Quick answer#
Amazon Bedrock Managed Agents is worth a bounded pilot for AWS teams that want an OpenAI-powered agent harness without building the conversation loop themselves. It is not a finished AI employee, a course, or a generally available substitute for every AgentCore application. The current documentation calls it public preview in three US Regions; the seed listing's limited-preview description is outdated.[2][3]
Verified October 6, 2026. During preview, AWS charges no additional BMA service fee, but you still pay for model inference and the resources your agent uses. The example stack can keep charging when no agent turn is running. Our recommendation is to evaluate one low-risk, text-in/file-out workflow, with a teardown owner and a measured cost per accepted result.[21][2]
- Best for: an engineering team already using AWS identity and infrastructure, willing to maintain its execution environment and tolerate preview changes.
- Avoid if: you need non-US deployment, built-in long-term memory, subagents, a customer-managed key for service-managed session data, or production SLA coverage for the preview.[3][6]
- Main advantage: AWS-native model access and session orchestration, with durable conversation output and reusable skills.[2]
- Main drawback: “managed” does not remove your responsibility for tool execution, permissions, infrastructure cleanup or business-level correctness.[4][15]
This is a source-based procurement review, not a paid-workload benchmark. We did not deploy a BMA agent, test failure recovery, measure latency or obtain an enterprise quote. The hosting choice is separate from learning to build agents; start with the self-hosted versus managed operating-model guide if ownership is the unresolved question.
Identity: BMA is not Bedrock Agents, AgentCore or a course#
The exact offer is Amazon Bedrock Managed Agents, powered by OpenAI, jointly developed by AWS and OpenAI. AWS describes it as a customized, AWS-native version of OpenAI's Agents API; the product page describes the combination of OpenAI models, the Codex harness and AgentCore. The current user guide is more specific about the implementation boundary: AWS manages conversation and model interactions, while tools execute on compute you provide.[21][1][2]
Do not silently substitute older reviews of Amazon Bedrock Agents, broad Bedrock model hosting, or AgentCore Runtime. AgentCore is the broader platform; BMA supplies a particular managed harness and supported API surface. The preview uses the bedrock-mantle endpoint, not bedrock-runtime, and compatibility with OpenAI-hosted Agents APIs is not guaranteed.[1][3]
A “memory” promise needs similar care. Session conversation state is not cross-session, built-in long-term memory: the preview limitations explicitly exclude the latter. Likewise, the product page's broad language about specialized work does not establish subagent support in this preview; the limitations page says subagents are unsupported.[1][3]
Pricing: no extra preview fee does not mean a free agent#
The September 29 AWS announcement is the clearest fee statement: no additional BMA charge during preview beyond underlying AWS resources, with pricing subject to change at general availability. There is no verified all-inclusive monthly subscription price to quote.[21]
Budget separate lines rather than one supposed “Bedrock agent price”:
- Model inference: price the exact model supported in your account and Region. The preview does not support cross-Region inference profiles, so do not assume a global endpoint rate applies.[3][19]
- Execution compute: pay for your own host or the AgentCore runtime you deploy. The current AgentCore table separates v1 and v2 microVM consumption rates rather than providing one universal compute rate.[2][5]
- Storage and image artifacts: the AgentCore pricing page separately identifies code storage, including ECR storage for container deployment. Files and retained artifacts need their own lifecycle budget.[5]
- Networking: the BMA AgentCore example creates networking resources including a NAT gateway, which can continue to incur charges between tasks.[2]
- Optional services and tools: additional AWS services have their own terms and fees; third-party tools and your team's operating time are not made free by the preview waiver.[6]
For a transparent compute illustration, the retrieved AgentCore table lists v2 consumption CPU at $0.1276 per vCPU-hour and memory at $0.0169 per GB-hour. Two consumed vCPU-hours plus four consumed GB-hours calculate to $0.3228. This is arithmetic on listed consumption units, not a reservation quote or a measured one-hour BMA task.[5]
Actual billing is per second with a one-second minimum, includes system overhead, and treats CPU and memory differently: CPU scales to zero during I/O wait, while the current v2 description says idle memory is reclaimed after 120 seconds. Do not apply CPU's idle rule to every resource in the stack. The table also advertises committed-baseline rates with a launch qualification; this review does not assume those discounted rates are available to your account.[5]
For the hidden fixed-cost example, AWS's VPC page explicitly illustrates US East (Ohio) NAT pricing at $0.045 per hour plus $0.045 per GB processed. An assumed 730 provisioned hours therefore cost $32.85 before traffic, separate from model and runtime charges. This is a regional worksheet example, not a claim that every deployment requires that exact configuration.[20]
Use the agent cost calculator to separate fixed infrastructure, inference, failed attempts and engineering time. Measure accepted business results as the denominator; an inexpensive unsuccessful turn is not a cheap completed task.
