Skip to content

feat: add API Gateway REST API as new gateway target type - #509

Merged
jesseturner21 merged 4 commits into
mainfrom
feat/api-gateway-target
Mar 6, 2026
Merged

feat: add API Gateway REST API as new gateway target type#509
jesseturner21 merged 4 commits into
mainfrom
feat/api-gateway-target

Conversation

@aidandaly24

Copy link
Copy Markdown
Contributor

Description

Adds --type api-gateway as a new gateway target type, allowing users to register an existing Amazon API Gateway REST API as a gateway target. This enables agents to invoke tools backed by REST API endpoints through an AgentCore gateway without the REST API needing to speak MCP.

Changes:

  • Schema: Added 'apiGateway' to GatewayTargetTypeSchema, 5 new Zod schemas (ApiGatewayConfigSchema, ApiGatewayToolFilterSchema, etc.), apiGateway field on AgentCoreGatewayTargetSchema with superRefine validation
  • CLI flags: --rest-api-id, --stage, --tool-filter-path, --tool-filter-methods
  • Validation: apiGateway-specific validation (requires rest-api-id + stage, rejects inapplicable flags like --endpoint, --host, --outbound-auth)
  • Backend: createApiGatewayTarget() method on GatewayTargetPrimitive — writes apiGateway target config to mcp.json
  • Rename: mapMcpGatewaysToGatewayProvidersmapGatewaysToGatewayProviders, simplified outputs.ts regex
  • Tests: 13 new tests covering schema validation and CLI validation for apiGateway targets

Usage:

agentcore add gateway-target \
--type api-gateway \
--name my-api \
--rest-api-id e6ddhyjvu1 \
--stage prod \
--gateway my-gateway \
--tool-filter-path "/*" \
--tool-filter-methods "GET,POST"

Writes to mcp.json:

{
"name": "my-api",
"targetType": "apiGateway",
"apiGateway": {
"restApiId": "e6ddhyjvu1",
"stage": "prod",
"apiGatewayToolConfiguration": {
"toolFilters": [{ "filterPath": "/*", "methods": ["GET", "POST"] }]
}
}
}

Note: API Gateway targets use GATEWAY_IAM_ROLE for authentication — no credential setup needed. The corresponding CDK construct changes (which synthesize the CloudFormation) are in a separate CDK repo PR.

Related Issue

Closes #

Documentation PR

N/A — documentation updates will follow with the TUI wizard PR.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • I ran npm run test:unit and npm run test:integ
  • I ran npm run typecheck
  • I ran npm run lint
  • If I modified src/assets/, I ran npm run test:update-snapshots and committed the updated snapshots

Additionally:

  • Manually tested CLI end-to-end: created apiGateway target, verified mcp.json output
  • Deployed with CDK construct changes and confirmed API Gateway target discovers tools via OpenAPI spec
  • 128 tests pass (117 existing + 11 new), zero regressions

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

@aidandaly24
aidandaly24 requested a review from a teamMarch 6, 2026 19:15
@github-actionsgithub-actionsBot added the size/m PR size: M label Mar 6, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines42.27%3628 / 8581
🔵Statements41.92%3829 / 9133
🔵Functions43.95%720 / 1638
🔵Branches44.03%2348 / 5332
Generated in workflow #887 for commit b4b7bc5 by the Vitest Coverage Report Action

@jesseturner21
jesseturner21 merged commit 3b1df62 into mainMar 6, 2026
19 checks passed
@jesseturner21
jesseturner21 deleted the feat/api-gateway-target branch March 6, 2026 20:32

@tejaskashtejaskash left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes

sourcePath: '',
language: 'Other',
host: 'AgentCoreRuntime',
targetType: 'apiGateway',

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we see if targetType is defined in the original Type?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

And it also looks like createApiGatewayTarget() never reads config.targetType — it hardcodes targetType: 'apiGateway' when building the target object at line ~527


// Handle API Gateway targets (no code generation)
if (cliOptions.type === 'apiGateway') {
const config: AddGatewayTargetConfig = {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The AddGatewayTargetConfig type was designed for MCP server / Lambda targets. For API Gateway targets, several required fields are set to meaningless values:

  • sourcePath: '' — no source code for API Gateway targets
  • host: 'AgentCoreRuntime' — not a real compute host
  • toolDefinition: { name, description, inputSchema: { type: 'object' } } — a dummy value, never used by
    createApiGatewayTarget()

Consider either making these fields optional or introducing a discriminated union / separate config type
for API Gateway targets so the type system enforces correctness.

Comment on lines +331 to +333
if (data.targetType === 'apiGateway') {
if (!data.apiGateway) {
ctx.addIssue({

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The CLI validation correctly rejects --outbound-auth for api-gateway, but the Zod schema's superRefine block does not check for outboundAuth on apiGateway targets. Someone editing mcp.json manually could add outboundAuth to an apiGateway target and the schema would accept it. Add a check similar to the compute/endpoint ones:

if(data.outboundAuth){ctx.addIssue({code: z.ZodIssueCode.custom,message: 'outboundAuth is not applicable for apiGateway target type',path: ['outboundAuth'],});}

.option('--rest-api-id <id>', 'API Gateway REST API ID (required for api-gateway type)')
.option('--stage <stage>', 'API Gateway deployment stage (required for api-gateway type)')
.option('--tool-filter-path <path>', 'Tool filter path pattern, e.g. /pets/*')
.option('--tool-filter-methods <methods>', 'Comma-separated HTTP methods, e.g. GET,POST')

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

When --tool-filter-methods is omitted:

  • In CLI action (GatewayTargetPrimitive.ts:~296): defaults to ['GET']
  • In createApiGatewayTarget (GatewayTargetPrimitive.ts:~530): defaults to [{ filterPath: '/*', methods:
    ['GET'] }]

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@aidandaly24@tejaskash@jesseturner21
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
feat: add API Gateway REST API as new gateway target type by aidandaly24 · Pull Request #509 · aws/agentcore-cli · GitHub
Skip to content

feat: add API Gateway REST API as new gateway target type - #509

Merged
jesseturner21 merged 4 commits into
mainfrom
feat/api-gateway-target
Mar 6, 2026
Merged

feat: add API Gateway REST API as new gateway target type#509
jesseturner21 merged 4 commits into
mainfrom
feat/api-gateway-target

Conversation

@aidandaly24

Copy link
Copy Markdown
Contributor

Description

Adds --type api-gateway as a new gateway target type, allowing users to register an existing Amazon API Gateway REST API as a gateway target. This enables agents to invoke tools backed by REST API endpoints through an AgentCore gateway without the REST API needing to speak MCP.

