Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

Amazon Bedrock AgentCore vs Kong AI Gateway

Amazon Bedrock AgentCore

AWS platform for building, deploying, and operating AI agents

Kong AI Gateway

Gateway that governs LLM, MCP, and agent-to-agent traffic

Short answer

Amazon Bedrock AgentCore is AWS’s platform to build, deploy, and operate agents; Kong AI Gateway is a gateway for LLM, MCP, and A2A traffic, proxying to agents registered as upstream URLs.⁠Source 1, Source 2, Source 3 AWS says AgentCore needs no infrastructure management; Kong AI Gateway 2.x pairs a Kong-managed control plane with data plane nodes you run.⁠Source 1, Source 2

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both put a gateway in front of agents and tools that can authenticate callers and check access on each request, and both emit OpenTelemetry-compatible telemetry.⁠Source 2, Source 3, Source 4, Source 5, Source 6, Source 7
Where they differ
AgentCore also helps build agents and hosts them in a serverless runtime.⁠Source 1, Source 8 In 2.x, Kong proxies to agents registered as upstream URLs from data plane nodes you run.⁠Source 2, Source 3
Running both
They can be combined: Kong’s docs describe signing requests with AWS IAM (SigV4) to reach an agent hosted on AgentCore Runtime.⁠Source 3
Public sources · checked 2 October 2026
  • Offered
  • Preview
  • Not publicly documented

Amazon Bedrock AgentCore

  • Build agents: OfferedHarness managed agent loop⁠Source 1
  • Host and run agents: OfferedAgentCore Runtime⁠Source 1
  • Identity and access: OfferedAgentCore Identity workload identities⁠Source 9
  • Registry and governance: OfferedAWS Agent Registry with approvals⁠Source 10
  • Traffic between agents, tools, and models: OfferedAgentCore Gateway⁠Source 5
  • Agents across organizations: OfferedRegistry shared through AWS RAM⁠Source 11

Kong AI Gateway

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedPer-agent allow or deny lists⁠Source 3
  • Registry and governance: PreviewKonnect Catalog agents⁠Source 12
  • Traffic between agents, tools, and models: OfferedGateway for LLM, MCP, A2A⁠Source 13
  • Agents across organizations: Not publicly documented

At a glance

TopicAmazon Bedrock AgentCoreKong AI Gateway
What it isAn AWS platform to build, deploy, and operate agents, made of modular services you can use together or on their own.⁠Source 1A gateway for LLM, MCP, and A2A traffic, with shared authentication, observability, and policy features.⁠Source 2
Where agents runIn serverless AgentCore Runtime, or anywhere reachable over HTTP, behind AgentCore Gateway as passthrough targets.⁠Source 1, Source 5Registered as upstream URLs that the gateway proxies to.⁠Source 3
Who runs itAWS says AgentCore needs no infrastructure management, and calls AWS Agent Registry fully managed.⁠Source 1, Source 10In 2.x, Kong runs the control plane in Konnect, and you run the data plane nodes.⁠Source 2
Pricing modelBy use, with no upfront commitment or minimum fee.⁠Source 14 AWS Agent Registry has a monthly free tier.⁠Source 14AI Management Plus from $25 a month plus usage, and $200 a month per hybrid AI gateway control plane.⁠Source 15 Enterprise is custom, billed annually.⁠Source 15
Generally availableSince October 2025; AWS Agent Registry since August 2026.⁠Source 16Kong announced 2.0 as generally available on 1 September 2026.⁠Source 17 The agent inventory in Konnect Catalog is in beta.⁠Source 12

What each one is

Amazon Bedrock AgentCore

Amazon Bedrock AgentCore is AWS’s platform for building, deploying, and operating agents with any framework and model.⁠Source 1 Its modular services, usable together or alone, include Runtime to host agents, Gateway and Policy for tool access, Identity, Observability, and AWS Agent Registry.⁠Source 1, Source 6, Source 7, Source 9, Source 10

Kong AI Gateway

Kong AI Gateway is one gateway for LLM, MCP, and agent-to-agent (A2A) traffic, with shared authentication, observability, and policy features.⁠Source 2, Source 13 An agent is added as an AI Agent entity, which exposes it at a gateway endpoint and can carry policies.⁠Source 3, Source 18

The differences that matter

  1. Building and hosting agents

    Amazon Bedrock AgentCore

    AgentCore Runtime hosts agents built with any framework, such as LangGraph or Strands Agents; the managed harness defines one from a model, prompt, and tools.⁠Source 1

    Kong AI Gateway

    Kong AI Gateway proxies to agents registered as upstream URLs; Kong says it governs A2A traffic without changing how agents are built.⁠Source 3, Source 19

