aws / aws/agentcore-cli

feat(gateway-target): allow GATEWAY_IAM_ROLE outbound auth on mcpServer / openApiSchema targets (iamCredentialProvider)

Open
#2,245 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
283
Forks
95
Avg merge
1d 2h
Merged PRs (30d)
183

Description

### Description

Gateway supports IAM outbound auth to MCP server and OpenAPI targets — the gateway signs with SigV4 via its service role. Per [Set up outbound authorization for your gateway](https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway-outbound-auth.html), these two target types take a `GATEWAY_IAM_ROLE` credential provider plus an `iamCredentialProvider` block (`service` required — `bedrock-agentcore` for MCP servers on AgentCore Runtime; `region` optional). Lambda / API Gateway / Smithy take the bare `credentialProviderType` with no `iamCredentialProvider`.

`TARGET_TYPE_AUTH_CONFIG` in `src/schema/schemas/mcp.ts` doesn't allow it: `mcpServer` is `OAUTH | NONE`, `openApiSchema` is `OAUTH | API_KEY`. Only `passthrough` gets `GATEWAY_IAM_ROLE`. So there's no way to put an IAM-auth MCP server hosted on AgentCore Runtime behind a gateway — it forces an OAuth provider in front of a runtime that already authenticates with SigV4.

It's a schema block, not just a missing flag — hand-editing `agentcore.json` fails too:

```
$ agentcore validate
- agentCoreGateways[0].targets[0].outboundAuth:
mcpServer targets do not support GATEWAY_IAM_ROLE outbound auth
```

Separately, the flag surface reports the wrong reason — the guard exempts only `NONE`, so `GATEWAY_IAM_ROLE` and `JWT_PASSTHROUGH` fall through into the OAuth credential requirement:

```
$ agentcore add gateway-target --type mcp-server --outbound-auth gateway-iam-role \
--signing-service bedrock-agentcore ...
--credential-name or inline OAuth fields (--oauth-client-id, --oauth-client-secret,
--oauth-discovery-url) required when outbound auth type is gateway-iam-role
```

### Acceptance Criteria

- [ ] `TARGET_TYPE_AUTH_CONFIG` allows `GATEWAY_IAM_ROLE` on `mcpServer` and `openApiSchema`, with `service` required there and rejected for Lambda / API Gateway / Smithy
- [ ] `--signing-service` / `--signing-region` accepted for these types, not just `passthrough`
- [ ] flag validator exempts `GATEWAY_IAM_ROLE` / `JWT_PASSTHROUGH` from the credential requirement
- [ ] L3 `buildCredentialConfig()` emits the `iamCredentialProvider` block for these types (today it returns `undefined` outside the passthrough branch — the #1005 failure shape)
- [ ] `--help` Auth table and TUI option list updated

### Additional Context

- `@aws/agentcore` 0.28.1, `@aws/agentcore-cdk` 0.1.0-alpha.50, `aws-cdk-lib` 2.261.0.
- Reproduced at config / `validate` level only; I haven't run a live `CreateGatewayTarget` with this shape.
- Related: #1359 (same map, `API_KEY`). Note #1914/#1915 recorded "mcpServer supports only OAuth or none" — accurate to the validator, but the doc above allows IAM.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.