Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.
Amazon Bedrock AgentCore vs Kong AI Gateway
Amazon Bedrock AgentCore
AWS platform for building, deploying, and operating AI agents
Kong AI Gateway
Gateway that governs LLM, MCP, and agent-to-agent traffic
Short answer
Amazon Bedrock AgentCore is AWS’s platform to build, deploy, and operate agents; Kong AI Gateway is a gateway for LLM, MCP, and A2A traffic, proxying to agents registered as upstream URLs.Source 1, Source 2, Source 3 AWS says AgentCore needs no infrastructure management; Kong AI Gateway 2.x pairs a Kong-managed control plane with data plane nodes you run.Source 1, Source 2
Where each one sits
Six layers of running AI agents at a company, and what each product’s own public sources say it covers.
These aren’t the same kind of product
- Where they overlap
- Both put a gateway in front of agents and tools that can authenticate callers and check access on each request, and both emit OpenTelemetry-compatible telemetry.Source 2, Source 3, Source 4, Source 5, Source 6, Source 7
- Where they differ
- AgentCore also helps build agents and hosts them in a serverless runtime.Source 1, Source 8 In 2.x, Kong proxies to agents registered as upstream URLs from data plane nodes you run.Source 2, Source 3
- Running both
- They can be combined: Kong’s docs describe signing requests with AWS IAM (SigV4) to reach an agent hosted on AgentCore Runtime.Source 3
Amazon Bedrock AgentCore
Kong AI Gateway
- Build agents: Not publicly documented
- Host and run agents: Not publicly documented
- Agents across organizations: Not publicly documented
At a glance
What each one is
Amazon Bedrock AgentCore
Amazon Bedrock AgentCore is AWS’s platform for building, deploying, and operating agents with any framework and model.Source 1 Its modular services, usable together or alone, include Runtime to host agents, Gateway and Policy for tool access, Identity, Observability, and AWS Agent Registry.Source 1, Source 6, Source 7, Source 9, Source 10
Kong AI Gateway
Kong AI Gateway is one gateway for LLM, MCP, and agent-to-agent (A2A) traffic, with shared authentication, observability, and policy features.Source 2, Source 13 An agent is added as an AI Agent entity, which exposes it at a gateway endpoint and can carry policies.Source 3, Source 18
The differences that matter
Building and hosting agents
Amazon Bedrock AgentCoreAgentCore Runtime hosts agents built with any framework, such as LangGraph or Strands Agents; the managed harness defines one from a model, prompt, and tools.Source 1
Agent registry
Amazon Bedrock AgentCoreAWS Agent Registry, generally available since August 2026, can list agents, MCP servers, and tools with approvals, including ones on premises or in other clouds.Source 1, Source 10, Source 16
Kong AI GatewayEach AI Agent entity is scoped to one gateway instance; Konnect Catalog’s organization-wide agent inventory is in beta and not for production.Source 2, Source 3, Source 12
With AWS Organizations, the registry can auto-detect AgentCore Runtimes and Gateways in member accounts; in Konnect Catalog, in beta, agents are added by pasting an A2A card.Source 12, Source 20
Who runs the infrastructure
Amazon Bedrock AgentCoreAWS says AgentCore runs agents, governs their tool access, and monitors them without any infrastructure management.Source 1 It is also generally available in AWS GovCloud (US-West).Source 16
Kong AI GatewayIn 2.x, Kong runs the control plane in Konnect; you run the data plane nodes, and your traffic never passes through the control plane.Source 2
Self-hosting AgentCore is not publicly documented. Kong’s docs say 2.x has no fully self-hosted control plane today; fully self-hosted AI gateways are a separate Gateway Enterprise offering.Source 2, Source 15
For security teams
What a security review asks, answered from each vendor’s public documentation.
