AWS Just Made Your AI Agent's Search API Optional
AWS added domain and date filters to Bedrock AgentCore Web Search at $7 per 1,000 queries. Compare the build-vs-buy math before you renew your search API.
On August 20, AWS shipped an update to Web Search on Amazon Bedrock AgentCore: domain and published-date filtering, plus expansion to Europe and Asia Pacific. Agents can now restrict results to an allowlist of up to 100 domains, exclude another 100, and constrain results to a published-date window using ISO-8601 timestamps.
That’s a feature note. Most people will skim it and move on.
Here’s why you shouldn’t. A large share of the small and mid-sized companies running production agents are paying a second vendor to do exactly this: Tavily, Perplexity’s Search API, Serper, Exa, or a legacy Google Custom Search key. Separate contract, separate API key, separate egress path out of your cloud. The filters AWS just added were the last real functional gap between the managed option and the standalone one.
Quick Verdict
| Question | The Answer |
|---|---|
| What shipped? | Domain include/exclude filtering and published-date range filtering for Web Search on AgentCore, announced August 20, 2026. |
| How many domains? | Up to 100 per list, across four independent lists: admin include, admin exclude, runtime include, runtime exclude. |
| Date format? | Inclusive ISO-8601 UTC bounds, like 2026-08-04T23:59:59Z, passed as from and to. |
| Where does it run? | US East (N. Virginia), plus new Europe (Ireland) and Asia Pacific (Tokyo). |
| What does it cost? | $7 per 1,000 queries, per the AgentCore pricing page. No commitment, no minimum. |
| Do I need a search API key? | No. It’s a built-in connector target on AgentCore Gateway, exposed over MCP. |
| Does my query leave AWS? | No. AWS describes it as a zero-egress architecture: queries are served inside AWS, not forwarded to a third-party engine. |
| What version? | Web-search connector 1.2.0. |
| Who should care? | Anyone already on Bedrock who pays a separate search vendor. |
| Who should not switch? | Anyone off AWS, or anyone whose agent needs search results AWS’s index doesn’t cover well. |
What is AI agent grounding?
Grounding is the practice of feeding an AI agent current, citable source material at query time so its answer reflects real information instead of whatever the model memorized during training. A grounded agent retrieves web snippets, URLs, titles, and publication dates, then answers from those. Ungrounded agents guess confidently about last week.
That’s the whole reason the search-API line item exists on your bill.
What Actually Changed
Web Search on AgentCore went generally available on June 17 at AWS Summit New York, announced as a way to ground agents in current, cited web knowledge. It launched in one region with no source controls. Useful for a demo. Hard to defend in a regulated workflow.
The August update fixed the second problem in two ways.
Domain filtering now works at two levels. An admin sets gateway-level policy when creating the Web Search target, and the agent can pass its own include and exclude lists per call in the tools/call payload. Four lists, 100 domains each, counted independently. The runtime piece is the part that matters operationally: an agent can narrow to trusted sources for one question and open up for the next without anyone reconfiguring a gateway.
Date filtering takes inclusive UTC bounds. You want stock coverage from the last seven days, you set from and to and the connector handles it. No post-filtering in your orchestration layer, no burning tokens on stale results your code throws away three steps later.
AWS’s own examples in the announcement are the honest use cases: a financial agent restricted to SEC filings and approved wire services, a clinical research assistant limited to FDA, NIH, and ClinicalTrials.gov, per-tenant source policies in a multi-tenant SaaS product. Those aren’t hypotheticals. They’re the exact requests that used to force teams to write their own filtering middleware.
And the regional expansion is not a footnote. Europe (Ireland) and Asia Pacific (Tokyo) mean a German or Japanese customer’s agent queries can stay in-region. If you’ve ever tried to explain to a European client that their agent’s search terms travel to a US search vendor’s infrastructure, you already know why eu-west-1 is the whole conversation.