Changes:

  • Schema: Added 'apiGateway' to GatewayTargetTypeSchema, 5 new Zod schemas (ApiGatewayConfigSchema, ApiGatewayToolFilterSchema, etc.), apiGateway field on AgentCoreGatewayTargetSchema with superRefine validation
  • CLI flags: --rest-api-id, --stage, --tool-filter-path, --tool-filter-methods
  • Validation: apiGateway-specific validation (requires rest-api-id + stage, rejects inapplicable flags like --endpoint, --host, --outbound-auth)
  • Backend: createApiGatewayTarget() method on GatewayTargetPrimitive — writes apiGateway target config to mcp.json
  • Rename: mapMcpGatewaysToGatewayProvidersmapGatewaysToGatewayProviders, simplified outputs.ts regex
  • Tests: 13 new tests covering schema validation and CLI validation for apiGateway targets

Usage:

agentcore add gateway-target \
--type api-gateway \
--name my-api \
--rest-api-id e6ddhyjvu1 \
--stage prod \
--gateway my-gateway \
--tool-filter-path "/*" \
--tool-filter-methods "GET,POST"

Writes to mcp.json:

{
"name": "my-api",
"targetType": "apiGateway",
"apiGateway": {
"restApiId": "e6ddhyjvu1",
"stage": "prod",
"apiGatewayToolConfiguration": {
"toolFilters": [{ "filterPath": "/*", "methods": ["GET", "POST"] }]
}
}
}

Note: API Gateway targets use GATEWAY_IAM_ROLE for authentication — no credential setup needed. The corresponding CDK construct changes (which synthesize the CloudFormation) are in a separate CDK repo PR.

Related Issue

Closes #

Documentation PR

N/A — documentation updates will follow with the TUI wizard PR.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • I ran npm run test:unit and npm run test:integ
  • I ran npm run typecheck
  • I ran npm run lint
  • If I modified src/assets/, I ran npm run test:update-snapshots and committed the updated snapshots

Additionally:

  • Manually tested CLI end-to-end: created apiGateway target, verified mcp.json output
  • Deployed with CDK construct changes and confirmed API Gateway target discovers tools via OpenAPI spec
  • 128 tests pass (117 existing + 11 new), zero regressions

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

@aidandaly24
aidandaly24 requested a review from a teamMarch 6, 2026 19:15
@github-actionsgithub-actionsBot added the size/m PR size: M label Mar 6, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines42.27%3628 / 8581
🔵Statements41.92%3829 / 9133
🔵Functions43.95%720 / 1638
🔵Branches44.03%2348 / 5332
Generated in workflow #887 for commit b4b7bc5 by the Vitest Coverage Report Action

@jesseturner21
jesseturner21 merged commit 3b1df62 into mainMar 6, 2026
19 checks passed
@jesseturner21
jesseturner21 deleted the feat/api-gateway-target branch March 6, 2026 20:32

@tejaskashtejaskash left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes

sourcePath: '',
language: 'Other',
host: 'AgentCoreRuntime',
targetType: 'apiGateway',

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we see if targetType is defined in the original Type?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

And it also looks like createApiGatewayTarget() never reads config.targetType — it hardcodes targetType: 'apiGateway' when building the target object at line ~527


// Handle API Gateway targets (no code generation)
if (cliOptions.type === 'apiGateway') {
const config: AddGatewayTargetConfig = {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The AddGatewayTargetConfig type was designed for MCP server / Lambda targets. For API Gateway targets, several required fields are set to meaningless values:

  • sourcePath: '' — no source code for API Gateway targets
  • host: 'AgentCoreRuntime' — not a real compute host
  • toolDefinition: { name, description, inputSchema: { type: 'object' } } — a dummy value, never used by
    createApiGatewayTarget()

Consider either making these fields optional or introducing a discriminated union / separate config type
for API Gateway targets so the type system enforces correctness.

Comment on lines +331 to +333
if (data.targetType === 'apiGateway') {
if (!data.apiGateway) {
ctx.addIssue({

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The CLI validation correctly rejects --outbound-auth for api-gateway, but the Zod schema's superRefine block does not check for outboundAuth on apiGateway targets. Someone editing mcp.json manually could add outboundAuth to an apiGateway target and the schema would accept it. Add a check similar to the compute/endpoint ones:

if(data.outboundAuth){ctx.addIssue({code: z.ZodIssueCode.custom,message: 'outboundAuth is not applicable for apiGateway target type',path: ['outboundAuth'],});}

.option('--rest-api-id <id>', 'API Gateway REST API ID (required for api-gateway type)')
.option('--stage <stage>', 'API Gateway deployment stage (required for api-gateway type)')
.option('--tool-filter-path <path>', 'Tool filter path pattern, e.g. /pets/*')
.option('--tool-filter-methods <methods>', 'Comma-separated HTTP methods, e.g. GET,POST')

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

When --tool-filter-methods is omitted:

  • In CLI action (GatewayTargetPrimitive.ts:~296): defaults to ['GET']
  • In createApiGatewayTarget (GatewayTargetPrimitive.ts:~530): defaults to [{ filterPath: '/*', methods:
    ['GET'] }]

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@aidandaly24@tejaskash@jesseturner21
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat: add API Gateway REST API as new gateway target type by aidandaly24 · Pull Request #509 · aws/agentcore-cli · GitHub
Skip to content

feat: add API Gateway REST API as new gateway target type - #509

Merged
jesseturner21 merged 4 commits into
mainfrom
feat/api-gateway-target
Mar 6, 2026
Merged

feat: add API Gateway REST API as new gateway target type#509
jesseturner21 merged 4 commits into
mainfrom
feat/api-gateway-target

Conversation

@aidandaly24

Copy link
Copy Markdown
Contributor

Description

Adds --type api-gateway as a new gateway target type, allowing users to register an existing Amazon API Gateway REST API as a gateway target. This enables agents to invoke tools backed by REST API endpoints through an AgentCore gateway without the REST API needing to speak MCP.

