicly documented. DIY runs where you put it, assembled from parts such as Istio and LangGraph.⁠Source 7, Source 8
Running both
AWS says AgentCore’s services work independently, its Registry works with agents on premises or in other clouds, and Identity with self-hosted ones.⁠Source 1, Source 9
Public sources · checked 2 October 2026
  • Offered
  • You build it

Amazon Bedrock AgentCore

  • Build agents: OfferedHarness managed agent loop⁠Source 1
  • Host and run agents: OfferedAgentCore Runtime⁠Source 1
  • Identity and access: OfferedAgentCore Identity workload identities⁠Source 10
  • Registry and governance: OfferedAWS Agent Registry with approvals⁠Source 11
  • Traffic between agents, tools, and models: OfferedAgentCore Gateway⁠Source 12
  • Agents across organizations: OfferedRegistry shared through AWS RAM⁠Source 13

DIY

  • Build agents: You build itOpen-source frameworks like ADK⁠Source 14
  • Host and run agents: You build itSelf-hosted, like LangGraph⁠Source 8
  • Identity and access: You build itYour own identity provider⁠Source 15
  • Registry and governance: You build itYour own agent registry⁠Source 16
  • Traffic between agents, tools, and models: You build itYour gateway and service mesh⁠Source 17
  • Agents across organizations: You build itA2A with API management⁠Source 18

At a glance

TopicAmazon Bedrock AgentCoreDIY
What it isAWS’s managed platform for building, deploying, and operating agents with any framework and foundation model.⁠Source 1Agents connected and governed in-house, on open protocols such as A2A and MCP, which the A2A specification calls complementary.⁠Source 2
Who operates itAWS: AgentCore runs without infrastructure for you to manage.⁠Source 1 A self-hosted edition is not publicly documented.Your teams: Uber, for example, runs its own MCP registry as a control plane and a proxy gateway as a data plane.⁠Source 17
Agent registryAWS Agent Registry, generally available since August 2026.⁠Source 11, Source 19 Consumers see only records approved through its workflow.⁠Source 20Build your own: A2A prescribes no standard API for curated registries, and the official MCP Registry is in preview and does not support private servers.⁠Source 16, Source 21
Identity and accessAgent identities are workload identities.⁠Source 10 Calls to hosted agents use IAM SigV4 by default, or JWTs from any OAuth 2.0 identity provider.⁠Source 22, Source 23Yours to design: A2A calls authorization logic implementation-specific, and MCP makes authorization optional.⁠Source 2, Source 24
PricingConsumption-based, per service used, with no upfront commitment or minimum fee.⁠Source 25 AWS Agent Registry has a monthly free tier.⁠Source 25The A2A and MCP specifications are openly licensed.⁠Source 2, Source 26 Build and running costs are not publicly documented.

What each one is

Amazon Bedrock AgentCore

Amazon Bedrock AgentCore is AWS’s platform for building, deploying, and operating agents with any framework and foundation model.⁠Source 1 Its modular services, usable together or independently, include a serverless Runtime for hosting agents, Gateway, Identity, Policy, Observability, and AWS Agent Registry.⁠Source 1, Source 6, Source 11, Source 27, Source 28

Build it yourself (DIY)

DIY means connecting and governing agents without buying an agent platform: open protocols wired together in-house, existing infrastructure stretched to cover agents, an in-house platform, self-hosted open-source frameworks, or no central approach; Uber, for one, built its own MCP registry and proxy gateway.⁠Source 17

The differences that matter

  1. Agent registry

    Amazon Bedrock AgentCore

    AWS Agent Registry can list agents, MCP servers, tools, and skills behind an approval workflow, and has been generally available since August 2026.⁠Source 11, Source 19

    DIY

    A2A’s specification prescribes no standard API for curated registries, and its docs say one requires deploying and maintaining a registry service.⁠Source 16

    The official MCP Registry, in preview, doesn’t support private servers; Uber and Pinterest run their own.⁠Source 17, Source 21, Source 29 With AWS Organizations, Agent Registry can currently auto-detect only AgentCore Runtimes and Gateways.⁠Source 30

  2. Identity and policy

    Amazon Bedrock AgentCore

    Agent identities are workload identities, and Policy can check each request through a Gateway before tool access, using rules in natural language or Cedar.⁠Source 10, Source 27

