Task 2 · 8 tasks
AgentCore Gateway
Put a single, governed front door in front of your tools, with semantic tool search.
The “Tool Discovery” challenge
Today there's one tool server. Tomorrow there'll be ten, each with its own auth. Alice's agent should talk to one endpoint that knows every tool and handles credentials for it.
What the platform provisions for you
uv run bootcamp.py up 2- An AgentCore Gateway (MCP) with inbound JWT auth and semantic tool search enabled
- An OAuth credential provider, so the Gateway can get its own token to call your MCP runtime
- A target named
DataStreamDatabasepointing at your MCP runtime
What you do as a developer
Find your tool through the Gateway
Through the Gateway your tool is exposed as
DataStreamDatabase___query_db(target name, three underscores, tool name). If you addedlist_tablesin Task 1 it appears asDataStreamDatabase___list_tables.terminaluv run bootcamp.py test --only 2Make a guard that survives the rename
Challenge
The agent's read-only guard must recognise
query_dbwhether it is called directly or through the Gateway. Write the condition that decides whether a tool call is the database tool.Hint 1
Gateway tool names follow the pattern
<Target>___<tool>. The guard reads the name fromevent.tool_use["name"].Hint 2
An equality check breaks behind the Gateway; a suffix check works in both places.
Solution
phase2/app/agent/agent.py (ReadOnlyGuardHook.guard)if not event.tool_use.get("name", "").endswith("query_db"): returnExperiments
- Semantic search lets an agent ask the Gateway “which tool finds employee data?” instead of loading every schema. When does that matter for cost and accuracy?
- Inbound auth (agent to Gateway) and outbound auth (Gateway to target) are separate. Why is that useful when targets are third-party APIs?
Re-test
Your guard change goes live when the agent is deployed in Task 4. For now, check the Gateway:
terminaluv run bootcamp.py test --only 2
Check your work
uv run bootcamp.py test --only 2Passes when the Gateway lists DataStreamDatabase___query_db.
Under the hood
AgentCore Gateway is a managed MCP endpoint that aggregates targets (MCP servers, Lambda functions, OpenAPI or Smithy APIs) into one tool catalogue. It validates inbound JWTs, then uses an OAuth2 credential provider from AgentCore Identity to fetch a client-credentials token for each outbound call. A Gateway IAM role lets it invoke your runtime. Semantic search adds a built-in search tool backed by embeddings of the tool descriptions, which is another reason docstrings matter.