Changes:

  • Schema: Added 'apiGateway' to GatewayTargetTypeSchema, 5 new Zod schemas (ApiGatewayConfigSchema, ApiGatewayToolFilterSchema, etc.), apiGateway field on AgentCoreGatewayTargetSchema with superRefine validation
  • CLI flags: --rest-api-id, --stage, --tool-filter-path, --tool-filter-methods
  • Validation: apiGateway-specific validation (requires rest-api-id + stage, rejects inapplicable flags like --endpoint, --host, --outbound-auth)
  • Backend: createApiGatewayTarget() method on GatewayTargetPrimitive — writes apiGateway target config to mcp.json
  • Rename: mapMcpGatewaysToGatewayProvidersmapGatewaysToGatewayProviders, simplified outputs.ts regex
  • Tests: 13 new tests covering schema validation and CLI validation for apiGateway targets

Usage:

agentcore add gateway-target \
--type api-gateway \
--name my-api \
--rest-api-id e6ddhyjvu1 \
--stage prod \
--gateway my-gateway \
--tool-filter-path "/*" \
--tool-filter-methods "GET,POST"

Writes to mcp.json:

{
"name": "my-api",
"targetType": "apiGateway",
"apiGateway": {
"restApiId": "e6ddhyjvu1",
"stage": "prod",
"apiGatewayToolConfiguration": {
"toolFilters": [{ "filterPath": "/*", "methods": ["GET", "POST"] }]
}
}
}

Note: API Gateway targets use GATEWAY_IAM_ROLE for authentication — no credential setup needed. The corresponding CDK construct changes (which synthesize the CloudFormation) are in a separate CDK repo PR.

Related Issue

Closes #

Documentation PR

N/A — documentation updates will follow with the TUI wizard PR.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • I ran npm run test:unit and npm run test:integ
  • I ran npm run typecheck
  • I ran npm run lint
  • If I modified src/assets/, I ran npm run test:update-snapshots and committed the updated snapshots

Additionally:

  • Manually tested CLI end-to-end: created apiGateway target, verified mcp.json output
  • Deployed with CDK construct changes and confirmed API Gateway target discovers tools via OpenAPI spec
  • 128 tests pass (117 existing + 11 new), zero regressions

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

@aidandaly24
aidandaly24 requested a review from a teamMarch 6, 2026 19:15
@github-actionsgithub-actionsBot added the size/m PR size: M label Mar 6, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines42.27%3628 / 8581
🔵Statements41.92%3829 / 9133
🔵Functions43.95%720 / 1638
🔵Branches44.03%2348 / 5332
Generated in workflow #887 for commit b4b7bc5 by the Vitest Coverage Report Action

@jesseturner21
jesseturner21 merged commit 3b1df62 into mainMar 6, 2026
19 checks passed
@jesseturner21
jesseturner21 deleted the feat/api-gateway-target branch March 6, 2026 20:32

@tejaskashtejaskash left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes

sourcePath: '',
language: 'Other',
host: 'AgentCoreRuntime',
targetType: 'apiGateway',

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we see if targetType is defined in the original Type?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

And it also looks like createApiGatewayTarget() never reads config.targetType — it hardcodes targetType: 'apiGateway' when building the target object at line ~527


// Handle API Gateway targets (no code generation)
if (cliOptions.type === 'apiGateway') {
const config: AddGatewayTargetConfig = {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The AddGatewayTargetConfig type was designed for MCP server / Lambda targets. For API Gateway targets, several required fields are set to meaningless values:

  • sourcePath: '' — no source code for API Gateway targets
  • host: 'AgentCoreRuntime' — not a real compute host
  • toolDefinition: { name, description, inputSchema: { type: 'object' } } — a dummy value, never used by
    createApiGatewayTarget()

Consider either making these fields optional or introducing a discriminated union / separate config type
for API Gateway targets so the type system enforces correctness.

Comment on lines +331 to +333
if (data.targetType === 'apiGateway') {
if (!data.apiGateway) {
ctx.addIssue({

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The CLI validation correctly rejects --outbound-auth for api-gateway, but the Zod schema's superRefine block does not check for outboundAuth on apiGateway targets. Someone editing mcp.json manually could add outboundAuth to an apiGateway target and the schema would accept it. Add a check similar to the compute/endpoint ones:

if(data.outboundAuth){ctx.addIssue({code: z.ZodIssueCode.custom,message: 'outboundAuth is not applicable for apiGateway target type',path: ['outboundAuth'],});}

.option('--rest-api-id <id>', 'API Gateway REST API ID (required for api-gateway type)')
.option('--stage <stage>', 'API Gateway deployment stage (required for api-gateway type)')
.option('--tool-filter-path <path>', 'Tool filter path pattern, e.g. /pets/*')
.option('--tool-filter-methods <methods>', 'Comma-separated HTTP methods, e.g. GET,POST')

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

When --tool-filter-methods is omitted:

  • In CLI action (GatewayTargetPrimitive.ts:~296): defaults to ['GET']
  • In createApiGatewayTarget (GatewayTargetPrimitive.ts:~530): defaults to [{ filterPath: '/*', methods:
    ['GET'] }]

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@aidandaly24@tejaskash@jesseturner21
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat: add API Gateway REST API as new gateway target type by aidandaly24 · Pull Request #509 · aws/agentcore-cli · GitHub
Skip to content

feat: add API Gateway REST API as new gateway target type - #509

Merged
jesseturner21 merged 4 commits into
mainfrom
feat/api-gateway-target
Mar 6, 2026
Merged

feat: add API Gateway REST API as new gateway target type#509
jesseturner21 merged 4 commits into
mainfrom
feat/api-gateway-target

Conversation

@aidandaly24

Copy link
Copy Markdown
Contributor

Description

Adds --type api-gateway as a new gateway target type, allowing users to register an existing Amazon API Gateway REST API as a gateway target. This enables agents to invoke tools backed by REST API endpoints through an AgentCore gateway without the REST API needing to speak MCP.

