Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

Amazon Bedrock AgentCore vs MuleSoft Agent Fabric

Amazon Bedrock AgentCore

AWS platform for building, deploying, and operating AI agents

MuleSoft Agent Fabric

Control plane for agents, MCP servers, and APIs across platforms

Short answer

Amazon Bedrock AgentCore is an AWS platform for building, deploying, and operating agents, while MuleSoft Agent Fabric is a control plane for agents, MCP servers, and APIs across platforms.⁠Source 1, Source 2 AgentCore hosts agents and bills by use; MuleSoft packages start at $2,000 a month, and the Agent Fabric package shows no published price.⁠Source 1, Source 3, Source 4

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both keep a registry of agents and MCP servers, control which tools agents can call at a gateway, and keep audit trails.⁠Source 5, Source 6, Source 7, Source 8
Where they differ
With AgentCore you can also build agents and host them in its serverless runtime.⁠Source 1 Agent Fabric’s brokers orchestrate A2A-compliant agents; MuleSoft says Salesforce’s separate Agentforce is for building agents.⁠Source 8, Source 9, Source 10
Running both
MuleSoft says its scanners read agent metadata from AgentCore, and scanned agents are cataloged so they can be governed in Agent Fabric.⁠Source 10, Source 11
Public sources · checked 2 October 2026
  • Offered
  • Not publicly documented

Amazon Bedrock AgentCore

  • Build agents: OfferedHarness managed agent loop⁠Source 1
  • Host and run agents: OfferedAgentCore Runtime⁠Source 1
  • Identity and access: OfferedAgentCore Identity workload identities⁠Source 12
  • Registry and governance: OfferedAWS Agent Registry with approvals⁠Source 5
  • Traffic between agents, tools, and models: OfferedAgentCore Gateway⁠Source 13
  • Agents across organizations: OfferedRegistry shared through AWS RAM⁠Source 14

MuleSoft Agent Fabric

  • Build agents: OfferedAgent brokers in Agent Script⁠Source 8
  • Host and run agents: OfferedAgent brokers on CloudHub 2.0⁠Source 8
  • Identity and access: OfferedOmni Gateway authentication and authorization⁠Source 8
  • Registry and governance: OfferedAgent Registry in Anypoint Exchange⁠Source 8
  • Traffic between agents, tools, and models: OfferedOmni Gateway in request path⁠Source 8
  • Agents across organizations: Not publicly documented

At a glance

TopicAmazon Bedrock AgentCoreMuleSoft Agent Fabric
Builds and runs agentsBuild agents with a managed harness or the AgentCore SDK; AgentCore Runtime, a serverless AWS environment, runs them.⁠Source 1, Source 15Agent brokers, defined in Agent Script, run on CloudHub 2.0 or Runtime Fabric.⁠Source 8 MuleSoft says Salesforce’s separate Agentforce is for building agents within Salesforce.⁠Source 10
Where policy is enforcedAt AgentCore Gateway: Policy in AgentCore can evaluate each request before allowing tool access.⁠Source 6At Omni Gateway, placed in the request path of each managed agent, API, or MCP server.⁠Source 8
Agent identityWorkload identities in AgentCore Identity.⁠Source 12 Its authorizer works with existing identity providers such as Amazon Cognito, Microsoft Entra ID, or Okta.⁠Source 15For rogue-agent detection, agents are set up as service identities in your own IdP.⁠Source 16 MuleSoft says user context is carried through the call chain.⁠Source 10
Pricing modelBy use, per service, with no upfront commitment or minimum fee.⁠Source 3MuleSoft packages from $2,000 a month, billed annually, with usage metered in Mule Credits.⁠Source 4 MuleSoft lists its Agent Fabric package with ‘Contact sales’ and no published price.⁠Source 4
Generally availableSince October 2025; AWS Agent Registry since August 2026.⁠Source 17Yes, MuleSoft says, with new capabilities each month.⁠Source 10 The first release note is dated 3 October 2025.⁠Source 9

