Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.
Amazon Bedrock AgentCore vs MuleSoft Agent Fabric
Amazon Bedrock AgentCore
AWS platform for building, deploying, and operating AI agents
MuleSoft Agent Fabric
Control plane for agents, MCP servers, and APIs across platforms
Short answer
Amazon Bedrock AgentCore is an AWS platform for building, deploying, and operating agents, while MuleSoft Agent Fabric is a control plane for agents, MCP servers, and APIs across platforms.Source 1, Source 2 AgentCore hosts agents and bills by use; MuleSoft packages start at $2,000 a month, and the Agent Fabric package shows no published price.Source 1, Source 3, Source 4
Where each one sits
Six layers of running AI agents at a company, and what each product’s own public sources say it covers.
These aren’t the same kind of product
Amazon Bedrock AgentCore
MuleSoft Agent Fabric
- Agents across organizations: Not publicly documented
At a glance
What each one is
Amazon Bedrock AgentCore
Amazon Bedrock AgentCore is an AWS platform for building, deploying, and operating agents with any framework and foundation model.Source 1 Its modular services work together or alone: Runtime hosts agents, Gateway and Policy control tool access, and AWS Agent Registry catalogs agents and tools.Source 1, Source 5, Source 6
MuleSoft Agent Fabric
MuleSoft Agent Fabric is a control plane for agents, MCP servers, and APIs across platforms.Source 2 Scanners and manual registration fill its registry, Omni Gateway enforces policy in managed agents’ request path, and agent brokers orchestrate A2A-compliant agents.Source 8, Source 18
The differences that matter
Where agents run
Amazon Bedrock AgentCoreAgentCore Runtime hosts agents in a serverless AWS environment; Gateway can also route to agents hosted elsewhere, at any HTTP endpoint.Source 1, Source 13
MuleSoft Agent FabricMuleSoft says Agent Fabric applies control to agents wherever they run, without rebuilding them; its own brokers run on CloudHub 2.0 or Runtime Fabric.Source 8, Source 10
AWS Agent Registry can also list agents on premises or in other clouds, and AgentCore Identity covers self-hosted agents.Source 1, Source 19
How agents get into the registry
Remote and partner agents
Amazon Bedrock AgentCoreA registry can be shared with other AWS accounts through AWS RAM; accounts outside your AWS Organization must accept an invitation.Source 14
MuleSoft Agent FabricAn egress Omni Gateway enforces policy on agent networks’ calls to agents outside the network; partner-held access controls are not publicly documented.Source 20
An agent in AgentCore Runtime can also be opened to a principal in another AWS account with resource-based policies.Source 21
For security teams
What a security review asks, answered from each vendor’s public documentation.
Full comparison
18 criteria in five groups. Every cell links to its source, or says no public source answers it.
| Amazon Bedrock AgentCore | MuleSoft Agent Fabric | |
|---|---|---|
| What it is | ||
| What it is and who it’s for | AWS platform to build, deploy, and operate agents with any framework and model, made of modular services used together or alone.Source 1 | Control plane for agents, MCP servers, and APIs across platforms.Source 2 MuleSoft says it discovers, governs, orchestrates, and observes them.Source 34 |
| Maturity | Generally available since October 2025.Source 17 AWS Agent Registry became generally available in August 2026, and Policy in March 2026.Source 17 | MuleSoft says it is generally available, with new capabilities each month.Source 10 Its first release note is dated 3 October 2025.Source 9 |
| Control | ||
| Agent registry and discovery | AWS Agent Registry catalogs agents, MCP servers, tools, and skills on AWS, on premises, or in other clouds.Source 1, Source 5 Consumers see only approved records.Source 35 | One inventory of agents, MCP servers, and APIs, whichever platform built them.Source 8 Scanners fill it; agents can also be added by agent card.Source 8, Source 18 |
| Identity and access control | Workload identities in AgentCore Identity.Source 12 Calls to hosted agents use IAM SigV4 by default, or JWTs from any OAuth 2.0 identity provider.Source 25, Source 36 | Omni Gateway can require authentication and authorization and limit which tools and APIs an agent can call.Source 8 User roles come from Anypoint access management.Source 2 |
| Ownership, policy, and revocation | Policy can check each Gateway request against rules in natural language or Cedar.Source 6 Registry records pass an approval workflow; curators can deprecate them.Source 5, Source 7 | Governance strategies set access, data privacy, cost, and compliance rules once for agents, APIs, and MCP servers in scope, and can block or flag noncompliance.Source 8 |
| Audit log and observability | CloudTrail logs Registry control-plane calls and can log Gateway calls (data events are off by default).Source 7, Source 28, Source 29 Policy logs its decisions.Source 6 | Omni Gateway can keep a traffic audit trail.Source 8 Platform audit logs are kept a year by default; Integration Advanced or Titanium adds export to third-party tools.Source 30 |
| Connection | ||
| How agents connect | Agents can run in AgentCore Runtime, which AWS calls a serverless environment.Source 1 Gateway can route to agents at any HTTP endpoint as passthrough targets.Source 13 | Omni Gateway sits in the request path of each managed agent, API, or MCP server.Source 8 One gateway can carry an agent network’s ingress and egress traffic.Source 37 |
