Amazon Bedrock Managed Agents Powered by OpenAI: Pricing, Regions, IAM, AgentCore and Limits
AWS and OpenAI have moved Bedrock Managed Agents into public preview. Here’s what actually runs in AWS, how IAM and AgentCore fit together, what the preview costs, and the limitations you need to know before building on it.
Published October 6, 2026 · Digital Pulse Brief · Source-checked against AWS and OpenAI documentation
Image credit: Amazon / AWS. Official AWS and OpenAI editorial artwork from Amazon’s announcement coverage.
Amazon Bedrock Managed Agents, powered by OpenAI, is now in public preview. The service adapts OpenAI’s Agents API for AWS, keeps model inference inside Amazon Bedrock, and lets developers run the agent’s commands and tools either on their own compute or in Amazon Bedrock AgentCore Runtime.
The important part is not simply that “OpenAI agents now run on AWS.” Bedrock Managed Agents (BMA) changes the operational model: AWS handles the stateful agent session and OpenAI-optimized harness, while IAM, SigV4 authentication, CloudTrail-supported auditing, human approvals and AWS-managed compute can sit around the workload.
| Status | Public preview |
| Built with | A customized, AWS-native version of OpenAI’s Agents API / agent harness |
| Model inference | Amazon Bedrock |
| Execution environment | Self-hosted compute or Amazon Bedrock AgentCore Runtime |
| Authentication | AWS IAM credentials with SigV4 signing |
| Preview regions | US East (N. Virginia), US West (Oregon), US East (Ohio) |
| BMA service charge in preview | No additional BMA charge; model inference and underlying AWS resources still cost money |
Verified October 6, 2026 against AWS’s launch announcement and preview documentation, OpenAI’s Bedrock Managed Agents comparison guide, and current Google/AdSense guidance. Public-preview APIs, limits and pricing can change.
What is Amazon Bedrock Managed Agents powered by OpenAI?
Bedrock Managed Agents is a joint AWS–OpenAI service for building stateful OpenAI-powered agents on Amazon Bedrock. AWS says the preview is based on a customized version of OpenAI’s Agents API that has been engineered to work with AWS identity, permissions and governance controls.
A developer creates a session, chooses an eligible OpenAI model, provides instructions and an execution environment, and sends messages to the session. The managed service coordinates the model interaction and agent loop. When the agent needs to run shell commands, work with files or use local tools, that work happens in the execution environment you provide.
That division is central to understanding the product. The agent harness and model inference are hosted in Amazon Bedrock; the commands and local tools run in either AgentCore Runtime or your self-hosted compute.
How the architecture works
Creates a session and submits work to the regional BMA endpoint using AWS credentials.
Maintains the session, coordinates reasoning, selects tools and invokes an eligible OpenAI model through Bedrock.
AgentCore Runtime or self-hosted compute executes commands, reads files and exposes local MCP tools.
Events stream progress; session items preserve messages, command results and MCP calls for later inspection.
A BMA session is stateful. AWS documents session states such as idle, in_progress and failed, and the session can be reused for follow-up work. Durable items can include user and assistant messages, reasoning summaries, command execution and MCP tool calls.
That makes BMA different from a simple one-shot model request. It is designed for work that can span multiple decisions and tool calls, such as investigating a codebase, processing documents or generating files.

Image credit: Amazon Web Services. Official OpenAI on Amazon Bedrock product artwork.
AgentCore Runtime vs self-hosted compute
AWS supports two execution patterns in the preview.
| Option | What you provide | Best fit |
|---|---|---|
| Self-hosted compute | A host, workspace, network access and the Codex exec server | Local development, existing containers, private infrastructure or highly customized environments |
| AgentCore Runtime | An AgentCore Runtime containing the exec server and adapter | Managed runtime sessions with AWS-controlled execution roles, VPC connectivity and configurable storage |
AWS’s AgentCore tutorial says each session can run in its own microVM, under an execution role you control. The Runtime can connect to a VPC so an agent can reach private AWS resources. Model calls remain in Bedrock Managed Agents; the Runtime receives the commands the harness wants executed.