What each one is

Amazon Bedrock AgentCore

Amazon Bedrock AgentCore is an AWS platform for building, deploying, and operating agents with any framework and foundation model.⁠Source 1 Its modular services work together or alone: Runtime hosts agents, Gateway and Policy control tool access, and AWS Agent Registry catalogs agents and tools.⁠Source 1, Source 5, Source 6

MuleSoft Agent Fabric

MuleSoft Agent Fabric is a control plane for agents, MCP servers, and APIs across platforms.⁠Source 2 Scanners and manual registration fill its registry, Omni Gateway enforces policy in managed agents’ request path, and agent brokers orchestrate A2A-compliant agents.⁠Source 8, Source 18

The differences that matter

  1. Where agents run

    Amazon Bedrock AgentCore

    AgentCore Runtime hosts agents in a serverless AWS environment; Gateway can also route to agents hosted elsewhere, at any HTTP endpoint.⁠Source 1, Source 13

    MuleSoft Agent Fabric

    MuleSoft says Agent Fabric applies control to agents wherever they run, without rebuilding them; its own brokers run on CloudHub 2.0 or Runtime Fabric.⁠Source 8, Source 10

    AWS Agent Registry can also list agents on premises or in other clouds, and AgentCore Identity covers self-hosted agents.⁠Source 1, Source 19

  2. How agents get into the registry

    Amazon Bedrock AgentCore

    Registry can create records for discovered AgentCore Runtimes and Gateways; other agents and tools are published as records behind an approval workflow.⁠Source 5, Source 7

    MuleSoft Agent Fabric

    Scanners register agents, APIs, and MCP servers they find on supported platforms; agents they miss can be registered by uploading an agent card.⁠Source 8, Source 18

  3. Remote and partner agents

    Amazon Bedrock AgentCore

    A registry can be shared with other AWS accounts through AWS RAM; accounts outside your AWS Organization must accept an invitation.⁠Source 14

    MuleSoft Agent Fabric

    An egress Omni Gateway enforces policy on agent networks’ calls to agents outside the network; partner-held access controls are not publicly documented.⁠Source 20

    An agent in AgentCore Runtime can also be opened to a principal in another AWS account with resource-based policies.⁠Source 21

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicAmazon Bedrock AgentCoreMuleSoft Agent Fabric
Network exposureCan reach private VPC resources without exposing them publicly; VPC callers can use PrivateLink, with no internet gateway.⁠Source 22, Source 23Omni Gateway sits in managed agents’ request path; agent-network ingress gateways get a public endpoint, egress gateways none.⁠Source 8, Source 20
IdentityWorkload identities in AgentCore Identity, which verifies each request independently; inbound JWTs from any OAuth 2.0 identity provider.⁠Source 12, Source 24, Source 25Agents set up as service identities in your IdP for rogue-agent detection; Omni Gateway supports OAuth 2.0 token exchange.⁠Source 16, Source 26
Access changes and revocationExplicit deny overrides other policies; removing an account from a registry share revokes its access; deprecated records leave discovery.⁠Source 14, Source 21, Source 27After review, quarantine stops a flagged agent from acting and blocks it at model proxies with the Kill Switch policy.⁠Source 16
Audit trailCloudTrail can log Gateway calls (data events are off by default) and logs Registry control-plane calls; Policy logs its decisions.⁠Source 6, Source 7, Source 28, Source 29Omni Gateway can keep a traffic audit trail; Anypoint Platform audit logs are kept one year by default.⁠Source 8, Source 30
ComplianceHIPAA eligible; AWS lists it as FedRAMP (Class C and Class D), SOC 2, ISO 27001:2022, and CSA STAR compliant.⁠Source 31, Source 32MuleSoft says Anypoint Platform is certified to ISO 27001, SOC 2, PCI DSS, and HIPAA.⁠Source 33