    DIY

    A2A leaves authorization logic to each server and MCP makes it optional; Uber’s gateway applies policies from its internal Access Control System.⁠Source 2, Source 17, Source 24

    MCP’s roadmap says MCP authorization assumes a person with a browser at consent time.⁠Source 31

  3. Sharing across accounts and companies

    Amazon Bedrock AgentCore

    A registry can be shared with other AWS accounts through AWS RAM; accounts outside your AWS Organization must accept an invitation.⁠Source 13

    DIY

    A2A is designed for agents built by different companies on separate servers; each server authorizes requests under its own policies.⁠Source 2, Source 32

    AWS says its record-level condition keys don’t apply to registry search and list, which return summaries of all matching records.⁠Source 13

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicAmazon Bedrock AgentCoreDIY
Network exposureGateway can forward requests to an external agent’s endpoint URL.⁠Source 12 VPC callers can reach AgentCore over PrivateLink.⁠Source 33MCP servers on Streamable HTTP expose an HTTP endpoint; A2A agents declare a URL, HTTPS in production for HTTP-based transports.⁠Source 2, Source 34
IdentityAgent identities are workload identities.⁠Source 10 Runtime accepts IAM SigV4 by default, or JWTs from Cognito, Entra ID, Okta, and others.⁠Source 6, Source 22, Source 23In A2A, identity is established at the HTTP layer.⁠Source 18 Keycloak’s MCP authorization support is Experimental (in preview) from MCP 2025-06-18.⁠Source 15
Access changes and revocationExplicit deny policies can block Runtime, Gateway, and Memory access; removing an account from a registry share revokes its access.⁠Source 13, Source 35Built per server: each A2A server authorizes requests under its own policies, using implementation-specific logic.⁠Source 2
Audit trailCloudTrail can log Gateway API calls and logs Registry control-plane calls; Policy logs its decisions.⁠Source 27, Source 30, Source 36 Telemetry is OpenTelemetry-compatible.⁠Source 28A2A docs advise auditing task creation, critical state changes, and agent actions, plus distributed tracing.⁠Source 18
ComplianceAWS lists AgentCore as FedRAMP (Class C and Class D), SOC 2, ISO, and CSA STAR compliant, and HIPAA eligible.⁠Source 37, Source 38Sits with the implementer: A2A’s guidance says to ensure GDPR, CCPA, and HIPAA compliance where relevant.⁠Source 18