  2. Agent registry

    Amazon Bedrock AgentCore

    AWS Agent Registry, generally available since August 2026, can list agents, MCP servers, and tools with approvals, including ones on premises or in other clouds.⁠Source 1, Source 10, Source 16

    Kong AI Gateway

    Each AI Agent entity is scoped to one gateway instance; Konnect Catalog’s organization-wide agent inventory is in beta and not for production.⁠Source 2, Source 3, Source 12

    With AWS Organizations, the registry can auto-detect AgentCore Runtimes and Gateways in member accounts; in Konnect Catalog, in beta, agents are added by pasting an A2A card.⁠Source 12, Source 20

  3. Who runs the infrastructure

    Amazon Bedrock AgentCore

    AWS says AgentCore runs agents, governs their tool access, and monitors them without any infrastructure management.⁠Source 1 It is also generally available in AWS GovCloud (US-West).⁠Source 16

    Kong AI Gateway

    In 2.x, Kong runs the control plane in Konnect; you run the data plane nodes, and your traffic never passes through the control plane.⁠Source 2

    Self-hosting AgentCore is not publicly documented. Kong’s docs say 2.x has no fully self-hosted control plane today; fully self-hosted AI gateways are a separate Gateway Enterprise offering.⁠Source 2, Source 15

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicAmazon Bedrock AgentCoreKong AI Gateway
Network exposureGateway reaches agents hosted elsewhere at their endpoint URLs; PrivateLink lets VPC callers reach AgentCore without an internet gateway.⁠Source 5, Source 21In 2.x, your data plane nodes proxy to agents registered as upstream URLs, authenticating to Kong’s control plane over mTLS.⁠Source 2, Source 3
IdentityAgent identities are workload identities.⁠Source 9 Runtime calls use IAM SigV4 by default, or JWTs from an OAuth 2.0 identity provider.⁠Source 22, Source 23Agents can require API key or OpenID Connect (Okta, Azure AD, Google, or any OIDC provider) authentication before routing.⁠Source 3, Source 24
Access changes and revocationAn explicit deny overrides other policies.⁠Source 25 Removing an account from a registry share revokes its registry access.⁠Source 11Each AI Agent has an enabled switch; a Request Termination policy can end an agent’s requests with a set response.⁠Source 3, Source 26, Source 27
Audit trailCloudTrail can log Gateway calls (data events are off by default) and logs Registry control-plane calls; Policy logs its decisions.⁠Source 6, Source 20, Source 28, Source 29A2A audit logs record task IDs, method calls, latencies, and errors; Konnect telemetry omits request bodies unless you opt in.⁠Source 2, Source 30
ComplianceHIPAA eligible; AWS lists it as FedRAMP (Class C and Class D), SOC 2, ISO 27001:2022, and CSA STAR compliant.⁠Source 31, Source 32Kong Inc. lists ISO 27001, SOC 2, PCI DSS, and CSA STAR.⁠Source 33 Which products they cover is not publicly documented.