This separation gives teams a cleaner trust boundary than putting every capability into a single model endpoint. It also means security depends on both sides: the BMA session role and the permissions, files, credentials and network routes available inside the execution environment.
IAM, SigV4, approvals and CloudTrail
BMA does not use an OpenAI API key for its AWS-side API requests. The preview uses AWS Signature Version 4 with the regional bedrock-mantle service endpoint.
AWS recommends separating three identities:
- The caller identity that sends BMA API requests.
- The session role that BMA assumes for authorized operations such as model inference and, when configured, AgentCore activation.
- The execution-environment identity used by the compute that runs commands and local tools.
This matters because an agent should not automatically inherit every permission held by the application, administrator or runtime. Least-privilege roles reduce the blast radius if an instruction, tool or generated command behaves unexpectedly.
AWS also says each agent can use human approval before consequential actions, and supported BMA API activity is recorded through AWS CloudTrail. Those controls are useful, but they are not a substitute for application-level authorization, tool allowlists or environment isolation.
Sessions, skills and MCP support
The current preview supports durable sessions, filesystem-based skills and environment-based STDIO Model Context Protocol servers.
Skills let teams package repeatable procedures that an agent can discover and use. MCP servers expose tools to the agent. Together, they make it possible to keep operational instructions and tool integrations reusable instead of embedding every procedure into one large prompt.
There is an important memory nuance. AWS’s product messaging describes persistent memory as part of the managed-agent experience, while the technical preview documentation draws a narrower boundary: the preview maintains session conversation, but it does not provide a built-in long-term memory integration across separate sessions. Workspace files also have a lifecycle separate from the BMA session itself.
For developers, the safe interpretation is simple: treat session state as durable within the documented session model, but do not design a production memory architecture around capabilities that the preview documentation does not yet expose.
Amazon Bedrock Managed Agents pricing: what is free and what still costs money?
During public preview, AWS says there is no additional charge for the BMA service itself beyond the underlying AWS resources your agents consume. AWS also says pricing may change at general availability.
That does not mean an agent is free to run. You can still incur charges for:
- OpenAI model inference through Amazon Bedrock.
- Amazon Bedrock AgentCore Runtime where used.
- Storage created for the runtime or workspace.
- Networking resources.
- Other AWS services the agent invokes.
For teams evaluating BMA, the useful cost comparison is therefore not “BMA fee versus OpenAI fee.” It is the total cost of model inference plus the runtime, networking, storage, observability and supporting AWS services required by your workload.
Which AWS regions support BMA?
The public preview is currently available in three AWS regions:
| AWS Region | Code | Preview endpoint |
|---|---|---|
| US East (N. Virginia) | us-east-1 | bedrock-mantle.us-east-1.api.aws |
| US West (Oregon) | us-west-2 | bedrock-mantle.us-west-2.api.aws |
| US East (Ohio) | us-east-2 | bedrock-mantle.us-east-2.api.aws |
Session operations use the /openai/v1/agents/sessions path. Model discovery uses /v1/models. AWS notes that model availability can differ by region and account, so the presence of an OpenAI model elsewhere in Bedrock does not automatically mean it is BMA-compatible in your selected region.
Which OpenAI models work with Bedrock Managed Agents?
AWS does not publish one permanent universal list in the preview overview because supported models can vary by region and account. The current setup documentation uses openai.gpt-5.6-luna as the example/default model and tells developers to query the endpoint’s model catalog before relying on a specific model.
The important caveat is that a model appearing in the Bedrock Mantle model catalog is not, by itself, proof that it supports BMA. Your account also needs model access and the session role must have the required inference permissions.
If you are comparing OpenAI’s current model options more broadly, our GPT-6 Sol vs Luna comparison covers pricing, capability and workload trade-offs, while our OpenAI DevDay 2026 recap summarizes the latest developer-platform changes.