Changes:

  • Schema: Added 'apiGateway' to GatewayTargetTypeSchema, 5 new Zod schemas (ApiGatewayConfigSchema, ApiGatewayToolFilterSchema, etc.), apiGateway field on AgentCoreGatewayTargetSchema with superRefine validation
  • CLI flags: --rest-api-id, --stage, --tool-filter-path, --tool-filter-methods
  • Validation: apiGateway-specific validation (requires rest-api-id + stage, rejects inapplicable flags like --endpoint, --host, --outbound-auth)
  • Backend: createApiGatewayTarget() method on GatewayTargetPrimitive — writes apiGateway target config to mcp.json
  • Rename: mapMcpGatewaysToGatewayProvidersmapGatewaysToGatewayProviders, simplified outputs.ts regex
  • Tests: 13 new tests covering schema validation and CLI validation for apiGateway targets

Usage:

agentcore add gateway-target \
--type api-gateway \
--name my-api \
--rest-api-id e6ddhyjvu1 \
--stage prod \
--gateway my-gateway \
--tool-filter-path "/*" \
--tool-filter-methods "GET,POST"

Writes to mcp.json:

{
"name": "my-api",
"targetType": "apiGateway",
"apiGateway": {
"restApiId": "e6ddhyjvu1",
"stage": "prod",
"apiGatewayToolConfiguration": {
"toolFilters": [{ "filterPath": "/*", "methods": ["GET", "POST"] }]
}
}
}

Note: API Gateway targets use GATEWAY_IAM_ROLE for authentication — no credential setup needed. The corresponding CDK construct changes (which synthesize the CloudFormation) are in a separate CDK repo PR.

Related Issue

Closes #

Documentation PR

N/A — documentation updates will follow with the TUI wizard PR.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • I ran npm run test:unit and npm run test:integ
  • I ran npm run typecheck
  • I ran npm run lint
  • If I modified src/assets/, I ran npm run test:update-snapshots and committed the updated snapshots

Additionally:

  • Manually tested CLI end-to-end: created apiGateway target, verified mcp.json output
  • Deployed with CDK construct changes and confirmed API Gateway target discovers tools via OpenAPI spec
  • 128 tests pass (117 existing + 11 new), zero regressions

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

@aidandaly24
aidandaly24 requested a review from a teamMarch 6, 2026 19:15
@github-actionsgithub-actionsBot added the size/m PR size: M label Mar 6, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines42.27%3628 / 8581
🔵Statements41.92%3829 / 9133
🔵Functions43.95%720 / 1638
🔵Branches44.03%2348 / 5332
Generated in workflow #887 for commit b4b7bc5 by the Vitest Coverage Report Action

@jesseturner21
jesseturner21 merged commit 3b1df62 into mainMar 6, 2026
19 checks passed
@jesseturner21
jesseturner21 deleted the feat/api-gateway-target branch March 6, 2026 20:32

@tejaskashtejaskash left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes

sourcePath: '',
language: 'Other',
host: 'AgentCoreRuntime',
targetType: 'apiGateway',

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we see if targetType is defined in the original Type?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

And it also looks like createApiGatewayTarget() never reads config.targetType — it hardcodes targetType: 'apiGateway' when building the target object at line ~527


// Handle API Gateway targets (no code generation)
if (cliOptions.type === 'apiGateway') {
const config: AddGatewayTargetConfig = {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The AddGatewayTargetConfig type was designed for MCP server / Lambda targets. For API Gateway targets, several required fields are set to meaningless values:

  • sourcePath: '' — no source code for API Gateway targets
  • host: 'AgentCoreRuntime' — not a real compute host
  • toolDefinition: { name, description, inputSchema: { type: 'object' } } — a dummy value, never used by
    createApiGatewayTarget()

Consider either making these fields optional or introducing a discriminated union / separate config type
for API Gateway targets so the type system enforces correctness.

Comment on lines +331 to +333
if (data.targetType === 'apiGateway') {
if (!data.apiGateway) {
ctx.addIssue({

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The CLI validation correctly rejects --outbound-auth for api-gateway, but the Zod schema's superRefine block does not check for outboundAuth on apiGateway targets. Someone editing mcp.json manually could add outboundAuth to an apiGateway target and the schema would accept it. Add a check similar to the compute/endpoint ones:

if(data.outboundAuth){ctx.addIssue({code: z.ZodIssueCode.custom,message: 'outboundAuth is not applicable for apiGateway target type',path: ['outboundAuth'],});}

.option('--rest-api-id <id>', 'API Gateway REST API ID (required for api-gateway type)')
.option('--stage <stage>', 'API Gateway deployment stage (required for api-gateway type)')
.option('--tool-filter-path <path>', 'Tool filter path pattern, e.g. /pets/*')
.option('--tool-filter-methods <methods>', 'Comma-separated HTTP methods, e.g. GET,POST')

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

When --tool-filter-methods is omitted:

  • In CLI action (GatewayTargetPrimitive.ts:~296): defaults to ['GET']
  • In createApiGatewayTarget (GatewayTargetPrimitive.ts:~530): defaults to [{ filterPath: '/*', methods:
    ['GET'] }]

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@aidandaly24@tejaskash@jesseturner21
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' feat: add API Gateway REST API as new gateway target type by aidandaly24 · Pull Request #509 · aws/agentcore-cli · GitHub
Skip to content

feat: add API Gateway REST API as new gateway target type - #509

Merged
jesseturner21 merged 4 commits into
mainfrom
feat/api-gateway-target
Mar 6, 2026
Merged

feat: add API Gateway REST API as new gateway target type#509
jesseturner21 merged 4 commits into
mainfrom
feat/api-gateway-target

Conversation

@aidandaly24

Copy link
Copy Markdown
Contributor

Description

Adds --type api-gateway as a new gateway target type, allowing users to register an existing Amazon API Gateway REST API as a gateway target. This enables agents to invoke tools backed by REST API endpoints through an AgentCore gateway without the REST API needing to speak MCP.

