Key takeaways
- On October 2, 2026, AWS published a deployment walkthrough for connecting Claude Desktop to AgentCore Web Search through an AgentCore Gateway secured with JWTs. The Web Search product itself was already generally available; this is a new integration guide, not a model launch.
- The reference flow uses IAM Identity Center for employee sign-in, Cognito as a SAML-to-OAuth federation layer and JWT validation on every Gateway request. AWS says the query path stays within AWS infrastructure.
- AWS lists Web Search at $7 per 1,000 queries. Gateway API calls are separately listed at $0.005 per 1,000 invocations, before model inference, identity, logging and other workload costs.
- The live developer guide lists Web Search in us-east-1, eu-west-1 and ap-northeast-1. It accepts queries up to 200 characters and returns 1–25 results, with 10 as the default.
- The connector can return titles, URLs, snippets and publication dates. Version 1.2.0 adds request-level domain and publication-date filters, but retrieved web content remains untrusted input that can be stale, wrong or adversarial.
AWS published the Claude Desktop integration on October 2
AWS’s October 2, 2026 walkthrough shows enterprises how to add current-web retrieval to Claude Desktop through Amazon Bedrock AgentCore. Claude Desktop connects to an AgentCore Gateway as a managed MCP server, and the Gateway exposes Amazon’s Web Search connector as a tool. This gives the desktop client a governed route to search without placing a separate search API key on each employee device.
The date needs a qualifier: Web Search on AgentCore was already generally available before this post. AWS announced the managed connector in June 2026. October’s news is a documented Claude Desktop deployment pattern with enterprise authentication—not a new foundation model, Claude tier, search index or API launch.
The reference identity chain has three enforcement points
In the AWS design, IAM Identity Center authenticates the employee through SAML. Amazon Cognito acts as the federation layer and issues an OAuth access token. AgentCore Gateway validates the resulting JWT before it accepts tool calls. Claude Desktop is then configured with the Gateway endpoint as an administrator-managed remote MCP server.
That chain can centralize access, but it does not make authorization automatic. Operators still need to bind Cognito groups or claims to the correct users, restrict the Gateway service role, control who can alter the managed desktop configuration and decide whether the Web Search tool is allowed, requires confirmation or is blocked. Anthropic documents those per-tool policy states for managed MCP servers.
Web Search costs $7 per 1,000 queries before the rest of the stack
AWS’s current price page lists Web Search on AgentCore at $7 per 1,000 queries, or $0.007 for each submitted query. It separately lists Gateway API invocations—including operations such as ListTools, InvokeTool and Ping—at $0.005 per 1,000 calls. There is no stated minimum fee or upfront commitment.
Those figures are not a complete cost per answer. A production estimate also needs the number of searches an agent makes per user request, Gateway discovery and invocation traffic, Claude inference charges, Cognito and identity usage where applicable, logs and traces, networking, storage and failed or repeated searches. Budget with a measured query-per-task distribution rather than assuming one search per answer.
The live contract includes three regions and bounded results
The AgentCore developer guide currently lists US East (Northern Virginia), Europe (Ireland) and Asia Pacific (Tokyo): us-east-1, eu-west-1 and ap-northeast-1. The tool accepts a natural-language query up to 200 characters. maxResults ranges from 1 to 25 and defaults to 10.
Results can include a title, URL, semantically selected snippet and publication date in text and structured JSON forms. AWS says its own index spans tens of billions of documents and can reflect changed content within minutes. Those are vendor claims about the service; they are not a completeness, latency, ranking-quality or factual-accuracy guarantee.
Connector version 1.2.0 adds useful retrieval boundaries
Administrators can set target-level domain restrictions that apply to every request. With connector version 1.2.0 or later, the calling agent can also pass domain include and exclude lists of up to 100 domains each plus inclusive ISO-8601 publication-date bounds. Request filters can narrow an administrator’s target policy, but they cannot bypass an exclusion or expand beyond a target-level inclusion list.
That distinction matters for primary-source research. A team can constrain a target to approved public domains and let an agent narrow the set further for one task. Filters still do not prove authorship, truth, freshness or relevance, and a publication date may be absent. Preserve URLs and snippets, validate the final source directly and never treat retrieved text as an instruction with tool authority.
“Queries stay in AWS” is a data-path claim, not a safety certification
AWS says customer queries are served inside AWS infrastructure and are not sent to a third-party search engine. That can remove one external processor from an architecture review. It does not mean the public pages returned by search are trustworthy, that Claude cannot disclose sensitive terms placed in the query, or that every organization’s residency and retention requirements are automatically met.
Before rollout, verify the actual region, CloudTrail and application logs, Cognito configuration, token scopes, desktop policy, query content and retention controls. Redact secrets and personal data before retrieval, enforce an allowlist where the task permits it, require citations in the model output and gate consequential actions on evidence outside the generated answer.
What AI platform teams should do next
Pilot the pattern when employees already use Claude Desktop on an approved third-party inference setup and AWS is the required search boundary. Start with read-only research tasks, a small domain allowlist, short token lifetimes, least-privilege Gateway permissions, explicit per-tool policy and tests for expired tokens, inaccessible domains, empty results, missing dates and malicious page text.