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Amazon Bedrock AgentCore and DIY compared on 18 criteria
Amazon Bedrock AgentCoreDIY
What it is
What it is and who it’s forAWS’s platform for building, deploying, and operating agents with any framework and model, for moving agents from proof of concept to production.⁠Source 1, Source 6An in-house build on open protocols: A2A, an open standard for communication between agent systems, and MCP, which A2A calls complementary.⁠Source 2
MaturityGenerally available since October 2025.⁠Source 19 Policy GA in March 2026; AWS Agent Registry GA in August 2026.⁠Source 19Varies by part: MCP’s latest specification revision is 2026-07-28.⁠Source 3 The official MCP Registry is in preview.⁠Source 21
Control
Agent registry and discoveryAWS Agent Registry can list agents, MCP servers, tools, and skills behind an approval workflow, including ones on premises or in other clouds.⁠Source 1, Source 11Build your own: A2A sets no standard API for curated registries.⁠Source 16 The MCP Registry, in preview, recommends your own for private servers.⁠Source 21
Identity and access controlAgent identities are workload identities.⁠Source 10 Hosted agents take IAM SigV4 by default, or JWTs from any OAuth 2.0 provider.⁠Source 22, Source 23 Policy can check Gateway traffic.⁠Source 27In A2A, identity is established at the HTTP layer, and authorization logic is implementation-specific.⁠Source 2, Source 18 MCP authorization is optional.⁠Source 24
Ownership, policy, and revocationGateway policies, in natural language or Cedar, set which tools an agent may call and when.⁠Source 27 One control to disable an agent everywhere: not publicly documented.MCP leaves consent and authorization flows to implementers.⁠Source 3 Uber starts MCP servers and tools disabled; Pinterest gives non-experimental servers an owning team.⁠Source 17, Source 29
Audit log and observabilityMetrics, spans, and logs go to CloudWatch, OpenTelemetry-compatible.⁠Source 28 CloudTrail can log Gateway API calls and logs Registry control-plane calls.⁠Source 30, Source 36A2A docs advise auditing significant events and tracing, for example with OpenTelemetry.⁠Source 18 Pinterest’s MCP servers log inputs, outputs, and exceptions.⁠Source 29
Connection
How agents connectAgents can run in serverless Runtime, or elsewhere behind a Gateway that can forward to their endpoint URL.⁠Source 1, Source 12 Outbound-only connections: not publicly documented.MCP servers on Streamable HTTP expose an HTTP endpoint; A2A agents declare a URL.⁠Source 2, Source 34 A standard outbound-only binding: not publicly documented.
Agents across organizationsA registry can be shared with other AWS accounts via AWS RAM to discover, publish, or administer.⁠Source 13 Runtime agents can be opened to principals in other accounts.⁠Source 35A2A is designed for agents from different companies on separate servers.⁠Source 32 Its docs highly recommend API management across organizations.⁠Source 18
Protocol supportRuntime agents can serve HTTP, MCP, A2A, or AG-UI.⁠Source 5 Gateway supports MCP 2025-03-26, 2025-06-18, 2025-11-25, and 2026-07-28 for MCP targets.⁠Source 39MCP defines stdio and Streamable HTTP transports and allows custom ones.⁠Source 40 A2A maps to JSON-RPC, gRPC, and HTTP/REST bindings.⁠Source 2
Frameworks, models, and clouds supportedRuntime works with CrewAI, LangGraph, LlamaIndex, Google ADK, OpenAI Agents SDK, Strands Agents, and custom frameworks.⁠Source 1A2A gives agents built on different frameworks, languages, or vendors a common language.⁠Source 2 Google’s ADK says it is deployment-agnostic.⁠Source 14
Operations
Deployment options and data residencyAWS says cross-region inference can move Memory, Policy, and Evaluations prompts out of the primary Region; AgentCore may store content to improve your service.⁠Source 1, Source 41Wherever you run it: Pinterest optimized for MCP servers in its internal cloud.⁠Source 29 A2A leaves protecting stored data to your policies.⁠Source 18
Compliance attestationsAWS lists AgentCore as FedRAMP (Class C and Class D) compliant.⁠Source 37, Source 38 In scope for SOC 1, 2, and 3 reports; ISO and CSA STAR compliant; HIPAA eligible.⁠Source 19, Source 37Sits with the implementer: A2A docs name GDPR, CCPA, and HIPAA; MCP leaves access controls and data protections to implementers.⁠Source 3, Source 18
Support and SLAAWS says the Amazon Bedrock SLA applies to AgentCore.⁠Source 6 Basic Support is included for all AWS customers.⁠Source 42Depends on the component: MCP SDKs are tiered partly by maintenance commitments; the official MCP Registry, in preview, gives no uptime guarantees.⁠Source 43, Source 44
Time and effort to get runningAWS’s quickstart scaffolds, tests, and deploys one agent with the AgentCore CLI.⁠Source 4 It needs an AWS account and Node.js 20 or later.⁠Source 4A curated A2A registry is a service you deploy and maintain.⁠Source 16 Pinterest built a unified deployment pipeline after new MCP servers took too much setup.⁠Source 29
Pricing model and public pricesConsumption-based per service, no minimum fee.⁠Source 25 Examples: Policy $0.000025 per authorization request; Runtime v1 CPU $0.0895 per vCPU-hour.⁠Source 25A2A and MCP are openly licensed specifications, A2A under Apache 2.0.⁠Source 2, Source 26 Build and running costs are not publicly documented.
Building
Agent building toolsWrite the agent loop in Python with a framework such as Strands, LangGraph, or Google ADK and deploy it to Runtime, or use the managed Harness.⁠Source 1, Source 4Open-source frameworks such as LangGraph and Google’s ADK build and deploy agents.⁠Source 8, Source 14 The A2A project hosts SDKs in six languages.⁠Source 45
Model accessModel-agnostic, AWS says: models in or outside Amazon Bedrock, including OpenAI, Gemini, Claude, Nova, Llama, and Mistral.⁠Source 6Your choice per agent: Google’s ADK, for example, is optimized for Gemini and model-agnostic.⁠Source 14
Integrations and ecosystemGateway has 1-click integrations such as Salesforce, Slack, Jira, Asana, and Zendesk, and can import AWS Partner tools bought through AWS Marketplace.⁠Source 6, Source 46The official MCP Registry, in preview, offers a REST API to discover MCP servers and an OpenAPI spec other registries can implement.⁠Source 21