Features and limits that change the buying decision#
BMA's documented workflow supports session creation, retrieval, listing and deletion; text messages; cancellation of the current turn; durable items; streamed progress; filesystem-based skills; and environment-based STDIO MCP servers. These are useful building blocks for codebase investigation, document processing and generated-file workflows, but they are not a no-code business application.[2][3]
The current preview boundaries are concrete:
- Regions: US East (N. Virginia), US West (Oregon) and US East (Ohio).[3]
- Models: supported OpenAI models available in the target Region and account, not every model exposed elsewhere in Bedrock.[3]
- Input: the documented session input surface is text.[3]
- Orchestration: subagents and programmatic tool calling/code mode are outside the supported preview workflow.[3]
- Persistence: no built-in long-term-memory integration; session conversation and workspace files have separate lifecycles.[3]
- Encryption configuration: no exposed customer-managed KMS key setting for service-managed session data.[3]
The example's idle timeout and maximum compute lifetime are both 28,800 seconds. AWS explicitly labels these example configuration values, not universal account quotas. Extending a client polling timeout does not extend the execution environment's lifetime or increase model capacity.[3]
Security: three identities and a separate tool boundary#
AWS documents three identities: the caller, the service-assumed session role and the execution environment's identity. Keep those roles separate and scope each to its job. The examples use AWS Signature Version 4 and do not require an OpenAI API key.[4]
A session role is not a complete tool-safety system. Commands and MCP tools inherit the execution environment's access, so AWS recommends a dedicated workspace, restricted OS identity, limited credentials and network destinations, and application/tool-level authorization for external effects. Deployment credentials should not be exposed to runtime commands.[4]
Before a pilot, list every operation that can send, delete, purchase or modify shared data. Put approval and authorization at the actual tool boundary, not only in a natural-language instruction. Our MCP security review checklist provides a way to inspect that boundary without assuming a managed harness makes untrusted documents safe.
Cancellation, refunds, preview terms and cleanup#
This is metered cloud infrastructure, not a course with a tuition-refund window. We did not verify a BMA-specific money-back guarantee. AWS's general terms say associated services bring their own fees, while the beta/preview section says SLAs do not apply and functionality or access can change.[6]
The preview terms also say beta services are for evaluation and should not process sensitive data unless AWS communicates otherwise. Content may become inaccessible or be deleted when access ends, and migration into a generally available service is not promised. Take those contract constraints more seriously than “production-ready” marketing language.[6][1]
Stopping a turn, deleting a session and removing your infrastructure are different actions. AWS's guide warns that deleting a BMA session does not delete files in your own buckets or host. Its cleanup instructions cover resources created by the examples; use that resource inventory rather than assuming an empty session list means an empty bill.[2][15]
A practical exit plan should name the owner of each retained bucket, image, log and network resource. Export the useful output, stop execution, inspect the deployed stack and confirm the next billing period no longer contains abandoned infrastructure. Those are proposed controls, not actions we performed in this review.
Independent community evidence: useful questions, limited proof#
The Hacker News discussion of OpenAI coming to Bedrock contains identifiable developer concerns and benefits, but it predates the current public preview. Commenter zmmmmm described Bedrock availability as an adoption driver in their organization; spindump8930 cautioned that the same named model can behave differently across inference platforms. These are reports and hypotheses, not our measured comparison of BMA with OpenAI direct.[23]
The thread is broader than Managed Agents and contains disputed claims about providers, retention and performance. We therefore do not turn it into a BMA failure rate, an enterprise satisfaction score, or evidence that today's preview has a specific defect. A targeted Reddit search returned no results in this research pass; that is a coverage gap, not proof nobody uses the service.
The decision implication is narrower: replay your own acceptance set on the target provider and Region, and verify its contract and retention settings. The Microsoft Foundry Agent Service review offers a contrasting session/runtime model, not an interchangeable price benchmark.
