Add Secure Web Search to Claude Desktop with Amazon Bedrock AgentCore
A new integration guide details how to bridge Claude Desktop on Amazon Bedrock with secure, managed web search capabilities using Amazon Bedrock AgentCore Gateway and enterprise identity management.

Overcoming Knowledge Cutoffs in Claude Desktop
Claude Desktop on Amazon Bedrock provides powerful AI assistance, but its default responses are strictly limited to the model’s training knowledge cutoff. When users require current information—such as live pricing, weather updates, or recent documentation changes—the model cannot retrieve it independently.
To bridge this gap, developers can leverage Amazon Bedrock AgentCore, a platform designed to build, connect, and optimize agents at scale using any framework or model. Specifically, AgentCore Gateway allows organizations to connect Claude Desktop directly to Web Search.

Architecture and Infrastructure Security
The Web Search capability is a fully managed, Model Context Protocol-compatible tool backed by an extensive Amazon web index that spans tens of billions of documents. Crucially, all query traffic remains securely within AWS infrastructure, eliminating the need to manage external API keys or let queries leave the organizational boundary.
Using managed MCP servers, users can connect Claude Desktop straight to an AgentCore Gateway configured with the Web Search target enabled. This setup ensures seamless integration while maintaining strict enterprise compliance and data governance standards.

Enterprise Authentication with AWS IAM and Cognito
Many enterprises operating on AWS rely on AWS IAM Identity Center for single sign-on access to their environments. By using this service as the primary authentication source for the AgentCore Gateway, Claude Desktop can invoke web search queries through a trusted, enterprise-managed identity flow without requiring separate credentials or third-party identity providers.
To connect IAM Identity Center with the gateway's JSON Web Token-based authentication, Amazon Cognito functions as a federation layer implementing the OAuth 2.0 authorization code grant flow. While IAM Identity Center handles user authentication via Security Assertion Markup Language (SAML), Cognito issues the necessary JWTs which the gateway validates on each request.

Prerequisites and Regional Availability
Deploying this architecture requires an AWS account with proper permissions to configure AWS Identity and Access Management roles and Amazon Bedrock AgentCore resources. Administrators also need access to their AWS Organizations management account, a preconfigured IAM Identity Center setup, Claude Desktop configured with Amazon Bedrock as the inference provider, and the AWS Command Line Interface v2 installed.
Web Search on Amazon Bedrock AgentCore is currently available in specific global areas, including the US East (N. Virginia), Europe (Ireland), and Asia Pacific (Tokyo) AWS Regions. Teams must verify that their gateway resources are deployed within one of these supported regions before proceeding with configuration.

Step-by-Step Configuration Workflow
The deployment process involves establishing the complete authentication chain from IAM Identity Center to Amazon Cognito and down to JWT validation, followed by wiring the AgentCore Gateway into Claude Desktop. First, administrators create a Cognito user pool to act as the OpenID Connect token issuer.
Next, a SAML application is created within the AWS Organizations management account to federate with Cognito, mapping attributes like subject and email fields. After registering IAM Identity Center as a SAML identity provider and setting up a Cognito app client with a client secret, engineers can configure the AgentCore Gateway using a Python script with JSON Web Token inbound authorization.
Finally, users access the Claude Desktop configuration window, navigate to connectors and extensions, add a blank server, and supply the gateway resource URL, client ID, client secret, and authorization server endpoints. Completing this allows users to sign in and test the secure workflow via their standard SSO credentials.
Sources
- AWS Machine Learning BlogAdd secure Web Search to Claude Desktop with Amazon Bedrock AgentCore
Continue chronologically





