Skip to main content

AgentCore Gateway

Gateway is the AgentCore access boundary. It has two distinct paths: TokenHub Gateway for models and Tool Gateway for tools and external services.

Two Gateway paths​

Agent
├── TokenHub Gateway ──> LLM / embedding / rerank / multimodal models
└── Tool Gateway ──────> API / function / MCP / external agent / enterprise service

Distinction​

DimensionTokenHub GatewayTool Gateway
CallsLLM, embedding, rerank, image, and speech modelsAPIs, functions, MCP tools, other agents, or enterprise services
CapabilityAgentCore model-access component; also independently usableAgentCore tool-access component
Current statusAvailable todayIn development
GovernanceAPI keys, protocol, rate, timeout, fallback, and token usageIdentity, authorization, discovery, policy, and execution audit
Runtime relationshipModel egress for an agent or RuntimeMay become a Runtime tool egress

Current integration choices​

  • Use TokenHub protocol APIs when an application calls a model.
  • A backend agent can execute tools in its own loop and return results to the model.
  • Use AgentCore LTM for durable state; Gateway is not a memory system.
  • Until the Tool Gateway contract is stable, follow the relevant product integration docs for resources and APIs.

Design principles​

  • Gateway is an access boundary, not the tool, model, agent state, or Runtime.
  • Model and tool calls can be composed, but authentication, errors, and audit responsibilities remain explicit.
  • Future Agent API, Runtime, and Tool Gateway contracts must state current availability clearly.