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Amazon Bedrock AgentCore and MuleSoft Agent Fabric compared on 18 criteria
Amazon Bedrock AgentCoreMuleSoft Agent Fabric
What it is
What it is and who it’s forAWS platform to build, deploy, and operate agents with any framework and model, made of modular services used together or alone.⁠Source 1Control plane for agents, MCP servers, and APIs across platforms.⁠Source 2 MuleSoft says it discovers, governs, orchestrates, and observes them.⁠Source 34
MaturityGenerally available since October 2025.⁠Source 17 AWS Agent Registry became generally available in August 2026, and Policy in March 2026.⁠Source 17MuleSoft says it is generally available, with new capabilities each month.⁠Source 10 Its first release note is dated 3 October 2025.⁠Source 9
Control
Agent registry and discoveryAWS Agent Registry catalogs agents, MCP servers, tools, and skills on AWS, on premises, or in other clouds.⁠Source 1, Source 5 Consumers see only approved records.⁠Source 35One inventory of agents, MCP servers, and APIs, whichever platform built them.⁠Source 8 Scanners fill it; agents can also be added by agent card.⁠Source 8, Source 18
Identity and access controlWorkload identities in AgentCore Identity.⁠Source 12 Calls to hosted agents use IAM SigV4 by default, or JWTs from any OAuth 2.0 identity provider.⁠Source 25, Source 36Omni Gateway can require authentication and authorization and limit which tools and APIs an agent can call.⁠Source 8 User roles come from Anypoint access management.⁠Source 2
Ownership, policy, and revocationPolicy can check each Gateway request against rules in natural language or Cedar.⁠Source 6 Registry records pass an approval workflow; curators can deprecate them.⁠Source 5, Source 7Governance strategies set access, data privacy, cost, and compliance rules once for agents, APIs, and MCP servers in scope, and can block or flag noncompliance.⁠Source 8
Audit log and observabilityCloudTrail logs Registry control-plane calls and can log Gateway calls (data events are off by default).⁠Source 7, Source 28, Source 29 Policy logs its decisions.⁠Source 6Omni Gateway can keep a traffic audit trail.⁠Source 8 Platform audit logs are kept a year by default; Integration Advanced or Titanium adds export to third-party tools.⁠Source 30
Connection
How agents connectAgents can run in AgentCore Runtime, which AWS calls a serverless environment.⁠Source 1 Gateway can route to agents at any HTTP endpoint as passthrough targets.⁠Source 13Omni Gateway sits in the request path of each managed agent, API, or MCP server.⁠Source 8 One gateway can carry an agent network’s ingress and egress traffic.⁠Source 37
Agents across organizationsA registry can be shared with other AWS accounts through AWS RAM; accounts outside your AWS Organization accept an invitation.⁠Source 14An egress gateway enforces policy on agent networks’ calls to agents outside the network.⁠Source 20 Partner-held access controls: not publicly documented.
Protocol supportRuntime agents can serve HTTP, MCP, A2A, or AG-UI.⁠Source 38 Gateway acts as one MCP server over its MCP targets.⁠Source 39 Registry checks records against MCP and A2A schemas.⁠Source 7Omni Gateway supports MCP and A2A, and A2A powers orchestration in agent networks.⁠Source 40, Source 41 MCP Bridge turns an existing API into an MCP server without custom code.⁠Source 8
