---
title: Mastering Amazon Bedrock CLIs: AWS CLI, Model Operations, and AgentCore
description: Two CLIs, not one binary named bedrock-cli. AWS CLI 2.37.12 and agentcore 0.30.0, checked 11 October 2026.
url: https://www.factualminds.com/blog/mastering-bedrock-cli/
datePublished: 2026-10-11T00:00:00.000Z
dateModified: 2026-10-11T00:00:00.000Z
author: palaniappan-p
category: Generative AI
tags: amazon-bedrock, bedrock-agentcore, aws-cli, ai-agents
---

# Mastering Amazon Bedrock CLIs: AWS CLI, Model Operations, and AgentCore

> Two CLIs, not one binary named bedrock-cli. AWS CLI 2.37.12 and agentcore 0.30.0, checked 11 October 2026.

On 11 October 2026 this page was checked against AWS CLI `2.37.12` and AgentCore CLI `0.30.0` (`agentcore --version`). There is no single official executable named `bedrock-cli` in that pair. `aws help` on this build lists eight Bedrock-related namespaces. `agentcore --help` lists a separate project CLI. Commands that would call a model, create a runtime, or read production logs were **not** run.

Two published figures from this site, not new measurements: a support-style AgentCore sketch at about $791 per month for 50K sessions is in the [AgentCore vs Quick decision guide](/blog/aws-bedrock-agentcore-vs-amazon-q-enterprise-decision-guide-2026/). Gateway server-side tool round-trip from about 180 ms to about 95 ms on a B2B CRM assistant is in the [Gateway post](/blog/amazon-bedrock-agentcore-gateway-server-side-tool-execution-2026/). Use them as cost and latency context. They are not a promise for your catalog agent.

> **What broke** — AWS CLI help for `bedrock-agent` and `bedrock-agent-runtime` on 2.37.12 says Amazon Bedrock Agents, now Agents Classic, is no longer open to new customers and tells you to look at AgentCore. A tutorial that starts with `aws bedrock-agent create-agent` is the wrong default for a new support bot. The [June 2026 lifecycle note](/blog/aws-service-lifecycle-updates-june-2026/) dates maintenance for new customers at 30 July 2026. Existing Agents Classic workloads can keep running. New work starts on AgentCore. Architecture is in [AgentCore production](/blog/amazon-bedrock-agentcore-production/), not repeated here.

> **Reproduce this** — Run `bash examples/architecture-blog-2026/mastering-developer-tools/mastering-bedrock-cli/check-clis.sh`. On 11 October 2026 it printed `aws-cli/2.37.12` and `agentcore=0.30.0`, then `lab=ok`. It does not call Bedrock. Published copy: [/examples/architecture-blog-2026/mastering-developer-tools/mastering-bedrock-cli/check-clis.sh](/examples/architecture-blog-2026/mastering-developer-tools/mastering-bedrock-cli/check-clis.sh).

We recommend the `agentcore` CLI for project create, local dev, deploy, invoke, logs, traces, and evals, and the AWS CLI when you need an API operation the project CLI does not wrap. The trade-off: `agentcore deploy` hides CloudFormation or CDK details that `aws bedrock-agentcore-control` shows. When a deploy fails, you still need the AWS CLI identity check and the control-plane `get-*` call.

## The interfaces, and which plane they talk to

| Interface | Binary | Plane | Use |
| --- | --- | --- | --- |
| `aws bedrock` | AWS CLI | Control | Models, guardrails, evaluation jobs, provisioned throughput |
| `aws bedrock-runtime` | AWS CLI | Data | `converse`, `invoke-model`, `count-tokens`, guardrail checks |
| `aws bedrock-agent` | AWS CLI | Control | Agents Classic configuration. Not the default for new agents. |
| `aws bedrock-agent-runtime` | AWS CLI | Data | Agents Classic retrieval and sessions. Same lifecycle note. |
| `aws bedrock-agentcore-control` | AWS CLI | Control | Runtimes, harnesses, gateways, evaluators |
| `aws bedrock-agentcore` | AWS CLI | Data | `invoke-agent-runtime`, memory, batch evaluation |
| `agentcore` | AgentCore CLI 0.30.0 | Project tool | Create, dev, deploy, logs, traces, evals |

`aws bedrock-data-automation` and `aws bedrock-data-automation-runtime` also appear in `aws help` on this build. They are a different product surface. This article does not teach them.

Identity and region are the [AWS CLI](/blog/mastering-aws-cli/) checks. Run them before any command in the tables below.

```bash
aws sts get-caller-identity --no-cli-pager
aws configure get region
```

A wrong region is a wrong model list. Model access is regional.