Advertising: verified lookup results, not invented campaign proof#
Our fresh Google Ads Transparency lookup for aws.amazon.com displayed “0 ads” with the selected worldwide/all-time filters. The Meta keyword lookup displayed no matching ads, but the browser received HTTP 403. Neither observation establishes that AWS runs no ads, or that this exact offer is not advertised through other domains or campaigns.[26][28]
We did not verify a product-specific creative ID, spend, targeting, conversion rate or customer outcome. The seeded row is a research priority, not verified paid-ad activity. AWS's own product page and announcement establish an active marketed offer; they are not independent performance evidence.[1][21]
Pros, cons and alternatives#
The strongest reasons to consider BMA are the AWS-native permissions/billing context, an already managed conversation loop, durable session output and a path to either your existing compute or AgentCore. Those benefits matter when AWS is already where the workload must live.[2][4]
The strongest reasons to wait are preview contractual risk, three-Region availability, missing subagents/long-term memory and the ongoing execution-environment work. An experienced team may reasonably prefer more application control rather than adapting to a changing preview.[3][6]
- Choose the Claude Managed Agents review for a first-party Claude harness comparison, especially session budgets and the distinction between self-hosted tools and provider-held conversation state.
- Consider the Cloudflare Agents review when you are choosing a developer runtime/state model rather than buying a fixed OpenAI harness. Compare lifecycle and operating responsibility before headline rates.
- Use the Hermes Agent review if the real need is an operator-facing agent with inspectable local workflows, rather than an embedded cloud agent API. Hermes's official docs emphasize its skill-learning loop; it is not a drop-in BMA API replacement.[30]
If you choose the local operator route, the Hermes installation guide is the practical next step. Managed Hermes hosting can reduce server-maintenance work, but it does not automatically reproduce AWS governance, BMA APIs or your application's acceptance logic. There is no reason to migrate a well-governed AWS application merely to win a superficial subscription-price comparison.
Decision checklist before committing#
- Pick one reversible workflow and write down the required output, allowed tools and human approval points.
- Confirm the exact model, Region and supported preview API surface; reject assumptions copied from OpenAI-hosted Agents APIs.
- Set a small pilot budget covering tokens, runtime, NAT, storage and failed attempts, with a named teardown owner.
- Separate caller, session and execution identities; test a denied action as well as a successful one.
- Test interruption, restart and output retrieval without duplicating external effects. Record which state survives and where it lives.
- Review preview terms, sensitive-data restrictions and deletion/export obligations with the responsible owner.
- Expand only after measuring cost per accepted task and an acceptable recovery process. Otherwise keep the workload on your existing controlled runtime.
Verdict: a credible AWS-native preview for a specific engineering problem, not a universal replacement for agent infrastructure. The most important purchase decision is whether its managed conversation loop saves more work than its preview limits and execution boundary add.
Sources#
[1] https://aws.amazon.com/bedrock/managed-agents-openai — Amazon Bedrock Managed Agents
[2] https://docs.aws.amazon.com/bedrock/latest/userguide/bedrock-managed-agents-openai.html — Amazon Bedrock Managed Agents, powered by OpenAI (preview) - Amazon Bedrock
[3] https://docs.aws.amazon.com/bedrock/latest/userguide/bedrock-managed-agents-openai-quotas-limitations.html — Preview availability and limitations - Amazon Bedrock
[4] https://docs.aws.amazon.com/bedrock/latest/userguide/bedrock-managed-agents-openai-security.html — Security and IAM roles - Amazon Bedrock
[5] https://aws.amazon.com/bedrock/agentcore/pricing — Amazon Bedrock AgentCore Pricing - AWS
[6] https://aws.amazon.com/service-terms — AWS Service Terms
[15] https://docs.aws.amazon.com/bedrock/latest/userguide/bedrock-managed-agents-openai-cleanup.html — Clean up example resources - Amazon Bedrock
[19] https://aws.amazon.com/bedrock/pricing — Amazon Bedrock Pricing
[20] https://aws.amazon.com/vpc/pricing — Amazon VPC Pricing
[21] https://aws.amazon.com/about-aws/whats-new/2026/09/bedrock-managed-agents-preview
[23] https://news.ycombinator.com/item?id=47939320
[26] https://adstransparency.google.com/?region=anywhere&domain=aws.amazon.com&hl=en — aws-google advertising lookup
[28] https://www.facebook.com/ads/library/?active_status=active&ad_type=all&country=ALL&q=Amazon%20Bedrock%20Managed%20Agents&search_type=keyword_unordered — aws-meta advertising lookup
[30] https://hermes-agent.nousresearch.com/docs — Official Hermes documentation