Frameworks, models, and clouds supportedRuntime works with custom and open-source frameworks such as CrewAI, LangGraph, and Google ADK.⁠Source 1 Identity covers agents on Runtime, self-hosted, or hybrid.⁠Source 19MuleSoft calls it vendor agnostic and says its scanners cover Amazon, Google, Microsoft, Databricks, and more.⁠Source 10, Source 34 Brokers orchestrate only A2A-compliant agents.⁠Source 8
Operations
Deployment options and data residencyAWS says cross-region inference can move Memory, Policy, and Evaluations prompts out of the primary Region; AgentCore may store content to improve your service.⁠Source 1, Source 42Agent Fabric runs on MuleSoft-hosted control planes; Omni Gateway can be self-managed.⁠Source 43, Source 44 Self-hosting Agent Fabric’s control plane is not publicly documented.
Compliance attestationsAWS lists AgentCore as FedRAMP (Class C and Class D) compliant.⁠Source 31, Source 32 It is HIPAA eligible, and SOC 2, ISO 27001:2022, and CSA STAR compliant.⁠Source 17, Source 31MuleSoft says Anypoint Platform is certified to ISO 27001, SOC 2, PCI DSS, and HIPAA.⁠Source 33 An attestation naming Agent Fabric is not publicly documented.
Support and SLAAWS says the Amazon Bedrock SLA applies to AgentCore.⁠Source 15 Basic Support is included for all AWS customers.⁠Source 45MuleSoft’s SLA for subscriptions started by 1 May 2025 commits to 99.95% monthly availability, without naming Agent Fabric.⁠Source 46 A Premier Success Plan is offered.⁠Source 47
Time and effort to get runningWith the CLI quickstart you scaffold, test, deploy, and invoke one agent.⁠Source 48 You need an AWS account with credentials and Node.js 20 or later.⁠Source 48With product access, an admin turns Agent Fabric on.⁠Source 2 Agent networks need a Managed Omni Gateway; scanners need a connected cloud provider for each source.⁠Source 2
Pricing model and public pricesBy use, per service, with no upfront commitment or minimum fee.⁠Source 3 Registry has a monthly free tier; Gateway calls such as InvokeTool are $0.005 per 1,000.⁠Source 3MuleSoft packages start at $2,000 a month, billed annually; usage is metered in Mule Credits.⁠Source 4 The Agent Fabric package lists no price: contact sales.⁠Source 4
Building
Agent building toolsA managed harness defines agents from a model, prompt, and tools; or write the loop in Python with a framework such as Strands, LangGraph, or Google ADK.⁠Source 1, Source 48Agent networks are defined in YAML, brokers in Agent Script.⁠Source 8, Source 49 MuleSoft says Salesforce’s separate Agentforce is for building agents within Salesforce.⁠Source 10
Model accessModel-agnostic, AWS says: any model in or outside Amazon Bedrock, naming OpenAI, Gemini, Claude, Amazon Nova, Llama, and Mistral.⁠Source 15Brokers support OpenAI, Azure OpenAI, Bedrock OpenAI, and Gemini models.⁠Source 49 Model Proxy is one access layer for several providers, with spend caps.⁠Source 8, Source 50
Integrations and ecosystemGateway has 1-click integrations with tools such as Salesforce, Slack, Jira, Asana, and Zendesk, and can import AWS Marketplace partner tools.⁠Source 15, Source 51The catalog has curated public MCP servers from the Official MCP Registry and Informatica.⁠Source 8 Policies can apply to Apigee, Kong, and Azure API Management APIs.⁠Source 52

