Product decisions8 min readOctober 3, 2026

Amazon Bedrock AgentCore for document agents on S3: what it runs, what it costs, and when you don't need it

What Amazon Bedrock AgentCore is, how an agent running on it reaches documents in an S3 bucket, how its consumption pricing works, and how it compares with Amazon Quick and with asking one document directly in BucketDesk.

JeVaughn Ferguson
Founder, developer
The short version

Amazon Bedrock AgentCore is a sound place to run an agent that has to act on documents, with per-session microVMs, MCP tools through Gateway and billing that doesn't charge for waiting. It does not give you document access or permissions out of the box: you add S3 access to its execution role and build per-user rules yourself, and the model tokens come on top of the AgentCore meters. If the job is answering questions about a file people already have open, a cited single-document chat gets there without any of that.

Search interest in Amazon Bedrock AgentCore is now several times that of everyday S3 commands like aws s3 sync, and a common reason teams look at it is documents: an agent that reads the contracts, invoices and reports already sitting in S3 and does something useful with them. AgentCore can host that agent. Whether you should build one depends on what the agent has to do beyond answering a question.

This article covers what AgentCore actually provides, what an S3 document agent needs from it, how the bill is calculated, and where Amazon Quick or a single-document chat is the shorter path.

What AgentCore is

AgentCore is a set of managed services for running agents you write yourself, with any framework and any model. AWS lists Strands Agents, LangGraph, CrewAI, LlamaIndex, Google ADK and the OpenAI Agents SDK, and models inside or outside Bedrock, including Claude. The core platform became generally available in October 2025, and the services can be used together or one at a time.

AgentCore also offers Code Interpreter, Browser, Evaluations and a managed agent loop called Harness, but none of them is required to read a PDF. The pieces that matter for a document agent are listed below.

  • Runtime: hosts your agent code. Each session gets its own microVM, which is terminated and its memory sanitized when the session ends.
  • Gateway: turns Lambda functions, OpenAPI and Smithy APIs into MCP tools the agent can call, and connects to existing MCP servers.
  • Identity: handles sign-in through providers such as Cognito, Okta, Entra ID and Auth0, so the agent can act on behalf of a user.
  • Memory: short-term conversation state and long-term records across sessions.
  • Policy and Observability: rules on which tool calls are allowed, and traces in CloudWatch.

How an AgentCore agent reads files in S3

AgentCore has no built-in S3 document connector. The agent reads files one of two ways: directly through the AWS SDK under the Runtime execution role, or through a Gateway tool, usually a Lambda function that lists and fetches objects.

The execution role is trusted by bedrock-agentcore.amazonaws.com, and AWS's example policy covers container images, logs, traces and Bedrock model calls, not your buckets. You add S3 access yourself, and the scope you choose is the scope of everything the agent can read for every user.

That is the part teams underestimate. One role means one view of the bucket. If different people may see different folders, you either pass the user's identity through Identity and check it in your tool code, or run the file access in a Lambda that applies per-user rules. Add kms:Decrypt if the bucket uses SSE-KMS.

The policy below is the minimum for read-only access to one prefix:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "s3:ListBucket",
      "Resource": "arn:aws:s3:::acme-contracts",
      "Condition": { "StringLike": { "s3:prefix": "signed/*" } }
    },
    {
      "Effect": "Allow",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::acme-contracts/signed/*"
    }
  ]
}

Limits worth knowing

Runtime sessions on microVMs last up to 8 hours by default and end after 15 minutes idle. Synchronous requests time out at 15 minutes, request payloads can be up to 100 MB, and a session gets at most 2 vCPU and 8 GB of memory. Gateway tool calls are limited to 6 MB of payload, so a tool should return extracted text or a reference, not a large file.

The model limits still apply on top. Claude on Bedrock accepts up to five documents of 4.5 MB each per Converse message, so an agent working through a folder of contracts still reads them a few at a time.

What it costs

AgentCore is billed by consumption with no upfront commitment, and each service has its own meter. Runtime on microVMs is billed per vCPU-hour and per GB-hour of memory; the listed us-east-1 rates at the time of writing are $0.1276 per vCPU-hour and $0.0169 per GB-hour. CPU time spent waiting on the model or a tool isn't charged, which matters because a document agent spends most of its time waiting on the model.

Gateway charges $0.005 per 1,000 tool invocations plus a small amount for tool search and indexing. Memory is billed per GB ingested and stored for short-term state and per record for long-term memory. Observability is billed at normal CloudWatch rates.

None of that includes the model. Every Claude call the agent makes is billed by Bedrock per token, and for document work that is usually the largest line, because each page read is input tokens. Check the AgentCore and Bedrock pricing pages for your Region before you budget.

AgentCore, Amazon Quick, or one document at a time

These answer different needs. Amazon Q Business, the product many teams first looked at, is closed to new customers, and AWS points them to Amazon Quick. Quick is a finished workspace with indexes over your data; it can also call an AgentCore Gateway or an MCP server hosted on AgentCore Runtime through its MCP client, so the two can work together.

BucketDesk Document AI is a single-document option. You open a document in a connected bucket, ask in plain language, and Claude on Amazon Bedrock answers in your AWS account with a citation to the supporting passage. It reads with the access the person already has in BucketDesk, keeps no file content after the session, and needs no agent code, index or execution role to maintain. It does not run multi-step workflows; that is what AgentCore is for.

  • Build on AgentCore when the agent must take steps: read a batch of invoices, compare them against a purchase order system, and file a result somewhere. You write and run the code, and you own the permissions model.
  • Use Amazon Quick when people need search and chat across thousands of files with an index already built and maintained for them.
  • Use single-document chat when the question is about the file in front of you.
Try it in BucketDesk

Starter is free. Deploy a scoped role with CloudFormation, sign in, and browse, without handing anyone an access key.

Connect a bucket

Primary sources

Discussion

0 comments · open to guests · moderated
Comments appear after a quick review.

Liked this? Get the next article by email. No schedule, no filler, one click to leave.

Keep reading

All writing →