Which to choose

Choose Amazon Bedrock AgentCore if

  • You want hosting, identity, policy, and a registry as managed AWS services you can adopt together or one at a time.⁠Source 1
  • You want a registry with an approval workflow, so builders discover only records that meet your organization’s criteria.⁠Source 11, Source 20
  • Your agents already span AWS accounts, and you want one registry shared through AWS RAM, with record-level controls on reads and writes.⁠Source 13
  • You need vendor attestations: AWS lists AgentCore as HIPAA eligible, in scope for SOC reports, and ISO and CSA STAR compliant.⁠Source 19, Source 37

Choose DIY if

  • You want your own routing and security logic on agent traffic, as Pinterest applies to MCP servers in its internal cloud.⁠Source 29
  • You want access checks from systems you already run, as Uber and Pinterest do with internal access control and mesh identities.⁠Source 17, Source 29
  • You want your own review rules, such as Uber’s: every MCP server and tool starts disabled until reviewed and enabled.⁠Source 17
  • You want no agent platform contract: A2A and MCP are openly licensed specifications you can build on.⁠Source 2, Source 26

Questions buyers ask

Can Amazon Bedrock AgentCore manage agents that run outside AWS?

AWS says its Registry works with agents and MCP servers on premises or in other clouds, and that AgentCore Identity manages identities for self-hosted agents.⁠Source 1, Source 9 Automatic discovery through AWS Organizations can currently create records only for AgentCore Runtimes and Gateways.⁠Source 30

Does Amazon Bedrock AgentCore support MCP and A2A?

Yes. Agents in AgentCore Runtime can serve MCP or A2A, and A2A servers keep Agent Card discovery and JSON-RPC.⁠Source 5, Source 48 For MCP server targets, AgentCore Gateway supports MCP revisions 2025-03-26, 2025-06-18, 2025-11-25, and 2026-07-28.⁠Source 39

Can Amazon Bedrock AgentCore be self-hosted?

A self-hosted or customer-operated edition is not publicly documented. AWS presents AgentCore as a managed service, offered in AWS Regions including AWS GovCloud (US-West).⁠Source 1, Source 6, Source 19 A DIY build runs where you deploy it; A2A’s docs leave protecting its data to your own security policies.⁠Source 18

How do the costs compare?

AgentCore is priced by consumption for each service used, with no upfront commitment or minimum fee; AWS Agent Registry includes a monthly free tier.⁠Source 25 For DIY, the A2A and MCP specifications are openly licensed.⁠Source 2, Source 26 Build and running costs are not publicly documented.

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

53 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Overview - Amazon Bedrock AgentCore (Developer Guide) AWS · checked Back:abcdefghijklmnopqr

  2. Source 2: Agent2Agent (A2A) Protocol Specification a2a-protocol.org · checked Back:abcdefghijklmnopq

  3. Source 3: Specification - Model Context Protocol 2026-07-28 modelcontextprotocol.io · checked Back:abcd

  4. Source 4: Get started with Amazon Bedrock AgentCore AWS · checked Back:abcde

  5. Source 5: Understand the AgentCore Runtime service contract AWS · checked Back:abc

  6. Source 6: Amazon Bedrock AgentCore FAQs AWS · checked Back:abcdefgh

  7. Source 7: Security - Istio concepts istio.io · checked Back to text

  8. Source 8: langchain-ai/langgraph README (GitHub) github.com · checked Back:abc

  9. Source 9: Features of AgentCore Identity AWS · checked Back:ab

  10. Source 10: Provide identity and credential management for agent applications with Amazon Bedrock AgentCore Identity AWS · checked Back:abcde

