翻訳は機械翻訳により提供されています。提供された翻訳内容と英語版の間で齟齬、不一致または矛盾がある場合、英語版が優先します。
レジストリ MCP エンドポイントの使用
AWS エージェントレジストリが新しいagent-registry名前空間で起動されました。パブリックプレビューbedrock-agentcore名前空間のサポートは、2026 年 9 月 17 日に終了します。移行手順については、「包括的なレジストリ移行ガイド」を参照してください。
概要
各レジストリは、Model Context Protocol ウェブサイトの 2025-11-25 仕様に従って MCP 互換エンドポイントを公開します。エンドポイントは、レジストリレコードを検索するためのツールリストとツール呼び出しをサポートしています。
例
- AWS Agent Registry namespace
-
https://agent-registry.<region>.api.aws/registry/<registryId>/mcp
- Amazon Bedrock AgentCore namespace (to be deprecated)
-
https://bedrock-agentcore.<region>.amazonaws.com/registry/<registryId>/mcp
agent-registry 名前空間では、MCP エンドポイントは 3 つの検出データプレーン APIsとして公開します。
-
search_discoverable_registry_records — 承認されたレコードの自然言語検索。
-
list_discoverable_registry_records — 承認済みレコードのページ分割リスト。
-
batch_get_discoverable_registry_record — レコード ID によるフルレコードコンテンツの一括取得。
bedrock-agentcore 名前空間では、search_registry_recordsツールのみが公開されます。次の表は、ツールの定義を示しています。
例
- AWS Agent Registry namespace
-
Tool name: search_discoverable_registry_records
Description:
Searches for approved registry records using natural language queries. Returns metadata for matching records.
Parameters:
- searchQuery (required): string - Natural language search query
- maxResults: integer - Maximum number of results to return (1-20, default 10)
- filter: object - Optional metadata filter using structured JSON operators. Supports field-level operators ($eq, $ne,
$in) and logical operators ($and, $or) on filterable fields (name, recordType, recordVersion). Example:
{"recordType": {"$eq": "MCP"}}
---
Tool name: list_discoverable_registry_records
Description:
Returns paginated summaries of approved records in the registry. Summaries include record metadata but not descriptor
content. Use batch_get_discoverable_registry_record to fetch full descriptors after identifying the records you need.
Parameters:
- maxResults: integer - Maximum number of results per page (1-100, default 20)
- nextToken: string - Pagination token from a previous response. Omit for the first page.
- filters: array - Optional list of filter entries in the form {"name": "<field>", "values": ["<value>"]}. Supported
filter names: recordType (valid values: AGENT, MCP, SKILL, CUSTOM) and descriptorType (valid values: a2aAgentCard,
mcpServer, agentSkillsDefinition, custom). Duplicate filter names are rejected. If you specify multiple values for
a single filter, the values are joined by OR. If you specify multiple filters, the filters are joined by AND.
---
Tool name: batch_get_discoverable_registry_record
Description:
Retrieves the full descriptor content for up to 100 approved records in a single call. Common use case: after
identifying records with list_discoverable_registry_records or search_discoverable_registry_records, fetch their full
descriptors in one call rather than making one call per record.
Parameters:
- recordIds (required): array - List of 1-100 record ARNs or IDs to retrieve from the registry.
The response returns HTTP 200 even on partial failure. Records that could not be retrieved appear in an errors list
with an errorCode (RESOURCE_NOT_FOUND, ACCESS_DENIED, or INTERNAL_ERROR) rather than causing the whole call to fail.
- Amazon Bedrock AgentCore namespace (to be deprecated)
-
Tool name: search_registry_records
Description:
Searches for registry records using natural language queries. Returns metadata for matching records.