The Price Comparison Nobody Runs
Here’s the part that gets skipped, because $7 sounds like more than $5 and people stop there.
| Option | List price | Notes |
|---|---|---|
| Web Search on AgentCore | $7 / 1,000 queries | No separate key, no egress, IAM-scoped |
| Perplexity Search API | $5 / 1,000 requests | Flat per successful request, no token cost |
| Tavily pay-as-you-go | $0.008 / credit | Basic search is 1 credit, so ~$8 / 1,000 |
| Tavily Project plan | ~$12-15 / month | 4,000 credits included, higher rate limits |
| Google Custom Search JSON API | $5 / 1,000 queries | Closed to new customers. Shuts down January 1, 2027. |
Read the last row twice. If your agent’s grounding runs on a Google Custom Search key, you have a migration deadline about four months out and Google isn’t taking new signups. That alone reframes this from “interesting AWS feature” to “one of your two remaining options.”
Now the actual math. At 50,000 queries a month, AgentCore costs $350 and Perplexity costs $250. A hundred dollars a month apart. Call it $1,200 a year.
Against that, count what the second vendor actually costs you beyond the invoice: a security review, a vendor questionnaire, a key rotation policy, a data-processing agreement, an entry in your subprocessor list, an outage you can’t escalate through your existing AWS support contract, and one more egress path an auditor will ask about. I’ve watched organizations spend more than $1,200 in staff time getting a single new vendor through procurement.
Below roughly 100,000 queries a month, the price difference is not a decision input. It’s rounding.
Where the $7 Stops Being a Good Deal
I’m not writing an AWS ad, so let’s be specific about when this is the wrong call.
You’re not on AWS. Obvious, and it disqualifies most of the market. AgentCore Web Search is a connector on AgentCore Gateway. If your agents run on Azure, GCP, or a VPS, the integration cost swamps the savings. Use the standalone API.
Your queries are high-volume and simple. At 500,000 queries a month, $7 versus $5 is $1,000 a month, and now it’s real money. Volume changes the answer. Tavily’s Growth tier and Perplexity’s flat rate both get more attractive as the count climbs, and at that scale you probably have the engineering capacity to manage another key.
You need search features AWS hasn’t shipped. Tavily does extraction and crawling. Exa does embedding-based retrieval. Perplexity gives you a synthesis layer on top. AgentCore Web Search returns snippets, URLs, titles, and publication dates against Amazon’s index and knowledge graph. That covers grounding well. It does not cover every retrieval pattern.
You have not tested result quality on your actual queries. This is the one people skip. Search indexes differ, and the difference shows up in your domain, not in a benchmark. Run 200 of your real production queries through both and compare. That test takes an afternoon and it’s the only evidence that matters.
You’re consolidating for its own sake. Vendor consolidation is a strategy, not a virtue. I made this case when Gemini Spark priced Google’s agent layer and it holds here: moving a component inside your cloud provider trades one dependency for a deeper one. Deeper is often correct. It’s never free.
How do you decide between AgentCore Web Search and a standalone search API?
Six steps. A technical lead can work through this in a day, and the only cost is a few hundred test queries.
- Count your current monthly search volume. Pull the number from your existing provider’s dashboard. If you don’t have one because grounding isn’t in production yet, estimate queries per agent run times expected runs.
- Multiply by both prices and look at the gap. Under $200 a month of difference, price is not your deciding factor and you should stop optimizing it.
- Run 200 real production queries through both. Same prompts, same day. Compare result relevance and freshness by hand. Not a benchmark, your queries.
- Check whether you need the filters. If your agent must cite only approved sources or only recent content, the August update is the feature you were about to build yourself. Price that build honestly.
- Ask your security lead what a new subprocessor costs. Get a real number in staff hours for the review, the DPA, and the annual re-review. Add it to the standalone option’s total.
- Confirm your region. If you need EU or Japan data residency,
eu-west-1andap-northeast-1just became available and that may settle it outright.
Steps 1 through 3 are this week. Steps 4 through 6 are the decision meeting.
The Anti-Hype Read
Three caveats worth holding.