Changes:

  • Schema: Added 'apiGateway' to GatewayTargetTypeSchema, 5 new Zod schemas (ApiGatewayConfigSchema, ApiGatewayToolFilterSchema, etc.), apiGateway field on AgentCoreGatewayTargetSchema with superRefine validation
  • CLI flags: --rest-api-id, --stage, --tool-filter-path, --tool-filter-methods
  • Validation: apiGateway-specific validation (requires rest-api-id + stage, rejects inapplicable flags like --endpoint, --host, --outbound-auth)
  • Backend: createApiGatewayTarget() method on GatewayTargetPrimitive — writes apiGateway target config to mcp.json
  • Rename: mapMcpGatewaysToGatewayProvidersmapGatewaysToGatewayProviders, simplified outputs.ts regex
  • Tests: 13 new tests covering schema validation and CLI validation for apiGateway targets

Usage:

agentcore add gateway-target \
--type api-gateway \
--name my-api \
--rest-api-id e6ddhyjvu1 \
--stage prod \
--gateway my-gateway \
--tool-filter-path "/*" \
--tool-filter-methods "GET,POST"

Writes to mcp.json:

{
"name": "my-api",
"targetType": "apiGateway",
"apiGateway": {
"restApiId": "e6ddhyjvu1",
"stage": "prod",
"apiGatewayToolConfiguration": {
"toolFilters": [{ "filterPath": "/*", "methods": ["GET", "POST"] }]
}
}
}

Note: API Gateway targets use GATEWAY_IAM_ROLE for authentication — no credential setup needed. The corresponding CDK construct changes (which synthesize the CloudFormation) are in a separate CDK repo PR.

Related Issue

Closes #

Documentation PR

N/A — documentation updates will follow with the TUI wizard PR.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • I ran npm run test:unit and npm run test:integ
  • I ran npm run typecheck
  • I ran npm run lint
  • If I modified src/assets/, I ran npm run test:update-snapshots and committed the updated snapshots

Additionally:

  • Manually tested CLI end-to-end: created apiGateway target, verified mcp.json output
  • Deployed with CDK construct changes and confirmed API Gateway target discovers tools via OpenAPI spec
  • 128 tests pass (117 existing + 11 new), zero regressions

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

@aidandaly24
aidandaly24 requested a review from a teamMarch 6, 2026 19:15
@github-actionsgithub-actionsBot added the size/m PR size: M label Mar 6, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines42.27%3628 / 8581
🔵Statements41.92%3829 / 9133
🔵Functions43.95%720 / 1638
🔵Branches44.03%2348 / 5332
Generated in workflow #887 for commit b4b7bc5 by the Vitest Coverage Report Action

@jesseturner21
jesseturner21 merged commit 3b1df62 into mainMar 6, 2026
19 checks passed
@jesseturner21
jesseturner21 deleted the feat/api-gateway-target branch March 6, 2026 20:32

@tejaskashtejaskash left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes

sourcePath: '',
language: 'Other',
host: 'AgentCoreRuntime',
targetType: 'apiGateway',

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we see if targetType is defined in the original Type?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

And it also looks like createApiGatewayTarget() never reads config.targetType — it hardcodes targetType: 'apiGateway' when building the target object at line ~527


// Handle API Gateway targets (no code generation)
if (cliOptions.type === 'apiGateway') {
const config: AddGatewayTargetConfig = {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The AddGatewayTargetConfig type was designed for MCP server / Lambda targets. For API Gateway targets, several required fields are set to meaningless values:

  • sourcePath: '' — no source code for API Gateway targets
  • host: 'AgentCoreRuntime' — not a real compute host
  • toolDefinition: { name, description, inputSchema: { type: 'object' } } — a dummy value, never used by
    createApiGatewayTarget()

Consider either making these fields optional or introducing a discriminated union / separate config type
for API Gateway targets so the type system enforces correctness.

Comment on lines +331 to +333
if (data.targetType === 'apiGateway') {
if (!data.apiGateway) {
ctx.addIssue({

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The CLI validation correctly rejects --outbound-auth for api-gateway, but the Zod schema's superRefine block does not check for outboundAuth on apiGateway targets. Someone editing mcp.json manually could add outboundAuth to an apiGateway target and the schema would accept it. Add a check similar to the compute/endpoint ones:

if(data.outboundAuth){ctx.addIssue({code: z.ZodIssueCode.custom,message: 'outboundAuth is not applicable for apiGateway target type',path: ['outboundAuth'],});}

.option('--rest-api-id <id>', 'API Gateway REST API ID (required for api-gateway type)')
.option('--stage <stage>', 'API Gateway deployment stage (required for api-gateway type)')
.option('--tool-filter-path <path>', 'Tool filter path pattern, e.g. /pets/*')
.option('--tool-filter-methods <methods>', 'Comma-separated HTTP methods, e.g. GET,POST')

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

When --tool-filter-methods is omitted:

  • In CLI action (GatewayTargetPrimitive.ts:~296): defaults to ['GET']
  • In createApiGatewayTarget (GatewayTargetPrimitive.ts:~530): defaults to [{ filterPath: '/*', methods:
    ['GET'] }]

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@aidandaly24@tejaskash@jesseturner21
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat: add API Gateway REST API as new gateway target type by aidandaly24 · Pull Request #509 · aws/agentcore-cli · GitHub
Skip to content

feat: add API Gateway REST API as new gateway target type - #509

Merged
jesseturner21 merged 4 commits into
mainfrom
feat/api-gateway-target
Mar 6, 2026
Merged

feat: add API Gateway REST API as new gateway target type#509
jesseturner21 merged 4 commits into
mainfrom
feat/api-gateway-target

Conversation

@aidandaly24

Copy link
Copy Markdown
Contributor

Description

Adds --type api-gateway as a new gateway target type, allowing users to register an existing Amazon API Gateway REST API as a gateway target. This enables agents to invoke tools backed by REST API endpoints through an AgentCore gateway without the REST API needing to speak MCP.

