From 1111658e16cea78af5509d4dd9a9ca4b0e610b9e Mon Sep 17 00:00:00 2001 From: mateo-berri <277851410+mateo-berri@users.noreply.github.com> Date: Mon, 14 Sep 2026 21:31:45 -0700 Subject: [PATCH] fix(bedrock): grant the AgentCore for-user invoke action in the web identity session policy The chat and A2A AgentCore handlers send X-Amzn-Bedrock-AgentCore-Runtime-User-Id when runtimeUserId is set, and AWS requires bedrock-agentcore:InvokeAgentRuntimeForUser alongside InvokeAgentRuntime on that call, so the ceiling now carries both. The role identity policy still decides whether a given role may use it The invalid-token test now uses a neutral example audience --- litellm/llms/bedrock/base_aws_llm.py | 1 + .../llms/bedrock/test_web_identity_session_policy.py | 5 ++++- 2 files changed, 5 insertions(+), 1 deletion(-) diff --git a/litellm/llms/bedrock/base_aws_llm.py b/litellm/llms/bedrock/base_aws_llm.py index 70869f69e3a..385d5898569 100644 --- a/litellm/llms/bedrock/base_aws_llm.py +++ b/litellm/llms/bedrock/base_aws_llm.py @@ -133,6 +133,7 @@ _WEB_IDENTITY_SESSION_POLICY_ACTIONS: Final[Mapping[str, tuple[str, ...]]] = Map ), "BedrockAgentCoreLiteLLM": ( "bedrock-agentcore:InvokeAgentRuntime", + "bedrock-agentcore:InvokeAgentRuntimeForUser", "bedrock-agentcore:InvokeGateway", ), "ClaudePlatformLiteLLM": ( diff --git a/tests/test_litellm/llms/bedrock/test_web_identity_session_policy.py b/tests/test_litellm/llms/bedrock/test_web_identity_session_policy.py index 2e84c3ca36a..cbb69b4ceed 100644 --- a/tests/test_litellm/llms/bedrock/test_web_identity_session_policy.py +++ b/tests/test_litellm/llms/bedrock/test_web_identity_session_policy.py @@ -230,7 +230,7 @@ class TestInvalidIdentityTokenSurfacesAudience: operator can diagnose the mismatch without enabling LITELLM_LOG=DEBUG on a prod instance.""" - _AUD = "https://guidepoint.litellm-prod.ai" + _AUD = "https://gateway.example.com" _ISS = "https://accounts.google.com" _STS_MESSAGE = ( "An error occurred (InvalidIdentityToken) when calling the " @@ -322,6 +322,9 @@ _BEDROCK_ROUTE_ACTIONS: Final = MappingProxyType( "knowledgebases": "bedrock:ListKnowledgeBases", "agents/{agent_id}/agentAliases/{alias_id}/sessions/{session_id}/text": "bedrock:InvokeAgent", "runtimes/{agent_runtime_arn}/invocations": "bedrock-agentcore:InvokeAgentRuntime", + "runtimes/{agent_runtime_arn}/invocations with X-Amzn-Bedrock-AgentCore-Runtime-User-Id": ( + "bedrock-agentcore:InvokeAgentRuntimeForUser" + ), "mcp": "bedrock-agentcore:InvokeGateway", } )