  11. Source 11: AWS Agent Registry: Discover and manage agents, tools, and resources AWS · checked Back:abcdef

  12. Source 12: HTTP passthrough targets - AgentCore Gateway AWS · checked Back:abcd

  13. Source 13: Sharing a registry across accounts with AWS RAM AWS · checked Back:abcdef

  14. Source 14: google/adk-python README (GitHub) github.com · checked Back:abcd

  15. Source 15: Integrating with Model Context Protocol (MCP) - Keycloak keycloak.org · checked Back:ab

  16. Source 16: Agent Discovery - A2A Protocol a2a-protocol.org · checked Back:abcde

  17. Source 17: Designing MCP Gateway Uber's MCP Management Platform - Uber Blog uber.com · checked Back:abcdefgh

  18. Source 18: Enterprise Features - A2A Protocol a2a-protocol.org · checked Back:abcdefghij

  19. Source 19: Release notes - Amazon Bedrock AgentCore AWS · checked Back:abcdefg

  20. Source 20: Concepts and terminology - AWS Agent Registry AWS · checked Back:ab

  21. Source 21: The MCP Registry - Model Context Protocol modelcontextprotocol.io · checked Back:abcde

  22. Source 22: Authenticate and authorize with Inbound Auth and Outbound Auth AWS · checked Back:abc

  23. Source 23: Configure inbound JWT authorizer AWS · checked Back:abc

  24. Source 24: Authorization - Model Context Protocol specification 2026-07-28 modelcontextprotocol.io · checked Back:abc

  25. Source 25: Amazon Bedrock AgentCore Pricing AWS · checked Back:abcde

  26. Source 26: modelcontextprotocol/modelcontextprotocol LICENSE (GitHub) github.com · checked Back:abcd

  27. Source 27: Policy in Amazon Bedrock AgentCore: Control Agent Interactions AWS · checked Back:abcde

  28. Source 28: Observe your agent applications on Amazon Bedrock AgentCore Observability AWS · checked Back:abc

  29. Source 29: Building an MCP Ecosystem at Pinterest - Pinterest Engineering Blog medium.com · checked Back:abcdefg

  30. Source 30: Key capabilities - AWS Agent Registry AWS · checked Back:abcd

  31. Source 31: Roadmap - Model Context Protocol modelcontextprotocol.io · checked Back to text

  32. Source 32: a2aproject/A2A README (GitHub) github.com · checked Back:ab

  33. Source 33: Use interface VPC endpoints (AWS PrivateLink) with Amazon Bedrock AgentCore AWS · checked Back to text

  34. Source 34: Streamable HTTP - Model Context Protocol specification 2026-07-28 modelcontextprotocol.io · checked Back:ab

  35. Source 35: Resource-based policies for Amazon Bedrock AgentCore AWS · checked Back:ab

  36. Source 36: Log Amazon Bedrock AgentCore Gateway API calls with CloudTrail AWS · checked Back:ab

  37. Source 37: Compliance validation for Amazon Bedrock AgentCore AWS · checked Back:abcd

  38. Source 38: Federal Risk and Authorization Management Program (FedRAMP) - Services in Scope - Amazon Web Services AWS · checked Back:ab

  39. Source 39: MCP servers targets - AgentCore Gateway AWS · checked Back:ab

  40. Source 40: Transports - Model Context Protocol specification 2026-07-28 modelcontextprotocol.io · checked Back to text

  41. Source 41: Cross-region inference in AgentCore Memory, Policy in AgentCore, and AgentCore Evaluations AWS · checked Back to text

  42. Source 42: Compare AWS Support plans AWS · checked Back to text

  43. Source 43: SDK Tiers - Model Context Protocol modelcontextprotocol.io · checked Back to text

  44. Source 44: MCP Registry Aggregators - Model Context Protocol modelcontextprotocol.io · checked Back to text

  45. Source 45: A2A protocol roadmap a2a-protocol.org · checked Back to text

  46. Source 46: Amazon Bedrock AgentCore Gateway: A secure AI gateway for agents, tools, and models AWS · checked Back to text

  47. Source 47: Add observability to your Amazon Bedrock AgentCore resources AWS · checked Back to text

  48. Source 48: Deploy A2A servers in AgentCore Runtime AWS · checked Back to text

  49. Source 49: Your company's private network Blocks.ai · checked Back to text

  50. Source 50: Network requirements Blocks.ai · checked Back to text

  51. Source 51: Solutions: Agent sprawl Blocks.ai · checked Back to text

  52. Source 52: Why Blocks? Blocks.ai · checked Back to text

  53. Source 53: What is Blocks? Blocks.ai · checked Back to text