Changes:

  • Schema: Added 'apiGateway' to GatewayTargetTypeSchema, 5 new Zod schemas (ApiGatewayConfigSchema, ApiGatewayToolFilterSchema, etc.), apiGateway field on AgentCoreGatewayTargetSchema with superRefine validation
  • CLI flags: --rest-api-id, --stage, --tool-filter-path, --tool-filter-methods
  • Validation: apiGateway-specific validation (requires rest-api-id + stage, rejects inapplicable flags like --endpoint, --host, --outbound-auth)
  • Backend: createApiGatewayTarget() method on GatewayTargetPrimitive — writes apiGateway target config to mcp.json
  • Rename: mapMcpGatewaysToGatewayProvidersmapGatewaysToGatewayProviders, simplified outputs.ts regex
  • Tests: 13 new tests covering schema validation and CLI validation for apiGateway targets

Usage:

agentcore add gateway-target \
--type api-gateway \
--name my-api \
--rest-api-id e6ddhyjvu1 \
--stage prod \
--gateway my-gateway \
--tool-filter-path "/*" \
--tool-filter-methods "GET,POST"

Writes to mcp.json:

{
"name": "my-api",
"targetType": "apiGateway",
"apiGateway": {
"restApiId": "e6ddhyjvu1",
"stage": "prod",
"apiGatewayToolConfiguration": {
"toolFilters": [{ "filterPath": "/*", "methods": ["GET", "POST"] }]
}
}
}

Note: API Gateway targets use GATEWAY_IAM_ROLE for authentication — no credential setup needed. The corresponding CDK construct changes (which synthesize the CloudFormation) are in a separate CDK repo PR.

Related Issue

Closes #

Documentation PR

N/A — documentation updates will follow with the TUI wizard PR.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • I ran npm run test:unit and npm run test:integ
  • I ran npm run typecheck
  • I ran npm run lint
  • If I modified src/assets/, I ran npm run test:update-snapshots and committed the updated snapshots

Additionally:

  • Manually tested CLI end-to-end: created apiGateway target, verified mcp.json output
  • Deployed with CDK construct changes and confirmed API Gateway target discovers tools via OpenAPI spec
  • 128 tests pass (117 existing + 11 new), zero regressions

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

@aidandaly24
aidandaly24 requested a review from a teamMarch 6, 2026 19:15
@github-actionsgithub-actionsBot added the size/m PR size: M label Mar 6, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines42.27%3628 / 8581
🔵Statements41.92%3829 / 9133
🔵Functions43.95%720 / 1638
🔵Branches44.03%2348 / 5332
Generated in workflow #887 for commit b4b7bc5 by the Vitest Coverage Report Action

@jesseturner21
jesseturner21 merged commit 3b1df62 into mainMar 6, 2026
19 checks passed
@jesseturner21
jesseturner21 deleted the feat/api-gateway-target branch March 6, 2026 20:32

@tejaskashtejaskash left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes

sourcePath: '',
language: 'Other',
host: 'AgentCoreRuntime',
targetType: 'apiGateway',

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we see if targetType is defined in the original Type?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

And it also looks like createApiGatewayTarget() never reads config.targetType — it hardcodes targetType: 'apiGateway' when building the target object at line ~527


// Handle API Gateway targets (no code generation)
if (cliOptions.type === 'apiGateway') {
const config: AddGatewayTargetConfig = {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The AddGatewayTargetConfig type was designed for MCP server / Lambda targets. For API Gateway targets, several required fields are set to meaningless values:

  • sourcePath: '' — no source code for API Gateway targets
  • host: 'AgentCoreRuntime' — not a real compute host
  • toolDefinition: { name, description, inputSchema: { type: 'object' } } — a dummy value, never used by
    createApiGatewayTarget()

Consider either making these fields optional or introducing a discriminated union / separate config type
for API Gateway targets so the type system enforces correctness.

Comment on lines +331 to +333
if (data.targetType === 'apiGateway') {
if (!data.apiGateway) {
ctx.addIssue({

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The CLI validation correctly rejects --outbound-auth for api-gateway, but the Zod schema's superRefine block does not check for outboundAuth on apiGateway targets. Someone editing mcp.json manually could add outboundAuth to an apiGateway target and the schema would accept it. Add a check similar to the compute/endpoint ones:

if(data.outboundAuth){ctx.addIssue({code: z.ZodIssueCode.custom,message: 'outboundAuth is not applicable for apiGateway target type',path: ['outboundAuth'],});}

.option('--rest-api-id <id>', 'API Gateway REST API ID (required for api-gateway type)')
.option('--stage <stage>', 'API Gateway deployment stage (required for api-gateway type)')
.option('--tool-filter-path <path>', 'Tool filter path pattern, e.g. /pets/*')
.option('--tool-filter-methods <methods>', 'Comma-separated HTTP methods, e.g. GET,POST')

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

When --tool-filter-methods is omitted:

  • In CLI action (GatewayTargetPrimitive.ts:~296): defaults to ['GET']
  • In createApiGatewayTarget (GatewayTargetPrimitive.ts:~530): defaults to [{ filterPath: '/*', methods:
    ['GET'] }]

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@aidandaly24@tejaskash@jesseturner21
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat: add API Gateway REST API as new gateway target type by aidandaly24 · Pull Request #509 · aws/agentcore-cli · GitHub
Skip to content

feat: add API Gateway REST API as new gateway target type - #509

Merged
jesseturner21 merged 4 commits into
mainfrom
feat/api-gateway-target
Mar 6, 2026
Merged

feat: add API Gateway REST API as new gateway target type#509
jesseturner21 merged 4 commits into
mainfrom
feat/api-gateway-target

Conversation

@aidandaly24

Copy link
Copy Markdown
Contributor

Description

Adds --type api-gateway as a new gateway target type, allowing users to register an existing Amazon API Gateway REST API as a gateway target. This enables agents to invoke tools backed by REST API endpoints through an AgentCore gateway without the REST API needing to speak MCP.