The preview limitations that matter
The “managed” label can make the service sound more complete than the current preview actually is. AWS documents several boundaries that teams should account for before building around it:
| Area | Current public-preview behavior |
|---|---|
| Input | The documented session-input surface is text. |
| Subagents | Not supported in the documented BMA preview workflow. |
| Programmatic tool calling / code mode | Not included in the supported preview workflow. |
| Cross-region inference profiles | Not supported. |
| Long-term memory | No built-in long-term memory integration in the preview; session conversation and workspace files have separate lifecycles. |
| Session-data KMS key | The preview does not expose a customer-managed key setting for service-managed session data. |
| Console workflow | AWS’s current preview procedures rely on APIs and supplied deployment examples. |
AWS also warns that feature parity with the OpenAI-hosted Agents API should not be assumed. The two platforms share agent and session concepts, but their API contracts, model availability, tools and execution environments can differ.
Bedrock Managed Agents vs OpenAI Agents API
| Area | OpenAI Agents API | Bedrock Managed Agents |
|---|---|---|
| Agent loop | Managed by OpenAI | Hosted in Amazon Bedrock |
| Model inference | OpenAI API | Amazon Bedrock |
| Authentication | OpenAI project API key | AWS IAM credentials + SigV4 |
| Execution environment | OpenAI-hosted sandbox, self-hosted sandbox or no sandbox | AgentCore Runtime or self-hosted compute |
| Operational fit | Teams standardized on OpenAI’s platform and hosted agent infrastructure | AWS-centric teams that want OpenAI agent capabilities under AWS identity and infrastructure controls |
Choosing a self-hosted execution environment does not make the two products equivalent. OpenAI’s own documentation notes that an OpenAI Agents API self-hosted sandbox still uses OpenAI’s managed harness and inference service, while BMA moves the harness and model inference to Amazon Bedrock.
Bedrock Managed Agents vs AgentCore: they are complementary, not interchangeable
Amazon Bedrock AgentCore is a broader infrastructure platform that works with different models and agent frameworks. Bedrock Managed Agents is a more opinionated OpenAI-optimized managed harness.
If your organization wants to build with LangGraph, CrewAI, Strands, custom agent frameworks or non-OpenAI models, AgentCore is the more general platform. If you specifically want OpenAI’s agent harness and OpenAI frontier models while keeping inference and identity under Bedrock, BMA is the more direct fit.
They can also be used together: AgentCore Runtime is one of the two supported execution environments for BMA. For a separate AWS agent product focused on cloud architecture analysis, see our AWS Well-Architected Agent explainer.
Who should try BMA now — and who should wait?
- AWS-heavy organizations already using IAM, CloudTrail and VPC controls
- Teams evaluating OpenAI agents for multi-step enterprise workflows
- Developers who need stateful sessions, skills and MCP tools
- Organizations comfortable testing preview APIs and changing integration code later
- Production workloads that require stable GA contracts today
- Projects that depend on subagents in the current implementation
- Architectures needing cross-region BMA inference profiles
- Teams requiring built-in long-term memory across separate sessions
- Developers who need a full console-first workflow rather than preview APIs
What you need to start testing
AWS’s preview prerequisites currently include Node.js 20 or later, AWS CLI v2, Bash, curl with SigV4 support, jq and Codex CLI 0.154.0 or later. The AgentCore example adds Python 3 and Docker with Linux ARM64 build support.
You also need an AWS identity with the necessary permissions, a supported BMA region, access to a compatible OpenAI model, and an execution environment. AWS’s current AgentCore getting-started guide uses openai.gpt-5.6-luna as its model example.
For a production evaluation, do not stop at “the sample ran.” Validate the session role, execution role, VPC/network path, tool permissions, approval boundaries, logging, cleanup behavior and actual resource cost under your expected workload.