Full comparison
18 criteria in five groups. Every cell links to its source, or says no public source answers it.
| Amazon Bedrock AgentCore | Kong AI Gateway | |
|---|---|---|
| What it is | ||
| What it is and who it’s for | AWS platform for building, deploying, and operating agents with any framework and model, made of modular services usable together or independently.Source 1 | Gateway for LLM, MCP, and A2A traffic.Source 2 All three run through one data plane, with shared authentication, observability, and policy features.Source 2 |
| Maturity | Generally available since October 2025.Source 16 Policy followed in March 2026, and AWS Agent Registry in August 2026.Source 16 | Kong announced AI Gateway in February 2024 and 2.0 as generally available on 1 September 2026.Source 17, Source 34 Konnect Catalog’s agent inventory is in beta.Source 12 |
| Control | ||
| Agent registry and discovery | AWS Agent Registry catalogs agents, MCP servers, tools, and skills behind an approval workflow, including ones on premises or in other clouds.Source 1, Source 10 | Each AI Agent entity is scoped to one gateway instance.Source 2, Source 3 An organization-wide agent inventory in Konnect Catalog is in beta.Source 12 |
| Identity and access control | Agent identities are workload identities in AgentCore Identity.Source 9 Runtime calls use IAM SigV4 by default, or JWTs from any OAuth 2.0 identity provider.Source 22, Source 23 | An agent can require API key or OpenID Connect authentication before routing, and an allow or deny list enforced before traffic reaches it.Source 3 |
| Ownership, policy, and revocation | Policy can check each Gateway request against rules written in natural language or Cedar.Source 6 Only approved registry records are discoverable.Source 10 | Policies for agents: input validation, request logging, and rate limits.Source 3 The AI PII Sanitizer covers model requests: a Plus add-on, included on Enterprise.Source 15, Source 35 |
| Audit log and observability | CloudTrail can log Gateway calls (data events are off by default) and logs Registry control-plane calls.Source 20, Source 28, Source 29 Policy logs its decisions.Source 6 | A2A audit logs record task IDs, method calls, latencies, and errors.Source 30 Konnect audit logs (Enterprise): webhook delivery, kept 7 days in Konnect.Source 15, Source 36 |
| Connection | ||
| How agents connect | Agents can run in serverless AgentCore Runtime.Source 1 Gateway can also front agents hosted elsewhere, such as A2A agents, by endpoint URL.Source 5 | In 2.x, data plane nodes you run receive LLM, MCP, and A2A traffic and forward allowed calls to agents registered as upstream URLs.Source 2, Source 3 |
| Agents across organizations | Registries can be shared with other AWS accounts through AWS RAM; accounts outside your AWS Organization must accept an invitation.Source 11 | Not publicly documented (checked 2 October 2026) |
| Protocol support | Runtime agents can serve HTTP, MCP, A2A, or AG-UI.Source 37 Gateway combines its MCP targets into one MCP server; Registry validates MCP and A2A records.Source 20, Source 38 | Detects A2A over JSON-RPC and REST bindings and rewrites agent-card URLs.Source 3 Converts REST APIs into MCP tools, and proxies or combines MCP servers.Source 2 |
| Frameworks, models, and clouds supported | Runtime works with any open-source or custom framework, such as CrewAI, LangGraph, or Strands Agents.Source 1 Identity also covers self-hosted agents.Source 39 | Proxies A2A and plain HTTP agents, including ones on AgentCore Runtime via SigV4.Source 3 Kong says it doesn’t change how agents are built.Source 19 |
| Operations | ||
| Deployment options and data residency | AWS says cross-region inference can move Memory, Policy, and Evaluations prompts out of the primary Region; AgentCore may store content to improve your service.Source 1, Source 40 | 2.x is hybrid: Kong runs the control plane in Konnect; you run data plane nodes.Source 2 Kong’s pricing also lists Kong-run Dedicated Cloud and serverless AI gateways.Source 15, Source 41, Source 42 |