Changes:

  • Schema: Added 'apiGateway' to GatewayTargetTypeSchema, 5 new Zod schemas (ApiGatewayConfigSchema, ApiGatewayToolFilterSchema, etc.), apiGateway field on AgentCoreGatewayTargetSchema with superRefine validation
  • CLI flags: --rest-api-id, --stage, --tool-filter-path, --tool-filter-methods
  • Validation: apiGateway-specific validation (requires rest-api-id + stage, rejects inapplicable flags like --endpoint, --host, --outbound-auth)
  • Backend: createApiGatewayTarget() method on GatewayTargetPrimitive — writes apiGateway target config to mcp.json
  • Rename: mapMcpGatewaysToGatewayProvidersmapGatewaysToGatewayProviders, simplified outputs.ts regex
  • Tests: 13 new tests covering schema validation and CLI validation for apiGateway targets

Usage:

agentcore add gateway-target \
--type api-gateway \
--name my-api \
--rest-api-id e6ddhyjvu1 \
--stage prod \
--gateway my-gateway \
--tool-filter-path "/*" \
--tool-filter-methods "GET,POST"

Writes to mcp.json:

{
"name": "my-api",
"targetType": "apiGateway",
"apiGateway": {
"restApiId": "e6ddhyjvu1",
"stage": "prod",
"apiGatewayToolConfiguration": {
"toolFilters": [{ "filterPath": "/*", "methods": ["GET", "POST"] }]
}
}
}

Note: API Gateway targets use GATEWAY_IAM_ROLE for authentication — no credential setup needed. The corresponding CDK construct changes (which synthesize the CloudFormation) are in a separate CDK repo PR.

Related Issue

Closes #

Documentation PR

N/A — documentation updates will follow with the TUI wizard PR.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • I ran npm run test:unit and npm run test:integ
  • I ran npm run typecheck
  • I ran npm run lint
  • If I modified src/assets/, I ran npm run test:update-snapshots and committed the updated snapshots

Additionally:

  • Manually tested CLI end-to-end: created apiGateway target, verified mcp.json output
  • Deployed with CDK construct changes and confirmed API Gateway target discovers tools via OpenAPI spec
  • 128 tests pass (117 existing + 11 new), zero regressions

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

@aidandaly24
aidandaly24 requested a review from a teamMarch 6, 2026 19:15
@github-actionsgithub-actionsBot added the size/m PR size: M label Mar 6, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines42.27%3628 / 8581
🔵Statements41.92%3829 / 9133
🔵Functions43.95%720 / 1638
🔵Branches44.03%2348 / 5332
Generated in workflow #887 for commit b4b7bc5 by the Vitest Coverage Report Action

@jesseturner21
jesseturner21 merged commit 3b1df62 into mainMar 6, 2026
19 checks passed
@jesseturner21
jesseturner21 deleted the feat/api-gateway-target branch March 6, 2026 20:32

@tejaskashtejaskash left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes

sourcePath: '',
language: 'Other',
host: 'AgentCoreRuntime',
targetType: 'apiGateway',

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we see if targetType is defined in the original Type?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

And it also looks like createApiGatewayTarget() never reads config.targetType — it hardcodes targetType: 'apiGateway' when building the target object at line ~527


// Handle API Gateway targets (no code generation)
if (cliOptions.type === 'apiGateway') {
const config: AddGatewayTargetConfig = {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The AddGatewayTargetConfig type was designed for MCP server / Lambda targets. For API Gateway targets, several required fields are set to meaningless values:

  • sourcePath: '' — no source code for API Gateway targets
  • host: 'AgentCoreRuntime' — not a real compute host
  • toolDefinition: { name, description, inputSchema: { type: 'object' } } — a dummy value, never used by
    createApiGatewayTarget()

Consider either making these fields optional or introducing a discriminated union / separate config type
for API Gateway targets so the type system enforces correctness.

Comment on lines +331 to +333
if (data.targetType === 'apiGateway') {
if (!data.apiGateway) {
ctx.addIssue({

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The CLI validation correctly rejects --outbound-auth for api-gateway, but the Zod schema's superRefine block does not check for outboundAuth on apiGateway targets. Someone editing mcp.json manually could add outboundAuth to an apiGateway target and the schema would accept it. Add a check similar to the compute/endpoint ones:

if(data.outboundAuth){ctx.addIssue({code: z.ZodIssueCode.custom,message: 'outboundAuth is not applicable for apiGateway target type',path: ['outboundAuth'],});}

.option('--rest-api-id <id>', 'API Gateway REST API ID (required for api-gateway type)')
.option('--stage <stage>', 'API Gateway deployment stage (required for api-gateway type)')
.option('--tool-filter-path <path>', 'Tool filter path pattern, e.g. /pets/*')
.option('--tool-filter-methods <methods>', 'Comma-separated HTTP methods, e.g. GET,POST')

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

When --tool-filter-methods is omitted:

  • In CLI action (GatewayTargetPrimitive.ts:~296): defaults to ['GET']
  • In createApiGatewayTarget (GatewayTargetPrimitive.ts:~530): defaults to [{ filterPath: '/*', methods:
    ['GET'] }]

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@aidandaly24@tejaskash@jesseturner21
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); feat: add API Gateway REST API as new gateway target type by aidandaly24 · Pull Request #509 · aws/agentcore-cli · GitHub
Skip to content

feat: add API Gateway REST API as new gateway target type - #509

Merged
jesseturner21 merged 4 commits into
mainfrom
feat/api-gateway-target
Mar 6, 2026
Merged

feat: add API Gateway REST API as new gateway target type#509
jesseturner21 merged 4 commits into
mainfrom
feat/api-gateway-target

Conversation

@aidandaly24

Copy link
Copy Markdown
Contributor

Description

Adds --type api-gateway as a new gateway target type, allowing users to register an existing Amazon API Gateway REST API as a gateway target. This enables agents to invoke tools backed by REST API endpoints through an AgentCore gateway without the REST API needing to speak MCP.