| Agents across organizations | A registry can be shared with other AWS accounts through AWS RAM; accounts outside your AWS Organization accept an invitation.Source 14 | An egress gateway enforces policy on agent networks’ calls to agents outside the network.Source 20 Partner-held access controls: not publicly documented. |
| Protocol support | Runtime agents can serve HTTP, MCP, A2A, or AG-UI.Source 38 Gateway acts as one MCP server over its MCP targets.Source 39 Registry checks records against MCP and A2A schemas.Source 7 | Omni Gateway supports MCP and A2A, and A2A powers orchestration in agent networks.Source 40, Source 41 MCP Bridge turns an existing API into an MCP server without custom code.Source 8 |
| Frameworks, models, and clouds supported | Runtime works with custom and open-source frameworks such as CrewAI, LangGraph, and Google ADK.Source 1 Identity covers agents on Runtime, self-hosted, or hybrid.Source 19 | MuleSoft calls it vendor agnostic and says its scanners cover Amazon, Google, Microsoft, Databricks, and more.Source 10, Source 34 Brokers orchestrate only A2A-compliant agents.Source 8 |
| Operations | ||
| Deployment options and data residency | AWS says cross-region inference can move Memory, Policy, and Evaluations prompts out of the primary Region; AgentCore may store content to improve your service.Source 1, Source 42 | Agent Fabric runs on MuleSoft-hosted control planes; Omni Gateway can be self-managed.Source 43, Source 44 Self-hosting Agent Fabric’s control plane is not publicly documented. |
| Compliance attestations | AWS lists AgentCore as FedRAMP (Class C and Class D) compliant.Source 31, Source 32 It is HIPAA eligible, and SOC 2, ISO 27001:2022, and CSA STAR compliant.Source 17, Source 31 | MuleSoft says Anypoint Platform is certified to ISO 27001, SOC 2, PCI DSS, and HIPAA.Source 33 An attestation naming Agent Fabric is not publicly documented. |
| Support and SLA | AWS says the Amazon Bedrock SLA applies to AgentCore.Source 15 Basic Support is included for all AWS customers.Source 45 | MuleSoft’s SLA for subscriptions started by 1 May 2025 commits to 99.95% monthly availability, without naming Agent Fabric.Source 46 A Premier Success Plan is offered.Source 47 |
| Time and effort to get running | With the CLI quickstart you scaffold, test, deploy, and invoke one agent.Source 48 You need an AWS account with credentials and Node.js 20 or later.Source 48 | With product access, an admin turns Agent Fabric on.Source 2 Agent networks need a Managed Omni Gateway; scanners need a connected cloud provider for each source.Source 2 |
| Pricing model and public prices | By use, per service, with no upfront commitment or minimum fee.Source 3 Registry has a monthly free tier; Gateway calls such as InvokeTool are $0.005 per 1,000.Source 3 | MuleSoft packages start at $2,000 a month, billed annually; usage is metered in Mule Credits.Source 4 The Agent Fabric package lists no price: contact sales.Source 4 |
| Building | ||
| Agent building tools | A managed harness defines agents from a model, prompt, and tools; or write the loop in Python with a framework such as Strands, LangGraph, or Google ADK.Source 1, Source 48 | Agent networks are defined in YAML, brokers in Agent Script.Source 8, Source 49 MuleSoft says Salesforce’s separate Agentforce is for building agents within Salesforce.Source 10 |
| Model access | Model-agnostic, AWS says: any model in or outside Amazon Bedrock, naming OpenAI, Gemini, Claude, Amazon Nova, Llama, and Mistral.Source 15 | Brokers support OpenAI, Azure OpenAI, Bedrock OpenAI, and Gemini models.Source 49 Model Proxy is one access layer for several providers, with spend caps.Source 8, Source 50 |
| Integrations and ecosystem | Gateway has 1-click integrations with tools such as Salesforce, Slack, Jira, Asana, and Zendesk, and can import AWS Marketplace partner tools.Source 15, Source 51 | The catalog has curated public MCP servers from the Official MCP Registry and Informatica.Source 8 Policies can apply to Apigee, Kong, and Azure API Management APIs.Source 52 |
Which to choose
Choose Amazon Bedrock AgentCore if
- You want one AWS platform to build, host, and operate agents, with a managed agent loop and a serverless runtime.Source 1
- You want to pay only for what you use, with no upfront commitment or minimum fee.Source 3
- Your agents span AWS accounts, and you want one registry shared through AWS RAM, including with accounts outside your AWS Organization.Source 14
- You want each tool call through the gateway checked against policies written in natural language or Cedar.Source 6
Choose MuleSoft Agent Fabric if
- Your agents already run on several platforms, and you want scanners that MuleSoft says cover Amazon, Google, Microsoft, and more.Source 8, Source 34
- You want third-party agents governed at the communication layer, which MuleSoft says needs no changes to the agents.Source 10
- You already use MuleSoft: Agent Fabric uses Anypoint Platform access management, and MuleSoft cites hundreds of enterprise connectors.Source 2, Source 10
- You want brokers to orchestrate A2A-compliant agents across ecosystems, and caps on each caller’s model spend.Source 8, Source 9
Questions buyers ask
Can either one govern agents built on other platforms?