Why this launch matters beyond AWS developers
The broader shift is architectural. AI platforms are moving from stateless “prompt in, answer out” APIs toward durable execution systems that can hold context, use tools, work with files and continue over time. BMA is AWS and OpenAI’s answer to organizations that want that agent runtime while retaining AWS-native identity and infrastructure controls.
It also increases competitive pressure inside the enterprise-agent market. AWS is effectively giving customers multiple layers to choose from: general-purpose Bedrock model access, AgentCore for framework-neutral agent infrastructure, traditional Bedrock Agents, and now an OpenAI-optimized managed-agent path.
That flexibility is useful, but it raises the importance of choosing the right abstraction. Teams should start from the workload and governance requirement—not from the newest agent label.
Frequently asked questions
Is Amazon Bedrock Managed Agents generally available?
No. It is currently in public preview. AWS says preview functionality and APIs can change before general availability.
Does BMA cost extra during preview?
AWS says there is no additional BMA service charge during the preview. You still pay for model inference and the AWS resources your agent uses, including AgentCore, storage, networking and any downstream services.
Does BMA require an OpenAI API key?
Not for the BMA API. The preview authenticates AWS-side requests with AWS IAM credentials and Signature Version 4.
Can BMA use MCP servers?
Yes, the documented preview supports environment-based STDIO MCP servers. The agent can also use filesystem-based skills for reusable procedures.
Can I run Bedrock Managed Agents outside AWS?
The agent harness and model inference run in Amazon Bedrock. The execution environment can be self-hosted, which may be a development machine, container or other compute environment you operate.
Is BMA the same as Amazon Bedrock AgentCore?
No. AgentCore is a broader platform for running and operating agents built with different models and frameworks. BMA is optimized around OpenAI’s agent harness and OpenAI models on Bedrock. AgentCore Runtime can be used as BMA’s managed execution environment.
Bottom line
Amazon Bedrock Managed Agents is a significant step in the AWS–OpenAI partnership because it moves beyond simply hosting OpenAI models. AWS now has a managed path for the full stateful agent loop: durable sessions, OpenAI’s harness, AWS IAM, execution environments, skills and MCP-based tools.
The strongest reason to test it is operational fit. If your organization already governs workloads through AWS accounts, IAM roles, VPCs and CloudTrail, BMA can reduce the amount of new infrastructure and identity plumbing required to experiment with OpenAI-powered agents.
The strongest reason to be cautious is equally clear: this is still a preview. Region coverage is narrow, some Agents API capabilities are missing, pricing can change, and the current technical documentation explicitly limits features such as subagents and built-in long-term memory.
For experiments and architecture evaluation, BMA is worth understanding now. For critical production systems, teams should treat the public preview as a moving platform and design for change.
- AWS — Bedrock Managed Agents powered by OpenAI public preview announcement
- AWS Documentation — Amazon Bedrock Managed Agents powered by OpenAI
- AWS Documentation — Preview availability and limitations
- AWS Documentation — Security and IAM roles
- OpenAI — Bedrock Managed Agents comparison with the Agents API
- Amazon — AWS and OpenAI partnership and Bedrock Managed Agents overview
Related Digital Pulse Brief coverage
- AWS Well-Architected Agent Explained: Pricing, Permissions, Limits and What It Can Actually Do
- OpenAI DevDay 2026 Recap: GPT-6.1 Sol, Agents API and Key Announcements
- GPT-6 Sol vs GPT-6 Luna: Pricing, Benchmarks, Availability and Which Model Fits Your Work
- NVIDIA OpenShell and Sentry Explained: AI Agent Security, Requirements and Limits
Independent coverage of AI, software, cybersecurity and cloud infrastructure — explained clearly and sourced to primary documentation.
Get clear AI, technology and business insights in your inbox
Breaking developments, practical explainers, reviews and useful tech intelligence — without the noise.
OpenAI textGrain Watermarking Explained: What Changes for ChatGPT, Codex and API Users
Claude Sonnet 5.5 vs Opus 5.5: Price, Benchmarks, Coding and Which Model to Use