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Amazon Bedrock AgentCore and Kong AI Gateway compared on 18 criteria
Amazon Bedrock AgentCoreKong AI Gateway
What it is
What it is and who it’s forAWS platform for building, deploying, and operating agents with any framework and model, made of modular services usable together or independently.⁠Source 1Gateway for LLM, MCP, and A2A traffic.⁠Source 2 All three run through one data plane, with shared authentication, observability, and policy features.⁠Source 2
MaturityGenerally available since October 2025.⁠Source 16 Policy followed in March 2026, and AWS Agent Registry in August 2026.⁠Source 16Kong announced AI Gateway in February 2024 and 2.0 as generally available on 1 September 2026.⁠Source 17, Source 34 Konnect Catalog’s agent inventory is in beta.⁠Source 12
Control
Agent registry and discoveryAWS Agent Registry catalogs agents, MCP servers, tools, and skills behind an approval workflow, including ones on premises or in other clouds.⁠Source 1, Source 10Each AI Agent entity is scoped to one gateway instance.⁠Source 2, Source 3 An organization-wide agent inventory in Konnect Catalog is in beta.⁠Source 12
Identity and access controlAgent identities are workload identities in AgentCore Identity.⁠Source 9 Runtime calls use IAM SigV4 by default, or JWTs from any OAuth 2.0 identity provider.⁠Source 22, Source 23An agent can require API key or OpenID Connect authentication before routing, and an allow or deny list enforced before traffic reaches it.⁠Source 3
Ownership, policy, and revocationPolicy can check each Gateway request against rules written in natural language or Cedar.⁠Source 6 Only approved registry records are discoverable.⁠Source 10Policies for agents: input validation, request logging, and rate limits.⁠Source 3 The AI PII Sanitizer covers model requests: a Plus add-on, included on Enterprise.⁠Source 15, Source 35
Audit log and observabilityCloudTrail can log Gateway calls (data events are off by default) and logs Registry control-plane calls.⁠Source 20, Source 28, Source 29 Policy logs its decisions.⁠Source 6A2A audit logs record task IDs, method calls, latencies, and errors.⁠Source 30 Konnect audit logs (Enterprise): webhook delivery, kept 7 days in Konnect.⁠Source 15, Source 36
Connection
How agents connectAgents can run in serverless AgentCore Runtime.⁠Source 1 Gateway can also front agents hosted elsewhere, such as A2A agents, by endpoint URL.⁠Source 5In 2.x, data plane nodes you run receive LLM, MCP, and A2A traffic and forward allowed calls to agents registered as upstream URLs.⁠Source 2, Source 3
Agents across organizationsRegistries can be shared with other AWS accounts through AWS RAM; accounts outside your AWS Organization must accept an invitation.⁠Source 11Not publicly documented (checked 2 October 2026)
Protocol supportRuntime agents can serve HTTP, MCP, A2A, or AG-UI.⁠Source 37 Gateway combines its MCP targets into one MCP server; Registry validates MCP and A2A records.⁠Source 20, Source 38Detects A2A over JSON-RPC and REST bindings and rewrites agent-card URLs.⁠Source 3 Converts REST APIs into MCP tools, and proxies or combines MCP servers.⁠Source 2
Frameworks, models, and clouds supportedRuntime works with any open-source or custom framework, such as CrewAI, LangGraph, or Strands Agents.⁠Source 1 Identity also covers self-hosted agents.⁠Source 39Proxies A2A and plain HTTP agents, including ones on AgentCore Runtime via SigV4.⁠Source 3 Kong says it doesn’t change how agents are built.⁠Source 19
Operations
Deployment options and data residencyAWS says cross-region inference can move Memory, Policy, and Evaluations prompts out of the primary Region; AgentCore may store content to improve your service.⁠Source 1, Source 402.x is hybrid: Kong runs the control plane in Konnect; you run data plane nodes.⁠Source 2 Kong’s pricing also lists Kong-run Dedicated Cloud and serverless AI gateways.⁠Source 15, Source 41, Source 42
Compliance attestationsAWS lists AgentCore as FedRAMP (Class C and Class D) compliant.⁠Source 31, Source 32 It is HIPAA eligible, and SOC 2, ISO 27001:2022, and CSA STAR compliant.⁠Source 16, Source 31Kong Inc. lists ISO 27001, SOC 2 (report under NDA), PCI DSS, and CSA STAR.⁠Source 33 FIPS 140-3 mode from 2.2, not submitted for NIST validation.⁠Source 43
Support and SLAAWS says the Amazon Bedrock SLA applies to AgentCore.⁠Source 44 Basic Support is included for all AWS customers.⁠Source 45Konnect targets 99.9% monthly availability; Kong lists a 99.99% SLA for Dedicated Cloud Gateways, none for serverless.⁠Source 15 Enterprise support: up to 24x7.⁠Source 15
Time and effort to get runningAn AWS account with credentials, and the AgentCore CLI (Node.js 20 or later) to scaffold, test locally, deploy, and invoke an agent.⁠Source 8A quickstart script creates a Konnect control plane and a local Docker data plane; you then add each agent as an AI Agent entity and attach policies.⁠Source 18, Source 46
Pricing model and public pricesBy use, no upfront commitment or minimum fee.⁠Source 14 Gateway: $0.005 per 1,000 calls such as InvokeTool.⁠Source 14 Runtime v1 CPU: $0.0895 per vCPU-hour.⁠Source 14Plus from $25 a month plus usage.⁠Source 15 Plus control planes a month: hybrid $200, Dedicated Cloud $500, serverless $25.⁠Source 15 Enterprise is custom.⁠Source 15
Building
Agent building toolsWrite agents in Python with a framework such as Strands, LangGraph, or Google ADK, or define one by model, prompt, and tools in the managed harness.⁠Source 1, Source 8AI MCP Server can turn REST APIs into MCP tools.⁠Source 2 Tools for building agents are not publicly documented.
Model accessAWS calls it model-agnostic: any model in or outside Amazon Bedrock, including OpenAI, Gemini, Claude, Nova, Llama, and Mistral models.⁠Source 44One API to providers including OpenAI, Anthropic, Gemini, Amazon Bedrock, Mistral, and Ollama, with your own credentials.⁠Source 2, Source 46, Source 47
Integrations and ecosystemGateway has 1-click integrations with tools such as Salesforce, Slack, Jira, and Zendesk, and can import partner tools bought on AWS Marketplace.⁠Source 4, Source 44A Policies Hub of policies and integrations.⁠Source 26 AI Vault resolves secrets from backends such as AWS, GCP, Azure, and HashiCorp Vault.⁠Source 2