Parameters:
- searchQuery (required): string - Natural language search query
- maxResults: integer - Maximum number of results to return (1-20, default 10)
- filter: object - Optional metadata filter using structured JSON operators. Supports field-level operators ($eq, $ne,
$in) and logical operators ($and, $or) on filterable fields (name, descriptorType, version). Example:
{"descriptorType": {"$eq": "MCP"}}
Kiro、Claude などの既存の MCP クライアントからレジストリに接続できます。
既存の MCP クライアントから OAuth ベースのレジストリ MCP エンドポイントに接続する
アクセス許可
MCP エンドポイントは、同じ CustomJWTAuthorizerConfiguration を使用して受信リクエストを承認します。
.well-known/oauth-protected-resource パスは https://agent-registry.<region>.api.aws/.well-known/oauth-protected-resource/registry/<registryId>/mcp (https://bedrock-agentcore.<region>.amazonaws.com/.well-known/oauth-protected-resource/registry/<registryId>/mcp bedrock-agentcore 名前空間にまだ存在するレジストリの場合) です。
クライアントはWWW-Authenticateヘッダーからメタデータを検出することもできます。
例
- AWS Agent Registry namespace
-
www-authenticate: Bearer resource_metadata="https://agent-registry.<region>.api.aws/.well-known/oauth-protected-resource/registry/<registryId>/mcp"
- Amazon Bedrock AgentCore namespace (to be deprecated)
-
www-authenticate: Bearer resource_metadata="https://bedrock-agentcore.<region>.amazonaws.com/.well-known/oauth-protected-resource/registry/<registryId>/mcp"
アクセストークンを取得したら、検証できます。
例
- AWS Agent Registry namespace
-
curl -s -X POST "https://agent-registry.<region>.api.aws/registry/<registryId>/mcp" \
-H "Authorization: Bearer ${ACCESS_TOKEN}" \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"search_discoverable_registry_records","arguments":{"searchQuery":"weather"}}}'
- Amazon Bedrock AgentCore namespace (to be deprecated)
-
curl -s -X POST "https://bedrock-agentcore.<region>.amazonaws.com/registry/<registryId>/mcp" \
-H "Authorization: Bearer ${ACCESS_TOKEN}" \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"search_registry_records","arguments":{"searchQuery":"weather"}}}'
認可サーバーと組織のセキュリティ要件に応じて、次のいずれかのアプローチを選択して MCP クライアントを設定できます。
-
ベアラートークン: 別のプロセスを使用してベアラートークンを取得し、MCP クライアントヘッダーで設定します。
-
事前登録済みクライアント: 認可サーバーにクライアントを作成し、レジストリの設定でクライアントを許可リストに登録します。
-
動的クライアント登録: 認可サーバーが動的クライアント登録 (DCR) をサポートしている場合、レジストリの設定で対象者を許可リストに登録できます。
OAuth ベースの MCP クライアント設定
ベアラートークンを使用する
ほとんどの IDEs では、mcp 設定で認可ヘッダーベアラートークンを設定できます。たとえば、Kiro IDE は ${ENV_VAR}構文を使用して環境変数をサポートします。詳細については、Kiro ウェブサイトの「MCP 接続の保護」を参照してください。次の例を使用できます。
例
- AWS Agent Registry namespace
-
{
"mcpServers": {
"my-registry": {
"type": "http",
"url": "https://agent-registry.<region>.api.aws/registry/<registryId>/mcp",
"headers": {
"Authorization": "Bearer ${ACCESS_TOKEN}"
}
}
}
}
- Amazon Bedrock AgentCore namespace (to be deprecated)
-
{
"mcpServers": {
"my-registry": {
"type": "http",
"url": "https://bedrock-agentcore.<region>.amazonaws.com/registry/<registryId>/mcp",
"headers": {
"Authorization": "Bearer ${ACCESS_TOKEN}"
}
}
}
}
事前登録済みクライアント
認可サーバーで認可コードの付与に基づいて新しいクライアントを作成し、そのクライアントを使用してレジストリにアクセスできます。たとえば、Cognito ユーザープールにクライアントを作成します。