Which to choose

Choose Amazon Bedrock AgentCore if

  • You want one AWS platform to build, host, and operate agents, with a managed agent loop and a serverless runtime.⁠Source 1
  • You want to pay only for what you use, with no upfront commitment or minimum fee.⁠Source 3
  • Your agents span AWS accounts, and you want one registry shared through AWS RAM, including with accounts outside your AWS Organization.⁠Source 14
  • You want each tool call through the gateway checked against policies written in natural language or Cedar.⁠Source 6

Choose MuleSoft Agent Fabric if

  • Your agents already run on several platforms, and you want scanners that MuleSoft says cover Amazon, Google, Microsoft, and more.⁠Source 8, Source 34
  • You want third-party agents governed at the communication layer, which MuleSoft says needs no changes to the agents.⁠Source 10
  • You already use MuleSoft: Agent Fabric uses Anypoint Platform access management, and MuleSoft cites hundreds of enterprise connectors.⁠Source 2, Source 10
  • You want brokers to orchestrate A2A-compliant agents across ecosystems, and caps on each caller’s model spend.⁠Source 8, Source 9

Questions buyers ask

Can either one govern agents built on other platforms?

AWS says Agent Registry can list agents on AgentCore, other providers, or on premises; Observability shows outside agents’ metrics after extra setup.⁠Source 15, Source 56 MuleSoft says third-party agents can be governed without being modified, and that its scanners register agents from Amazon, Google, Microsoft, and more.⁠Source 10, Source 34

How is each one priced?

AgentCore is billed by use, with no upfront commitment or minimum fee; Agent Registry has a monthly free tier.⁠Source 3 MuleSoft packages start at $2,000 a month, and usage draws on Mule Credits.⁠Source 4 MuleSoft lists its Agent Fabric package with ‘Contact sales’ and no published price.⁠Source 4

Do they support MCP and A2A?

AgentCore Runtime can host MCP and A2A servers, Gateway acts as one MCP server over its MCP targets, and Agent Registry validates records against MCP and A2A schemas.⁠Source 7, Source 38, Source 39 Omni Gateway supports both protocols, and A2A powers orchestration in MuleSoft agent networks.⁠Source 40, Source 41

Can either one be self-hosted?

Neither publicly documents a self-hosted AgentCore or Agent Fabric control plane. AgentCore runs in AWS Regions with no infrastructure to manage.⁠Source 1, Source 15 Agent Fabric runs on MuleSoft-hosted regional control planes; Omni Gateway can be self-managed in a data center or on EKS, GKE, or AKS.⁠Source 43, Source 44

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

63 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Overview - Amazon Bedrock AgentCore (Developer Guide) AWS · checked Back:abcdefghijklmnopqr

  2. Source 2: Get Started with Agent Fabric Salesforce · checked Back:abcdefg

  3. Source 3: Amazon Bedrock AgentCore Pricing AWS · checked Back:abcdef

  4. Source 4: MuleSoft Pricing | Plans From $2,000 a Month Salesforce · checked Back:abcdefg

  5. Source 5: AWS Agent Registry: Discover and manage agents, tools, and resources AWS · checked Back:abcdef

  6. Source 6: Policy in Amazon Bedrock AgentCore: Control Agent Interactions AWS · checked Back:abcdefg

  7. Source 7: Key capabilities - AWS Agent Registry AWS · checked Back:abcdefg

  8. Source 8: Agent Fabric Overview Salesforce · checked Back:abcdefghijklmnopqrstuvwxyz27

  9. Source 9: Agent Fabric Release Notes Salesforce · checked Back:abcd

  10. Source 10: See Every Agent. Govern Every Agent. Control AI Costs. (mulesoft.com home page) Salesforce · checked Back:abcdefghijkl

  11. Source 11: Agent Scanners Salesforce · checked Back to text

  12. Source 12: Provide identity and credential management for agent applications with Amazon Bedrock AgentCore Identity AWS · checked Back:abcd

  13. Source 13: HTTP passthrough targets - AgentCore Gateway AWS · checked Back:abc

  14. Source 14: Sharing a registry across accounts with AWS RAM AWS · checked Back:abcde

  15. Source 15: Amazon Bedrock AgentCore FAQs AWS · checked Back:abcdefg

  16. Source 16: Detect and Contain Rogue Agents Salesforce · checked Back:abc

  17. Source 17: Release notes - Amazon Bedrock AgentCore AWS · checked Back:abcd

  18. Source 18: Register Services Manually Salesforce · checked Back:abc

  19. Source 19: Features of AgentCore Identity AWS · checked Back:ab

  20. Source 20: Deploying Agent Network Ingress and Egress Managed Omni Gateways Salesforce · checked Back:abc

  21. Source 21: Resource-based policies for Amazon Bedrock AgentCore AWS · checked Back:ab

  22. Source 22: Connect to private resources in your VPC using VPC Lattice AWS · checked Back to text

  23. Source 23: Use interface VPC endpoints (AWS PrivateLink) with Amazon Bedrock AgentCore AWS · checked Back to text

  24. Source 24: Overview of Amazon Bedrock AgentCore Identity AWS · checked Back to text

  25. Source 25: Configure inbound JWT authorizer AWS · checked Back:ab

  26. Source 26: OAuth 2.0 OBO Credential Injection Policy Salesforce · checked Back to text

  27. Source 27: Deprecating registry records AWS · checked Back to text

  28. Source 28: Log Amazon Bedrock AgentCore Gateway API calls with CloudTrail AWS · checked Back:ab

  29. Source 29: Enable CloudTrail data event logging for Amazon Bedrock AgentCore Gateway resources - Amazon Bedrock AgentCore AWS · checked Back:ab