| Compliance attestations | AWS lists AgentCore as FedRAMP (Class C and Class D) compliant.Source 31, Source 32 It is HIPAA eligible, and SOC 2, ISO 27001:2022, and CSA STAR compliant.Source 16, Source 31 | Kong Inc. lists ISO 27001, SOC 2 (report under NDA), PCI DSS, and CSA STAR.Source 33 FIPS 140-3 mode from 2.2, not submitted for NIST validation.Source 43 |
| Support and SLA | AWS says the Amazon Bedrock SLA applies to AgentCore.Source 44 Basic Support is included for all AWS customers.Source 45 | Konnect targets 99.9% monthly availability; Kong lists a 99.99% SLA for Dedicated Cloud Gateways, none for serverless.Source 15 Enterprise support: up to 24x7.Source 15 |
| Time and effort to get running | An AWS account with credentials, and the AgentCore CLI (Node.js 20 or later) to scaffold, test locally, deploy, and invoke an agent.Source 8 | A quickstart script creates a Konnect control plane and a local Docker data plane; you then add each agent as an AI Agent entity and attach policies.Source 18, Source 46 |
| Pricing model and public prices | By use, no upfront commitment or minimum fee.Source 14 Gateway: $0.005 per 1,000 calls such as InvokeTool.Source 14 Runtime v1 CPU: $0.0895 per vCPU-hour.Source 14 | Plus from $25 a month plus usage.Source 15 Plus control planes a month: hybrid $200, Dedicated Cloud $500, serverless $25.Source 15 Enterprise is custom.Source 15 |
| Building | ||
| Agent building tools | Write agents in Python with a framework such as Strands, LangGraph, or Google ADK, or define one by model, prompt, and tools in the managed harness.Source 1, Source 8 | AI MCP Server can turn REST APIs into MCP tools.Source 2 Tools for building agents are not publicly documented. |
| Model access | AWS calls it model-agnostic: any model in or outside Amazon Bedrock, including OpenAI, Gemini, Claude, Nova, Llama, and Mistral models.Source 44 | One API to providers including OpenAI, Anthropic, Gemini, Amazon Bedrock, Mistral, and Ollama, with your own credentials.Source 2, Source 46, Source 47 |
| Integrations and ecosystem | Gateway has 1-click integrations with tools such as Salesforce, Slack, Jira, and Zendesk, and can import partner tools bought on AWS Marketplace.Source 4, Source 44 | A Policies Hub of policies and integrations.Source 26 AI Vault resolves secrets from backends such as AWS, GCP, Azure, and HashiCorp Vault.Source 2 |
Which to choose
Choose Amazon Bedrock AgentCore if
- You want one AWS platform to build, host, and operate agents, writing them with frameworks such as Strands, LangGraph, or Google ADK.Source 1, Source 8
- You want a generally available registry, with approvals, that can list agents, MCP servers, and tools on premises or in other clouds.Source 1, Source 10, Source 16
- You want no infrastructure to manage, and pricing by use with no upfront commitment or minimum fee.Source 1, Source 14
- You need AWS GovCloud (US-West), HIPAA eligibility, or SOC 1, 2, and 3 reports for your agent platform.Source 16, Source 31
Choose Kong AI Gateway if
- You want one gateway for LLM, MCP, and A2A traffic, with shared authentication, observability, and policy features.Source 2
- You need FIPS 140-3 mode: Kong’s FIPS package uses only approved algorithms, but Kong says it hasn’t been submitted for NIST validation.Source 43
- You’d rather run the data plane yourself: Kong’s control plane never carries your data traffic, and nodes keep proxying if it’s unreachable.Source 2
- You want one API to model providers such as OpenAI, Anthropic, Gemini, and Amazon Bedrock, switching or combining them without rewriting integrations.Source 46, Source 47
Questions buyers ask
Is Kong AI Gateway an alternative to Amazon Bedrock AgentCore?
Partly: both can authenticate callers and check access rules on each request.Source 3, Source 4, Source 6 AgentCore also hosts agents and keeps a generally available registry; Kong’s organization-wide agent inventory is in beta.Source 1, Source 12, Source 16 Kong also routes LLM traffic to major providers through one API.Source 2, Source 46
Do they support MCP and A2A?
AgentCore Runtime can host MCP and A2A servers.Source 37 Kong AI Gateway detects A2A over JSON-RPC and REST, and proxies or combines MCP servers.Source 2, Source 3 Both list four MCP revisions, 2025-03-26 to 2026-07-28: AgentCore Gateway for its MCP targets, Kong for clients (2026-07-28 from version 2.1).Source 48, Source 49
How is each one priced?
