Task 2 · 8 tasks

AgentCore Gateway

Put a single, governed front door in front of your tools, with semantic tool search.

20 minMedium
Alice’s ask

The “Tool Discovery” challenge

Today there's one tool server. Tomorrow there'll be ten, each with its own auth. Alice's agent should talk to one endpoint that knows every tool and handles credentials for it.

Platform

What the platform provisions for you

terminal
uv run bootcamp.py up 2
  • An AgentCore Gateway (MCP) with inbound JWT auth and semantic tool search enabled
  • An OAuth credential provider, so the Gateway can get its own token to call your MCP runtime
  • A target named DataStreamDatabase pointing at your MCP runtime
You

What you do as a developer

  1. Find your tool through the Gateway

    Through the Gateway your tool is exposed as DataStreamDatabase___query_db (target name, three underscores, tool name). If you added list_tables in Task 1 it appears as DataStreamDatabase___list_tables.

    terminal
    uv run bootcamp.py test --only 2
  2. Make a guard that survives the rename

    Challenge

    The agent's read-only guard must recognise query_db whether it is called directly or through the Gateway. Write the condition that decides whether a tool call is the database tool.

    Hint 1

    Gateway tool names follow the pattern <Target>___<tool>. The guard reads the name from event.tool_use["name"].

    Hint 2

    An equality check breaks behind the Gateway; a suffix check works in both places.

    Solution
    phase2/app/agent/agent.py (ReadOnlyGuardHook.guard)
    if not event.tool_use.get("name", "").endswith("query_db"):
        return
  3. Experiments

    • Semantic search lets an agent ask the Gateway “which tool finds employee data?” instead of loading every schema. When does that matter for cost and accuracy?
    • Inbound auth (agent to Gateway) and outbound auth (Gateway to target) are separate. Why is that useful when targets are third-party APIs?
  4. Re-test

    Your guard change goes live when the agent is deployed in Task 4. For now, check the Gateway:

    terminal
    uv run bootcamp.py test --only 2

Check your work

terminal
uv run bootcamp.py test --only 2

Passes when the Gateway lists DataStreamDatabase___query_db.

Under the hood

AgentCore Gateway is a managed MCP endpoint that aggregates targets (MCP servers, Lambda functions, OpenAPI or Smithy APIs) into one tool catalogue. It validates inbound JWTs, then uses an OAuth2 credential provider from AgentCore Identity to fetch a client-credentials token for each outbound call. A Gateway IAM role lets it invoke your runtime. Semantic search adds a built-in search tool backed by embeddings of the tool descriptions, which is another reason docstrings matter.