“Zero egress” is a real security property and a partial one. Your query text doesn’t go to a third-party search vendor, which is genuinely better than the alternative and easy to explain to an auditor. It does not mean your agent is isolated. It’s fetching public web content and putting it into a model’s context, which is the same prompt-injection surface it always was. Filtering to trusted domains reduces that surface meaningfully. It doesn’t remove it.
Bundled tools get repriced. $7 per 1,000 is a launch-era number on a service that went GA in June. AWS has no obligation to hold it, and the switching cost after you’ve built against the MCP connector is higher than the switching cost today. Model your budget at flat pricing rather than assuming the usual decline, the same discipline I’d apply to any AI runtime cost line item.
A filter is a policy, and policies rot. A 100-domain allowlist written in August 2026 will contain a dead source by spring. Somebody owns that list by name, or it quietly degrades your agent’s answers while everyone assumes the filter is protecting them.
My Read
Three things I think are true.
The bundling of agent infrastructure is the story of this year, and search was the last obvious unbundled piece. Memory, identity, gateway, code interpreter, browser, and now grounded search all sit inside one AWS service with one IAM boundary and one bill. That’s the same consolidation pattern showing up in A2A becoming a neutral standard and in every hyperscaler’s agent roadmap. The pieces that were startups in 2024 are line items on a cloud invoice in 2026.
The filters matter more than the regions, and both matter more than the price. Domain allowlisting is what moves an agent from “interesting” to “approvable” in a compliance review. Most of the agent projects I see stall on governance, not capability, which is a large part of why so many agent efforts get canceled. A per-call source allowlist is a governance control with a config field, and those are rare.
Build-versus-buy on AI components is now mostly a question about your existing boundary, not about the component. Five years ago you’d compare feature matrices. Today the honest question is: does this thing live inside a security perimeter I’ve already paid for? If yes, a 40% price premium is usually still cheaper than the total cost of the alternative. If no, the managed convenience doesn’t reach you and you should buy the better standalone tool without guilt.
Here’s what I’d tell a business owner who thinks this is an engineering call. It’s a procurement call with an engineering test attached. You have a vendor doing one job. Your cloud provider now does that job at a slightly higher list price with fewer contracts to sign. That’s a decision you’ve made a hundred times in other categories, and the fact that it’s AI doesn’t change how you make it. Run the quality test, count the overhead, pick one.
The Bottom Line
AWS closed the functional gap between its bundled web search and the standalone AI search APIs. Domain allowlists up to 100 entries, exclude lists, ISO-8601 date windows, and now three regions instead of one. At $7 per 1,000 queries with no separate key and no egress out of your account, the managed option is competitive on price and ahead on governance.
That doesn’t mean cancel your Tavily contract this afternoon. It means the assumption that grounding requires a dedicated search vendor is no longer automatic for AWS customers, and if you’re on a Google Custom Search key you have a January 1, 2027 deadline whether you like it or not.
Your Next Step: This week, pull your last 30 days of search-API usage and write down two numbers: total queries and total spend. Then export 200 real production queries and run them against both your current provider and AgentCore Web Search. Compare the results yourself, by hand, for an hour. If quality is a wash and your volume is under 100,000 a month, consolidating removes a vendor from your stack for about the cost of a team lunch. If quality isn’t a wash, you just made your renewal conversation much easier, because now you know exactly what you’re paying the premium for.
Related Reading:
TAGS
What is this worth in your business?
The free Build Audit is 30 minutes. You leave with a ranked list of the automations worth doing in your business, whether or not we build them.
Related Articles
Keep Your Customer Data Out of ChatGPT and Claude
Free ChatGPT and Claude accounts can train on what your team types in. Two switches turn that off for nothing. Here is where to find both tonight.
How to Tell If an AI Vendor's ROI Claim Is Real
Learn the three-question test that separates a real AI vendor ROI number from a marketing one, before you sign the contract or approve the next renewal.
Thomson Reuters Just Answered Your Build vs. Buy Question
Thomson Reuters spent $40M fine-tuning an open-source model on Westlaw data to match frontier performance. Compare that build vs. buy math against your own.