クライアント ID を取得したら、レジストリで許可リストに登録してください。
例
- AWS Agent Registry namespace
-
aws agent-registry-control update-registry \
--registry-id <registryId> \
--discovery-configuration '{
"authorizerConfiguration": {
"optionalValue": {
"customJWTAuthorizer": {
"discoveryUrl": "https://<example-domain>/.well-known/openid-configuration",
"allowedClients": ["<client-id>"]
}
}
}
}'
- Amazon Bedrock AgentCore namespace (to be deprecated)
-
aws bedrock-agentcore-control update-registry \
--registry-id <registryId> \
--authorizer-configuration '{
"optionalValue": {
"customJWTAuthorizer": {
"discoveryUrl": "https://<example-domain>/.well-known/openid-configuration",
"allowedClients": ["<client-id>"]
}
}
}'
その後、clientId の指定をサポートしている場合は、MCP クライアントを設定できます。Claude コードの例:
例
- AWS Agent Registry namespace
-
{
"mcpServers": {
"pre-registered-registry": {
"type": "http",
"url": "https://agent-registry.<region>.api.aws/registry/<registryId>/mcp",
"oauth": {
"clientId": "<client-id>",
"callbackPort": "<port-number>"
}
}
}
}
- Amazon Bedrock AgentCore namespace (to be deprecated)
-
{
"mcpServers": {
"pre-registered-registry": {
"type": "http",
"url": "https://bedrock-agentcore.<region>.amazonaws.com/registry/<registryId>/mcp",
"oauth": {
"clientId": "<client-id>",
"callbackPort": "<port-number>"
}
}
}
}
Auth0 や Cognito などの一部の認可サーバーでは、ポートの範囲を許可リダイレクト URIs として設定できないため、事前登録されたクライアントの許可されたリダイレクト/コールバック URL と mcp.json で明示的に設定する必要があります。
動的クライアント登録
ほとんどの MCP クライアントアプリケーションは、動的クライアント登録をサポートしています。この場合、レジストリにallowedClients値を指定しないでください。代わりに、 を設定することもできますallowedAudience。値は MCP レジストリと同じにすることができます。と同じ値を持つ audフィールドで JWT を発行するように認可サーバーを設定する必要がありますallowedAudience。
例
- AWS Agent Registry namespace
-
aws agent-registry-control update-registry \
--registry-id <registryId> \
--discovery-configuration '{
"authorizerConfiguration": {
"optionalValue": {
"customJWTAuthorizer": {
"discoveryUrl": "https://<example-domain>/.well-known/openid-configuration",
"allowedAudience": ["https://agent-registry.<region>.api.aws/registry/<registryId>/mcp"]
}
}
}
}'
- Amazon Bedrock AgentCore namespace (to be deprecated)
-
aws bedrock-agentcore-control update-registry \
--registry-id <registryId> \
--authorizer-configuration '{
"optionalValue": {
"customJWTAuthorizer": {
"discoveryUrl": "https://<example-domain>/.well-known/openid-configuration",
"allowedAudience": ["https://bedrock-agentcore.<region>.amazonaws.com/registry/<registryId>/mcp"]
}
}
}'
その後、URL を使用して MCP クライアントを設定できます。
例
- AWS Agent Registry namespace
-
{
"mcpServers": {
"dcr-registry": {
"type": "http",
"url": "https://agent-registry.<region>.api.aws/registry/<registryId>/mcp"
}
}
}
- Amazon Bedrock AgentCore namespace (to be deprecated)
-
{
"mcpServers": {
"dcr-registry": {
"type": "http",
"url": "https://bedrock-agentcore.<region>.amazonaws.com/registry/<registryId>/mcp"
}
}
}
動的クライアント登録をセットアップする際の一般的なエラー:
-
認可サーバーが動的クライアント登録をサポートしていることを確認する必要があります。
-
