Amazon Bedrock AgentCore Identity now allows customers the ability to reference existing AWS Secrets Manager secret ARNs directly in AgentCore Identity Credential Providers.
Previously, AgentCore Identity used a service-managed secret approach, where secrets were created and managed by the service on the customer’s behalf. This approach prevented customers from applying resource tags on create, encrypting secrets with a customer-managed key (CMK), or applying other organization-specific governance controls at the time of secret creation — causing friction for teams with strict governance requirements.
Now, customers create and manage their secrets in AWS Secrets Manager using their own governance and compliance policies, including custom CMKs, tagging strategies, automatic rotation and resource policies, and then reference the existing secret ARN when configuring a Credential Provider in AgentCore Identity. This gives customers full ownership of how their secrets are created, classified, and governed, without changing how AgentCore Identity uses them at runtime.
Amazon Bedrock AgentCore Identity bring your own secret is now generally available in 14 AWS Regions: US East (N. Virginia), US East (Ohio), US West (Oregon), Canada (Central), Asia Pacific (Mumbai), Asia Pacific (Seoul), Asia Pacific (Singapore), Asia Pacific (Sydney), Asia Pacific (Tokyo), Europe (Frankfurt), Europe (Ireland), Europe (London), Europe (Paris), and Europe (Stockholm). To learn more, visit the Amazon Bedrock AgentCore Identity documentation.
Categories: marketing:marchitecture/security-identity-and-compliance,marketing:marchitecture/artificial-intelligence,general:products/amazon-bedrock,general:products/aws-secrets-manager
Source: Amazon Web Services
Latest Posts
- Durable Objects, Workers – New Asia-Pacific location hints: apac-ne and apac-se

- Durable Objects – Outbound connections keep Durable Objects alive

- (Updated) Upcoming change: Microsoft 365 Apps SAEC and MEC will unify [MC1274325]
![(Updated) Upcoming change: Microsoft 365 Apps SAEC and MEC will unify [MC1274325] 4 pexels mccutcheon 1148998](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Dynamics 365 Customer Service – Policy strictness control for governance rules [MC1397526]
![Dynamics 365 Customer Service - Policy strictness control for governance rules [MC1397526] 5 pexels pixabay 534174](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)



![(Updated) Upcoming change: Microsoft 365 Apps SAEC and MEC will unify [MC1274325] 4 pexels mccutcheon 1148998](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-mccutcheon-1148998-150x150.webp)
![Dynamics 365 Customer Service - Policy strictness control for governance rules [MC1397526] 5 pexels pixabay 534174](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-pixabay-534174-150x150.webp)
![Microsoft Dataverse - Create Dataverse agent users with Microsoft Entra agent identity [MC1324994] 7 Microsoft Dataverse – Create Dataverse agent users with Microsoft Entra agent identity [MC1324994]](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-pachon-in-motion-426015731-18545020-150x150.webp)