BedrockAgentCoreControl / Client / create_code_interpreter

create_code_interpreter

BedrockAgentCoreControl.Client.create_code_interpreter(**kwargs)

Creates a custom code interpreter.

See also: AWS API Documentation

Request Syntax

response = client.create_code_interpreter(
    name='string',
    description='string',
    executionRoleArn='string',
    networkConfiguration={
        'networkMode': 'PUBLIC'|'SANDBOX'|'VPC',
        'vpcConfig': {
            'securityGroups': [
                'string',
            ],
            'subnets': [
                'string',
            ],
            'requireServiceS3Endpoint': True|False
        }
    },
    certificates=[
        {
            'location': {
                'secretsManager': {
                    'secretArn': 'string'
                }
            }
        },
    ],
    clientToken='string',
    tags={
        'string': 'string'
    }
)
Parameters:
  • name (string) –

    [REQUIRED]

    The name of the code interpreter. The name must be unique within your account.

  • description (string) – The description of the code interpreter.

  • executionRoleArn (string) – The Amazon Resource Name (ARN) of the IAM role that provides permissions for the code interpreter to access Amazon Web Services services.

  • networkConfiguration (dict) –

    [REQUIRED]

    The network configuration for the code interpreter. This configuration specifies the network mode for the code interpreter.

    • networkMode (string) – [REQUIRED]

      The network mode for the code interpreter. This field specifies how the code interpreter connects to the network.

    • vpcConfig (dict) –

      The VPC configuration for the code interpreter. This configuration is required when the network mode is set to VPC.

      • securityGroups (list) – [REQUIRED]

        The security groups associated with the VPC configuration.

        • (string) –

      • subnets (list) – [REQUIRED]

        The subnets associated with the VPC configuration.

        • (string) –

      • requireServiceS3Endpoint (boolean) –

        Note

        This field applies only to Agent Runtimes. It is not applicable to Browsers or Code Interpreters.

        Controls whether a service-managed Amazon S3 gateway endpoint is provisioned in the VPC network topology for the agent runtime. This gateway is used by Amazon Bedrock AgentCore Runtime to download code and container images during agent startup.

        Starting May 5, 2026, Amazon Bedrock AgentCore Runtime is gradually rolling out a change to how network isolation is configured for VPC mode agents. Agent runtimes created on or after this rollout will no longer include the service-managed Amazon S3 gateway. Instead, all network access, including to Amazon S3, is governed exclusively by your VPC configuration. This field cannot be set on agent runtimes created after the rollout. Passing this field in an UpdateAgentRuntime request for these agent runtimes returns a ValidationException.

        Agent runtimes created before the rollout are not affected and continue to operate with the service-managed Amazon S3 gateway. To enforce full VPC network isolation on these existing agent runtimes, set this field to false via the UpdateAgentRuntime API. Before opting out, ensure your VPC provides the Amazon S3 access required for agent startup. If this field is not specified or is set to true, the service-managed Amazon S3 gateway remains provisioned.

        This field is only supported in the UpdateAgentRuntime API for pre-rollout agent runtimes. Passing this field in a CreateAgentRuntime request returns a ValidationException.

  • certificates (list) –

    A list of certificates to install in the code interpreter.

    • (dict) –

      A certificate to install in the browser or code interpreter.

      • location (dict) – [REQUIRED]

        The location of the certificate.

        Note

        This is a Tagged Union structure. Only one of the following top level keys can be set: secretsManager.

        • secretsManager (dict) –

          The Amazon Web Services Secrets Manager location of the certificate.

          • secretArn (string) – [REQUIRED]

            The ARN of the Amazon Web Services Secrets Manager secret containing the certificate.

  • clientToken (string) –

    A unique, case-sensitive identifier to ensure that the operation completes no more than one time. If this token matches a previous request, Amazon Bedrock AgentCore ignores the request but does not return an error.

    This field is autopopulated if not provided.

  • tags (dict) –

    A map of tag keys and values to assign to the code interpreter. Tags enable you to categorize your resources in different ways, for example, by purpose, owner, or environment.

    • (string) –

      • (string) –

Return type:

dict

Returns:

Response Syntax

{
    'codeInterpreterId': 'string',
    'codeInterpreterArn': 'string',
    'createdAt': datetime(2015, 1, 1),
    'status': 'CREATING'|'CREATE_FAILED'|'READY'|'DELETING'|'DELETE_FAILED'|'DELETED'
}

Response Structure

  • (dict) –

    • codeInterpreterId (string) –

      The unique identifier of the created code interpreter.

    • codeInterpreterArn (string) –

      The Amazon Resource Name (ARN) of the created code interpreter.

    • createdAt (datetime) –

      The timestamp when the code interpreter was created.

    • status (string) –

      The current status of the code interpreter.

Exceptions

  • BedrockAgentCoreControl.Client.exceptions.ServiceQuotaExceededException

  • BedrockAgentCoreControl.Client.exceptions.AccessDeniedException

  • BedrockAgentCoreControl.Client.exceptions.ConflictException

  • BedrockAgentCoreControl.Client.exceptions.ValidationException

  • BedrockAgentCoreControl.Client.exceptions.ThrottlingException

  • BedrockAgentCoreControl.Client.exceptions.InternalServerException