認可サーバーは、レジストリの CustomJWTAuthorizerConfiguration で許可されている audフィールドで JWT を発行する必要があります。
-
現在、レジストリは www-authenticate ヘッダーでスコープチャレンジを返しません。一部の MCP クライアントは、Kiro などの設定oauthScopesでの明示的な定義をサポートしています。
既存の MCP クライアントから IAM ベースのレジストリ MCP エンドポイントに接続する
アクセス許可
MCP の初期化とツールのリスト:
例
- AWS Agent Registry namespace
-
{
"Effect": "Allow",
"Action": "agent-registry:InvokeRegistryMcp",
"Resource": "arn:aws:agent-registry:*:<account>:registry/*"
}
- Amazon Bedrock AgentCore namespace (to be deprecated)
-
{
"Effect": "Allow",
"Action": "bedrock-agentcore:InvokeRegistryMcp",
"Resource": "arn:aws:bedrock-agentcore:*:<account>:registry/*"
}
MCP ツール呼び出しで検索するには、以下も必要です。
例
- AWS Agent Registry namespace
-
{
"Effect": "Allow",
"Action":
[
"agent-registry:InvokeRegistryMcp",
"agent-registry:SearchDiscoverableRegistryRecords"
],
"Resource": "arn:aws:agent-registry:*:<account>:registry/*"
}
- Amazon Bedrock AgentCore namespace (to be deprecated)
-
{
"Effect": "Allow",
"Action":
[
"bedrock-agentcore:InvokeRegistryMcp",
"bedrock-agentcore:SearchRegistryRecords"
],
"Resource": "arn:aws:bedrock-agentcore:*:<account>:registry/*"
}
コマンドを使用してアクセス許可を確認できます。
例
- AWS Agent Registry namespace
-
curl -s -X POST "https://agent-registry.<region>.api.aws/registry/<registryId>/mcp" \
-H "Content-Type: application/json" \
-H "X-Amz-Security-Token: ${AWS_SESSION_TOKEN}" \
--aws-sigv4 "aws:amz:<region>:agent-registry" \
--user "${AWS_ACCESS_KEY_ID}:${AWS_SECRET_ACCESS_KEY}" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"search_discoverable_registry_records","arguments":{"searchQuery":"weather"}}}'
- Amazon Bedrock AgentCore namespace (to be deprecated)
-
curl -s -X POST "https://bedrock-agentcore.<region>.amazonaws.com/registry/<registryId>/mcp" \
-H "Content-Type: application/json" \
-H "X-Amz-Security-Token: ${AWS_SESSION_TOKEN}" \
--aws-sigv4 "aws:amz:<region>:bedrock-agentcore" \
--user "${AWS_ACCESS_KEY_ID}:${AWS_SECRET_ACCESS_KEY}" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"search_registry_records","arguments":{"searchQuery":"weather"}}}'
IAM ベースの MCP クライアント設定
GitHub ウェブサイトで mcp-proxy-for-aws を使用して、IAM ベースのレジストリに接続できます。たとえば、Kiro mcp.json の場合:
例
- AWS Agent Registry namespace
-
{
"mcpServers": {
"iam-based-registry": {
"disabled": false,
"type": "stdio",
"command": "uvx",
"args": [
"mcp-proxy-for-aws@latest",
"https://agent-registry.<region>.api.aws/registry/<registryId>/mcp",
"--service",
"agent-registry",
"--region",
"<region>",
"--profile",
"my-profile"
]
}
}
}
- Amazon Bedrock AgentCore namespace (to be deprecated)
-
{
"mcpServers": {
"iam-based-registry": {
"disabled": false,
"type": "stdio",
"command": "uvx",
"args": [
"mcp-proxy-for-aws@latest",
"https://bedrock-agentcore.<region>.amazonaws.com/registry/<registryId>/mcp",
"--service",
"bedrock-agentcore",
"--region",
"<region>",
"--profile",
"my-profile"
]
}
}
}
独自の MCP クライアントを開発する
Kiro や Claude Code などの一般的な IDEs からのレジストリ MCP エンドポイントの呼び出し方法に関するその他のコードリファレンスについては、パブリックコードリポジトリのサンプルコードリファレンスを参照してください。