Amazon Bedrock AgentCore Identity supports BYO secrets with Secrets Manager
Amazon Bedrock AgentCore Identity now allows referencing existing AWS Secrets Manager secrets directly, enhancing governance and control. Previously, secrets were service-managed, hindering custom encryption, tagging, and policy enforcement. This update enables customers to manage their secrets with their own policies and CMKs, providing full ownership and governance, and is now generally available across 14 AWS regions.
- →Reference existing AWS Secrets Manager secrets in AgentCore Identity
- →Improved governance and compliance for AgentCore Identity secrets
Features (1) ›
- Reference existing AWS Secrets Manager secrets in AgentCore Identity
Customers can now directly reference existing AWS Secrets Manager secret ARNs within AgentCore Identity Credential Providers. This allows for greater control over secret creation, encryption, tagging, and governance policies.
Enhancements (1) ›
- Improved governance and compliance for AgentCore Identity secrets
This change allows organizations with strict governance requirements to apply custom policies, use customer-managed keys (CMKs), and implement tagging strategies for secrets used by AgentCore Identity. Customers retain full ownership and control over secret management while AgentCore Identity uses them at runtime without modification.
https://aws.amazon.com/about-aws/whats-new/2026/06/agentcore-identity-secrets-manager/
Related releases
- Amazon Bedrock lowers prices for OpenAI GPT-5.6 models AWS What's New ·
- OpenAI GPT-5.6 Terra and Luna models see pricing update on Amazon Bedrock AWS What's New ·
- xAI's Grok 4.3 now available on Amazon Bedrock in AWS GovCloud AWS What's New ·
- Gemma 4 models available on Amazon Bedrock in AWS GovCloud (US-West) AWS What's New ·
- Claude Opus 5 available on AWS with zero data retention AWS What's New ·
- Claude Sonnet 5 available on Amazon Bedrock in AWS GovCloud AWS What's New ·