Which to choose

Choose Amazon Bedrock AgentCore if

  • You want one AWS platform to build, host, and operate agents, writing them with frameworks such as Strands, LangGraph, or Google ADK.⁠Source 1, Source 8
  • You want a generally available registry, with approvals, that can list agents, MCP servers, and tools on premises or in other clouds.⁠Source 1, Source 10, Source 16
  • You want no infrastructure to manage, and pricing by use with no upfront commitment or minimum fee.⁠Source 1, Source 14
  • You need AWS GovCloud (US-West), HIPAA eligibility, or SOC 1, 2, and 3 reports for your agent platform.⁠Source 16, Source 31

Choose Kong AI Gateway if

  • You want one gateway for LLM, MCP, and A2A traffic, with shared authentication, observability, and policy features.⁠Source 2
  • You need FIPS 140-3 mode: Kong’s FIPS package uses only approved algorithms, but Kong says it hasn’t been submitted for NIST validation.⁠Source 43
  • You’d rather run the data plane yourself: Kong’s control plane never carries your data traffic, and nodes keep proxying if it’s unreachable.⁠Source 2
  • You want one API to model providers such as OpenAI, Anthropic, Gemini, and Amazon Bedrock, switching or combining them without rewriting integrations.⁠Source 46, Source 47

Questions buyers ask

Is Kong AI Gateway an alternative to Amazon Bedrock AgentCore?

Partly: both can authenticate callers and check access rules on each request.⁠Source 3, Source 4, Source 6 AgentCore also hosts agents and keeps a generally available registry; Kong’s organization-wide agent inventory is in beta.⁠Source 1, Source 12, Source 16 Kong also routes LLM traffic to major providers through one API.⁠Source 2, Source 46

Do they support MCP and A2A?

AgentCore Runtime can host MCP and A2A servers.⁠Source 37 Kong AI Gateway detects A2A over JSON-RPC and REST, and proxies or combines MCP servers.⁠Source 2, Source 3 Both list four MCP revisions, 2025-03-26 to 2026-07-28: AgentCore Gateway for its MCP targets, Kong for clients (2026-07-28 from version 2.1).⁠Source 48, Source 49

How is each one priced?

AgentCore is billed by use, with no upfront commitment or minimum fee; Gateway calls such as InvokeTool cost $0.005 per 1,000.⁠Source 14 Kong’s AI Management Plus plan starts at $25 a month plus usage, with $200 a month per hybrid control plane; Enterprise is custom.⁠Source 15

Can either one connect agents across organizations?

An AgentCore registry can be shared with other AWS accounts through AWS RAM, to discover, publish, or administer records; accounts outside your AWS Organization must accept an invitation.⁠Source 11 Kong AI Gateway proxies to agents by URL, but a cross-organization trust model is not publicly documented.⁠Source 3

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

56 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Overview - Amazon Bedrock AgentCore (Developer Guide) AWS · checked Back:abcdefghijklmnopqrstuvw

  2. Source 2: AI Gateway architecture - Kong Docs Kong · checked Back:abcdefghijklmnopqrstuvwxy

  3. Source 3: AI Agents - Kong AI Gateway docs Kong · checked Back:abcdefghijklmnopqrstuv

  4. Source 4: Amazon Bedrock AgentCore Gateway: A secure AI gateway for agents, tools, and models AWS · checked Back:abc

  5. Source 5: HTTP passthrough targets - AgentCore Gateway AWS · checked Back:abcde

  6. Source 6: Policy in Amazon Bedrock AgentCore: Control Agent Interactions AWS · checked Back:abcdef

  7. Source 7: Observe your agent applications on Amazon Bedrock AgentCore Observability AWS · checked Back:ab

  8. Source 8: Get started with Amazon Bedrock AgentCore AWS · checked Back:abcd

  9. Source 9: Provide identity and credential management for agent applications with Amazon Bedrock AgentCore Identity AWS · checked Back:abcd

