aws AWS What's New ·

Amazon Bedrock AgentCore Identity supports BYO secrets with Secrets Manager

aiawsgaengineeraws-bedrock
feature announcement

Amazon Bedrock AgentCore Identity now allows referencing existing AWS Secrets Manager secrets directly, enhancing governance and control. Previously, secrets were service-managed, hindering custom encryption, tagging, and policy enforcement. This update enables customers to manage their secrets with their own policies and CMKs, providing full ownership and governance, and is now generally available across 14 AWS regions.

  • Reference existing AWS Secrets Manager secrets in AgentCore Identity
  • Improved governance and compliance for AgentCore Identity secrets
Features (1)
  • Reference existing AWS Secrets Manager secrets in AgentCore Identity

    Customers can now directly reference existing AWS Secrets Manager secret ARNs within AgentCore Identity Credential Providers. This allows for greater control over secret creation, encryption, tagging, and governance policies.

Enhancements (1)
  • Improved governance and compliance for AgentCore Identity secrets

    This change allows organizations with strict governance requirements to apply custom policies, use customer-managed keys (CMKs), and implement tagging strategies for secrets used by AgentCore Identity. Customers retain full ownership and control over secret management while AgentCore Identity uses them at runtime without modification.

Read the original announcement →

https://aws.amazon.com/about-aws/whats-new/2026/06/agentcore-identity-secrets-manager/

Related releases