Adopt only after measuring grounded-answer quality, citation validity, unsafe retrieval, query volume and total cost on representative work. Constrain high-risk teams to approved domains and human-reviewed use. Wait if the required region, retention evidence or identity integration is missing. Reject the pattern for workflows that would turn unverified web snippets directly into payments, code execution, account changes or other irreversible actions.
Copy-ready AgentCore Web Search rollout record
Complete one record per Gateway target, Claude Desktop population and retrieval policy.
Entries stay in this browser tab and are not submitted to AccessAllGPT. Blank responses are copied as [Unresolved].
Record the October 2 integration guide separately from the June Web Search availability announcement and from any Claude model release.
AWS region, organization and account IDs, Claude Desktop population, managed-device scope and data-residency requirement.
IAM Identity Center source, SAML application, Cognito pool and client, token issuer and audience, claims, lifetimes and revocation path.
Gateway ARN, service role, allowed operations, Web Search target, connector version and change owner.
Target and request domain lists, date filters, maximum results, prohibited query content and citation requirement.
Managed MCP endpoint, transport, authentication mode, per-tool allow/ask/blocked state, update path and user-extension controls.
Representative current questions, primary-source retrieval, citation resolution, stale and missing-date cases, malicious text and empty results.
Searches and Gateway calls per task, Claude inference, identity, logs, retries, monthly volume, budget alert and stop threshold.
Adopt, constrain, wait or reject; approved tasks, exclusions, owner, expiry date and evidence required for expansion.
Primary sources
Browse the publication-wide evidence index →
- Add secure Web Search to Claude Desktop with Amazon Bedrock AgentCoreAWS Machine Learning Blog · Reviewed: October 2, 2026 publication metadata; architecture; prerequisites; IAM Identity Center, Cognito and JWT flow; AgentCore Gateway setup; Web Search target; Claude Desktop managed MCP configuration; validation and cleanup · Retrieved · Supports: AWS published an enterprise integration walkthrough connecting Claude Desktop to AgentCore Web Search through AgentCore Gateway, with IAM Identity Center authentication federated through Cognito and JWT validation at the gateway.
- Web Search ToolAmazon Bedrock AgentCore Developer Guide · Reviewed: Capabilities; Amazon-operated index; privacy statement; Gateway flow; connector versions; target- and request-level filters; input schema; response fields; regions; acceptable use · Retrieved · Supports: AWS documents Web Search as a managed MCP-compatible AgentCore Gateway connector with query, result-count, domain and date controls, structured result metadata, and availability in Northern Virginia, Ireland and Tokyo.
- Amazon Bedrock AgentCore PricingAmazon Web Services · Reviewed: Web Search on AgentCore description; per-query billing; price table; Gateway API invocation price; consumption model; no-minimum-fee statement · Retrieved · Supports: AWS lists Web Search at $7 per 1,000 queries and Gateway API calls at $0.005 per 1,000 invocations, with consumption pricing and no minimum fee or upfront commitment.
- MCP, plugins, skills, and hooksClaude.ai Documentation · Reviewed: Claude Desktop on third-party platforms; managed MCP servers; transport and URL configuration; OAuth and header helpers; per-tool allow, ask and blocked policies; connection testing; redirect behavior · Retrieved · Supports: Anthropic documents administrator-managed remote MCP server configuration for Claude Desktop, including per-tool policy locks, OAuth or header-based credentials, and a live initialize and tools/list connection test.
Limitations
AccessAllGPT reviewed public AWS and Anthropic documentation but did not deploy the reference architecture, access an AWS account, create a Gateway target, configure IAM Identity Center, Cognito, SAML or OAuth, install managed Claude Desktop settings, inspect tokens, issue searches, compare results with another index, test regional routing, measure latency, relevance, freshness, safety or uptime, audit query egress or retention, validate the tens-of-billions index claim, or reproduce AWS’s within-minutes refresh statement. Prices and regions can change and do not include the full cost of Claude inference, identity, observability, networking or operations. “Inside AWS” is AWS’s architectural statement, not an independent compliance finding or assurance that sensitive query text is appropriate to send.
Disclosures
AccessAllGPT did not receive AWS, AgentCore, Claude Desktop, Anthropic, Cognito or IAM Identity Center access, credits, subscriptions, support, a briefing, review or compensation for this article. AWS and Anthropic did not sponsor, review or endorse it. AccessAllGPT Research is operated by NeuralArc, is independent, and is not affiliated with Amazon Web Services or Anthropic. Publication-wide relationships are listed on the disclosures page.
Further AccessAllGPT guidance
- Microsoft and Hugging Face Bring ThinkingBox’s Stateful Agent Workflows to OpenEnv
- ServiceNow Details AutoSynthData for Enterprise Agent Training
- AWS Publishes a Dual-Monitoring Blueprint for Production AI Agents
- Claude Bedrock Inference Expands in Asia
- AI API Data Retention and Residency Procurement Gates
- Where Human Approval Belongs in AI Automation
- AccessAllGPT Research methodology
- Publication disclosures
Continue the research
Get evidence-led updates for teams making production AI decisions.