  10. Source 10: AWS Agent Registry: Discover and manage agents, tools, and resources AWS · checked Back:abcdefg

  11. Source 11: Sharing a registry across accounts with AWS RAM AWS · checked Back:abcd

  12. Source 12: Agents in Catalog - Kong Docs Kong · checked Back:abcdefg

  13. Source 13: Kong AI Gateway product page Kong · checked Back:ab

  14. Source 14: Amazon Bedrock AgentCore Pricing AWS · checked Back:abcdefg

  15. Source 15: Kong Pricing & Plans Kong · checked Back:abcdefghijkl

  16. Source 16: Release notes - Amazon Bedrock AgentCore AWS · checked Back:abcdefghi

  17. Source 17: Kong AI Gateway 2.0 Is Now GA - And It's Already Moving Faster Kong · checked Back:ab

  18. Source 18: Route A2A agent traffic through AI Gateway - Kong Docs Kong · checked Back:ab

  19. Source 19: The Agent Gateway for Secure, Observable Agent-to-Agent Communication (Kong) Kong · checked Back:ab

  20. Source 20: Key capabilities - AWS Agent Registry AWS · checked Back:abcd

  21. Source 21: Use interface VPC endpoints (AWS PrivateLink) with Amazon Bedrock AgentCore AWS · checked Back to text

  22. Source 22: Authenticate and authorize with Inbound Auth and Outbound Auth AWS · checked Back:abc

  23. Source 23: Configure inbound JWT authorizer AWS · checked Back:ab

  24. Source 24: AI Auth Strategies - Kong AI Gateway docs Kong · checked Back to text

  25. Source 25: Resource-based policies for Amazon Bedrock AgentCore AWS · checked Back to text

  26. Source 26: Kong AI Gateway Policies - Kong Docs Kong · checked Back:ab

  27. Source 27: Request Termination - Configuration Reference - Policy | Kong Docs Kong · checked Back to text

  28. Source 28: Log Amazon Bedrock AgentCore Gateway API calls with CloudTrail AWS · checked Back:ab

  29. Source 29: Enable CloudTrail data event logging for Amazon Bedrock AgentCore Gateway resources - Amazon Bedrock AgentCore AWS · checked Back:ab

  30. Source 30: Route A2A traffic through AI Gateway - Kong Docs Kong · checked Back:ab

  31. Source 31: Compliance validation for Amazon Bedrock AgentCore AWS · checked Back:abcd

  32. Source 32: Federal Risk and Authorization Management Program (FedRAMP) - Services in Scope - Amazon Web Services AWS · checked Back:ab

  33. Source 33: Trust Center - Kong Inc. Kong · checked Back:ab

  34. Source 34: Announcing Kong’s New Open Source AI Gateway with Multi-LLM Support, No-Code AI Plugins, Advanced Prompt Engineering, and More Kong · checked Back to text

  35. Source 35: AI PII Sanitizer - Policy | Kong Docs Kong · checked Back to text

  36. Source 36: Konnect and Dev Portal audit logs - Kong Docs Kong · checked Back to text

  37. Source 37: Understand the AgentCore Runtime service contract AWS · checked Back:ab

  38. Source 38: Supported targets for Amazon Bedrock AgentCore gateways AWS · checked Back to text

  39. Source 39: Features of AgentCore Identity AWS · checked Back to text

  40. Source 40: Cross-region inference in AgentCore Memory, Policy in AgentCore, and AgentCore Evaluations AWS · checked Back to text

  41. Source 41: Dedicated Cloud Gateways - Kong Docs Kong · checked Back to text

  42. Source 42: Serverless Gateways - Kong Docs Kong · checked Back to text

  43. Source 43: FIPS 140-3 compliance in AI Gateway - Kong Docs Kong · checked Back:ab

  44. Source 44: Amazon Bedrock AgentCore FAQs AWS · checked Back:abc

  45. Source 45: Compare AWS Support plans AWS · checked Back to text

  46. Source 46: Kong AI Gateway | Kong Docs Kong · checked Back:abcd

  47. Source 47: AI Gateway providers - Kong Docs Kong · checked Back:abc

  48. Source 48: MCP servers targets - AgentCore Gateway AWS · checked Back to text

  49. Source 49: MCP version support - Kong AI Gateway docs Kong · checked Back to text

  50. Source 50: Why Blocks? Blocks.ai · checked Back to text

  51. Source 51: What is Blocks? Blocks.ai · checked Back to text

  52. Source 52: Your company's private network Blocks.ai · checked Back to text

  53. Source 53: Network requirements Blocks.ai · checked Back to text

  54. Source 54: Solutions: Agent sprawl Blocks.ai · checked Back to text

  55. Source 55: Solutions: Partner networks Blocks.ai · checked Back to text

  56. Source 56: Pricing Blocks.ai · checked Back to text