Changes:

  • Schema: Added 'apiGateway' to GatewayTargetTypeSchema, 5 new Zod schemas (ApiGatewayConfigSchema, ApiGatewayToolFilterSchema, etc.), apiGateway field on AgentCoreGatewayTargetSchema with superRefine validation
  • CLI flags: --rest-api-id, --stage, --tool-filter-path, --tool-filter-methods
  • Validation: apiGateway-specific validation (requires rest-api-id + stage, rejects inapplicable flags like --endpoint, --host, --outbound-auth)
  • Backend: createApiGatewayTarget() method on GatewayTargetPrimitive — writes apiGateway target config to mcp.json
  • Rename: mapMcpGatewaysToGatewayProvidersmapGatewaysToGatewayProviders, simplified outputs.ts regex
  • Tests: 13 new tests covering schema validation and CLI validation for apiGateway targets

Usage:

agentcore add gateway-target \
--type api-gateway \
--name my-api \
--rest-api-id e6ddhyjvu1 \
--stage prod \
--gateway my-gateway \
--tool-filter-path "/*" \
--tool-filter-methods "GET,POST"

Writes to mcp.json:

{
"name": "my-api",
"targetType": "apiGateway",
"apiGateway": {
"restApiId": "e6ddhyjvu1",
"stage": "prod",
"apiGatewayToolConfiguration": {
"toolFilters": [{ "filterPath": "/*", "methods": ["GET", "POST"] }]
}
}
}

Note: API Gateway targets use GATEWAY_IAM_ROLE for authentication — no credential setup needed. The corresponding CDK construct changes (which synthesize the CloudFormation) are in a separate CDK repo PR.

Related Issue

Closes #

Documentation PR

N/A — documentation updates will follow with the TUI wizard PR.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • I ran npm run test:unit and npm run test:integ
  • I ran npm run typecheck
  • I ran npm run lint
  • If I modified src/assets/, I ran npm run test:update-snapshots and committed the updated snapshots

Additionally:

  • Manually tested CLI end-to-end: created apiGateway target, verified mcp.json output
  • Deployed with CDK construct changes and confirmed API Gateway target discovers tools via OpenAPI spec
  • 128 tests pass (117 existing + 11 new), zero regressions

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

@aidandaly24
aidandaly24 requested a review from a teamMarch 6, 2026 19:15
@github-actionsgithub-actionsBot added the size/m PR size: M label Mar 6, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines42.27%3628 / 8581
🔵Statements41.92%3829 / 9133
🔵Functions43.95%720 / 1638
🔵Branches44.03%2348 / 5332
Generated in workflow #887 for commit b4b7bc5 by the Vitest Coverage Report Action

@jesseturner21
jesseturner21 merged commit 3b1df62 into mainMar 6, 2026
19 checks passed
@jesseturner21
jesseturner21 deleted the feat/api-gateway-target branch March 6, 2026 20:32

@tejaskashtejaskash left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes

sourcePath: '',
language: 'Other',
host: 'AgentCoreRuntime',
targetType: 'apiGateway',

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we see if targetType is defined in the original Type?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

And it also looks like createApiGatewayTarget() never reads config.targetType — it hardcodes targetType: 'apiGateway' when building the target object at line ~527


// Handle API Gateway targets (no code generation)
if (cliOptions.type === 'apiGateway') {
const config: AddGatewayTargetConfig = {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The AddGatewayTargetConfig type was designed for MCP server / Lambda targets. For API Gateway targets, several required fields are set to meaningless values:

  • sourcePath: '' — no source code for API Gateway targets
  • host: 'AgentCoreRuntime' — not a real compute host
  • toolDefinition: { name, description, inputSchema: { type: 'object' } } — a dummy value, never used by
    createApiGatewayTarget()

Consider either making these fields optional or introducing a discriminated union / separate config type
for API Gateway targets so the type system enforces correctness.

Comment on lines +331 to +333
if (data.targetType === 'apiGateway') {
if (!data.apiGateway) {
ctx.addIssue({

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The CLI validation correctly rejects --outbound-auth for api-gateway, but the Zod schema's superRefine block does not check for outboundAuth on apiGateway targets. Someone editing mcp.json manually could add outboundAuth to an apiGateway target and the schema would accept it. Add a check similar to the compute/endpoint ones:

if(data.outboundAuth){ctx.addIssue({code: z.ZodIssueCode.custom,message: 'outboundAuth is not applicable for apiGateway target type',path: ['outboundAuth'],});}

.option('--rest-api-id <id>', 'API Gateway REST API ID (required for api-gateway type)')
.option('--stage <stage>', 'API Gateway deployment stage (required for api-gateway type)')
.option('--tool-filter-path <path>', 'Tool filter path pattern, e.g. /pets/*')
.option('--tool-filter-methods <methods>', 'Comma-separated HTTP methods, e.g. GET,POST')

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

When --tool-filter-methods is omitted:

  • In CLI action (GatewayTargetPrimitive.ts:~296): defaults to ['GET']
  • In createApiGatewayTarget (GatewayTargetPrimitive.ts:~530): defaults to [{ filterPath: '/*', methods:
    ['GET'] }]

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@aidandaly24@tejaskash@jesseturner21