AWS says Agent Registry can list agents on AgentCore, other providers, or on premises; Observability shows outside agents’ metrics after extra setup.Source 15, Source 56 MuleSoft says third-party agents can be governed without being modified, and that its scanners register agents from Amazon, Google, Microsoft, and more.Source 10, Source 34
How is each one priced?
Do they support MCP and A2A?
AgentCore Runtime can host MCP and A2A servers, Gateway acts as one MCP server over its MCP targets, and Agent Registry validates records against MCP and A2A schemas.Source 7, Source 38, Source 39 Omni Gateway supports both protocols, and A2A powers orchestration in MuleSoft agent networks.Source 40, Source 41
Can either one be self-hosted?
Neither publicly documents a self-hosted AgentCore or Agent Fabric control plane. AgentCore runs in AWS Regions with no infrastructure to manage.Source 1, Source 15 Agent Fabric runs on MuleSoft-hosted regional control planes; Omni Gateway can be self-managed in a data center or on EKS, GKE, or AKS.Source 43, Source 44
How we compare
Read the full methodEvery claim on this page links to a public source. Where none answers a question, the page says so.
We re-check every fact at least every 90 days. This page was last checked .
Something wrong or out of date? Tell us and we’ll correct it.
Sources
63 public sources, each with the date we checked it. Every one opens in a new tab.
Source 1: Overview - Amazon Bedrock AgentCore (Developer Guide) Back:abcdefghijklmnopqr
Source 4: MuleSoft Pricing | Plans From $2,000 a Month Back:abcdefg
Source 5: AWS Agent Registry: Discover and manage agents, tools, and resources Back:abcdef
Source 6: Policy in Amazon Bedrock AgentCore: Control Agent Interactions Back:abcdefg
Source 7: Key capabilities - AWS Agent Registry Back:abcdefg
Source 8: Agent Fabric Overview Back:abcdefghijklmnopqrstuvwxyz27
Source 10: See Every Agent. Govern Every Agent. Control AI Costs. (mulesoft.com home page) Back:abcdefghijkl
Source 12: Provide identity and credential management for agent applications with Amazon Bedrock AgentCore Identity Back:abcd
Source 13: HTTP passthrough targets - AgentCore Gateway Back:abc
Source 14: Sharing a registry across accounts with AWS RAM Back:abcde
Source 17: Release notes - Amazon Bedrock AgentCore Back:abcd
Source 20: Deploying Agent Network Ingress and Egress Managed Omni Gateways Back:abc
Source 21: Resource-based policies for Amazon Bedrock AgentCore Back:ab
Source 22: Connect to private resources in your VPC using VPC Lattice Back to text
Source 23: Use interface VPC endpoints (AWS PrivateLink) with Amazon Bedrock AgentCore Back to text
Source 24: Overview of Amazon Bedrock AgentCore Identity Back to text
Source 26: OAuth 2.0 OBO Credential Injection Policy Back to text
Source 28: Log Amazon Bedrock AgentCore Gateway API calls with CloudTrail Back:ab
Source 29: Enable CloudTrail data event logging for Amazon Bedrock AgentCore Gateway resources - Amazon Bedrock AgentCore Back:ab
Source 31: Compliance validation for Amazon Bedrock AgentCore Back:abc
Source 32: Federal Risk and Authorization Management Program (FedRAMP) - Services in Scope - Amazon Web Services Back:ab
Source 34: MuleSoft Agent Fabric | Agent Governance and Orchestration Back:abcd
Source 35: Concepts and terminology - AWS Agent Registry Back to text
Source 36: Authenticate and authorize with Inbound Auth and Outbound Auth Back to text
Source 38: Understand the AgentCore Runtime service contract Back:ab
Source 39: Supported targets for Amazon Bedrock AgentCore gateways Back:ab
Source 40: Securing Agent Interactions with Omni Gateway Back:ab
Source 42: Cross-region inference in AgentCore Memory, Policy in AgentCore, and AgentCore Evaluations Back to text
Source 46: MuleSoft Cloud Offerings Service Level Agreement (SLA) for subscriptions with an Order Start Date on or before May 1, 2025 Back to text
Source 47: MuleSoft Subscription Plans - effective for Customer purchases made from Salesforce on or after June 27, 2025 Back to text
Source 48: Get started with Amazon Bedrock AgentCore Back:abc
Source 51: Amazon Bedrock AgentCore Gateway: A secure AI gateway for agents, tools, and models Back to text
Source 52: Enhanced MuleSoft Experience Overview Back to text
Source 53: Deploy A2A servers in AgentCore Runtime Back to text
Source 55: Enhanced MuleSoft Experience Release Notes Back to text
Source 56: Add observability to your Amazon Bedrock AgentCore resources Back to text