  30. Source 30: Audit Logging in Anypoint Platform Salesforce · checked Back:ab

  31. Source 31: Compliance validation for Amazon Bedrock AgentCore AWS · checked Back:abc

  32. Source 32: Federal Risk and Authorization Management Program (FedRAMP) - Services in Scope - Amazon Web Services AWS · checked Back:ab

  33. Source 33: Anypoint Platform Trust Center Salesforce · checked Back:ab

  34. Source 34: MuleSoft Agent Fabric | Agent Governance and Orchestration Salesforce · checked Back:abcd

  35. Source 35: Concepts and terminology - AWS Agent Registry AWS · checked Back to text

  36. Source 36: Authenticate and authorize with Inbound Auth and Outbound Auth AWS · checked Back to text

  37. Source 37: Get Started with Agent Networks Salesforce · checked Back to text

  38. Source 38: Understand the AgentCore Runtime service contract AWS · checked Back:ab

  39. Source 39: Supported targets for Amazon Bedrock AgentCore gateways AWS · checked Back:ab

  40. Source 40: Securing Agent Interactions with Omni Gateway Salesforce · checked Back:ab

  41. Source 41: Using A2A Protocol in Agent Networks Salesforce · checked Back:ab

  42. Source 42: Cross-region inference in AgentCore Memory, Policy in AgentCore, and AgentCore Evaluations AWS · checked Back to text

  43. Source 43: Salesforce Hyperforce Overview Salesforce · checked Back:ab

  44. Source 44: Requirements and Limits for Omni Gateway Salesforce · checked Back:ab

  45. Source 45: Compare AWS Support plans AWS · checked Back to text

  46. Source 46: MuleSoft Cloud Offerings Service Level Agreement (SLA) for subscriptions with an Order Start Date on or before May 1, 2025 Salesforce · checked Back to text

  47. Source 47: MuleSoft Subscription Plans - effective for Customer purchases made from Salesforce on or after June 27, 2025 Salesforce · checked Back to text

  48. Source 48: Get started with Amazon Bedrock AgentCore AWS · checked Back:abc

  49. Source 49: Building Agent Networks for Agent Fabric Salesforce · checked Back:ab

  50. Source 50: Creating and Managing Model Proxies Salesforce · checked Back to text

  51. Source 51: Amazon Bedrock AgentCore Gateway: A secure AI gateway for agents, tools, and models AWS · checked Back to text

  52. Source 52: Enhanced MuleSoft Experience Overview Salesforce · checked Back to text

  53. Source 53: Deploy A2A servers in AgentCore Runtime AWS · checked Back to text

  54. Source 54: Make an Agent A2A-Compliant Salesforce · checked Back to text

  55. Source 55: Enhanced MuleSoft Experience Release Notes Salesforce · checked Back to text

  56. Source 56: Add observability to your Amazon Bedrock AgentCore resources AWS · checked Back to text

  57. Source 57: Why Blocks? Blocks.ai · checked Back to text

  58. Source 58: What is Blocks? Blocks.ai · checked Back to text

  59. Source 59: Your company's private network Blocks.ai · checked Back to text

  60. Source 60: Network requirements Blocks.ai · checked Back to text

  61. Source 61: Solutions: Agent sprawl Blocks.ai · checked Back to text

  62. Source 62: Solutions: Partner networks Blocks.ai · checked Back to text

  63. Source 63: Pricing Blocks.ai · checked Back to text