Can either one connect agents across organizations?
An AgentCore registry can be shared with other AWS accounts through AWS RAM, to discover, publish, or administer records; accounts outside your AWS Organization must accept an invitation.Source 11 Kong AI Gateway proxies to agents by URL, but a cross-organization trust model is not publicly documented.Source 3
How we compare
Read the full methodEvery claim on this page links to a public source. Where none answers a question, the page says so.
We re-check every fact at least every 90 days. This page was last checked .
Something wrong or out of date? Tell us and we’ll correct it.
Sources
56 public sources, each with the date we checked it. Every one opens in a new tab.
Source 1: Overview - Amazon Bedrock AgentCore (Developer Guide) Back:abcdefghijklmnopqrstuvw
Source 2: AI Gateway architecture - Kong Docs Back:abcdefghijklmnopqrstuvwxy
Source 3: AI Agents - Kong AI Gateway docs Back:abcdefghijklmnopqrstuv
Source 4: Amazon Bedrock AgentCore Gateway: A secure AI gateway for agents, tools, and models Back:abc
Source 5: HTTP passthrough targets - AgentCore Gateway Back:abcde
Source 6: Policy in Amazon Bedrock AgentCore: Control Agent Interactions Back:abcdef
Source 7: Observe your agent applications on Amazon Bedrock AgentCore Observability Back:ab
Source 8: Get started with Amazon Bedrock AgentCore Back:abcd
Source 9: Provide identity and credential management for agent applications with Amazon Bedrock AgentCore Identity Back:abcd
Source 10: AWS Agent Registry: Discover and manage agents, tools, and resources Back:abcdefg
Source 11: Sharing a registry across accounts with AWS RAM Back:abcd
Source 16: Release notes - Amazon Bedrock AgentCore Back:abcdefghi
Source 17: Kong AI Gateway 2.0 Is Now GA - And It's Already Moving Faster Back:ab
Source 18: Route A2A agent traffic through AI Gateway - Kong Docs Back:ab
Source 19: The Agent Gateway for Secure, Observable Agent-to-Agent Communication (Kong) Back:ab
Source 21: Use interface VPC endpoints (AWS PrivateLink) with Amazon Bedrock AgentCore Back to text
Source 22: Authenticate and authorize with Inbound Auth and Outbound Auth Back:abc
Source 24: AI Auth Strategies - Kong AI Gateway docs Back to text
Source 25: Resource-based policies for Amazon Bedrock AgentCore Back to text
Source 27: Request Termination - Configuration Reference - Policy | Kong Docs Back to text
Source 28: Log Amazon Bedrock AgentCore Gateway API calls with CloudTrail Back:ab
Source 29: Enable CloudTrail data event logging for Amazon Bedrock AgentCore Gateway resources - Amazon Bedrock AgentCore Back:ab
Source 30: Route A2A traffic through AI Gateway - Kong Docs Back:ab
Source 31: Compliance validation for Amazon Bedrock AgentCore Back:abcd
Source 32: Federal Risk and Authorization Management Program (FedRAMP) - Services in Scope - Amazon Web Services Back:ab
Source 34: Announcing Kong’s New Open Source AI Gateway with Multi-LLM Support, No-Code AI Plugins, Advanced Prompt Engineering, and More Back to text
Source 35: AI PII Sanitizer - Policy | Kong Docs Back to text
Source 36: Konnect and Dev Portal audit logs - Kong Docs Back to text
Source 37: Understand the AgentCore Runtime service contract Back:ab
Source 38: Supported targets for Amazon Bedrock AgentCore gateways Back to text
Source 40: Cross-region inference in AgentCore Memory, Policy in AgentCore, and AgentCore Evaluations Back to text
Source 41: Dedicated Cloud Gateways - Kong Docs Back to text
Source 43: FIPS 140-3 compliance in AI Gateway - Kong Docs Back:ab
Source 48: MCP servers targets - AgentCore Gateway Back to text
Source 49: MCP version support - Kong AI Gateway docs Back to text