## Discovery on each CLI

AWS CLI, read-only, no network beyond whatever `help` does locally:

```bash
aws bedrock help
aws bedrock-runtime help
aws bedrock-agentcore-control help
aws bedrock-agentcore help
```

AgentCore CLI, observed on 0.30.0:

```bash
agentcore --help
agentcore create --help
agentcore dev --help
agentcore logs --help
agentcore traces --help
agentcore validate --help
```

`agentcore --help` on 0.30.0 includes `create`, `dev`, `deploy`, `invoke`, `logs`, `status`, `traces`, `validate`, `evals`, `run`, `package`, and `export`, among others. If your version differs, trust `agentcore --help` over this page.

## Models, tokens, and guardrails

These AWS CLI operations were listed by help on 2.37.12. They were not executed.

| Task | Command | Risk |
| --- | --- | --- |
| List models | `aws bedrock list-foundation-models` | **Read-only** |
| One model | `aws bedrock get-foundation-model` | **Read-only** |
| Inference profiles | `aws bedrock list-inference-profiles` | **Read-only** |
| One profile | `aws bedrock get-inference-profile` | **Read-only** |
| List guardrails | `aws bedrock list-guardrails` | **Read-only** |
| Converse | `aws bedrock-runtime converse` | **Potential cost impact** |
| Invoke | `aws bedrock-runtime invoke-model` | **Potential cost impact** |
| Count tokens | `aws bedrock-runtime count-tokens` | **Potential cost impact** if the API bills the call. Check the pricing page for that model. |
| Apply a guardrail | `aws bedrock-runtime apply-guardrail` | **Potential cost impact** |

`converse` requires `--model-id`. The help text says that id can be a foundation model or an inference profile. Read `aws bedrock-runtime converse help` for the body shape. Do not reuse a JSON body from another provider. Parameter names are model-specific.

`create-provisioned-model-throughput` and `create-foundation-model-agreement` are **remote mutation**. Provisioned throughput is **potential cost impact** that continues until you delete it. `delete-provisioned-model-throughput` is the rollback, and it is also a change. List and get first.

Guardrail writes (`create-guardrail`, `update-guardrail`) change policy for every caller that uses that guardrail id. **Remote mutation.** Get the current guardrail and save the JSON before you update it.

## Knowledge bases and Agents Classic

`aws bedrock-agent help` can list and get knowledge bases, data sources, and ingestion jobs (`list-knowledge-bases`, `get-knowledge-base`, `list-data-sources`, `get-ingestion-job`). Those are control-plane reads when you only list or get. Starting an ingestion job is a mutation and can incur embedding cost.

`aws bedrock-agent-runtime` help on this CLI lists `retrieve` and `retrieve-and-generate`. Retrieval is a data-plane call. It can return customer content. Treat the output as sensitive.

The same help text says Agents Classic is no longer open to new customers. `create-agent` still appears for accounts that are allowed to call it. Do not use it as the template for a new e-commerce support agent. If you operate an existing Classic agent, `get-agent` and `list-agents` are the inspection commands. Invocation shapes change. Read `aws bedrock-agent-runtime help` on your CLI instead of an old `invoke-agent` snippet. On 2.37.12 that exact command name was **not** in the available-commands list.

## AgentCore control plane and data plane

Control plane (`aws bedrock-agentcore-control`), from help, not run:

| Task | Command | Risk |
| --- | --- | --- |
| Get a runtime | `get-agent-runtime` | **Read-only** |
| List is the matching `list-agent-runtimes` | see help | **Read-only** |
| Create a runtime | `create-agent-runtime` | **Remote mutation**, **potential cost impact** |
| Get a harness | `get-harness` | **Read-only** |
| Create a harness | `create-harness` | **Remote mutation**, **potential cost impact** |
| Get a gateway | `get-gateway` | **Read-only** |

`create-agent-runtime` help marks `--agent-runtime-name`, `--agent-runtime-artifact`, and `--role-arn` as required. The artifact structure is in that help page. Filling it in creates infrastructure. Do it in a sandbox account after `sts get-caller-identity`.

Data plane (`aws bedrock-agentcore`):

| Task | Command | Risk |
| --- | --- | --- |
| Invoke | `invoke-agent-runtime` | **Potential cost impact**. The agent may also call tools that change orders. |
| Evaluate | `evaluate`, `start-batch-evaluation` | **Potential cost impact** |
| Memory | `retrieve-memory-records`, `list-memory-records` | **Read-only**, may contain customer text |
| Delete memory | `delete-memory-record` | **Potentially destructive** |

`invoke-agent-runtime` is how you hit a deployed runtime without the `agentcore` wrapper. The wrapper is easier for a project. The AWS CLI is what you use when you are debugging permissions and the project CLI hides the error.

## The agentcore binary

Observed subcommands and flags on 0.30.0. Not a deploy.

`agentcore create` can run non-interactively with `--defaults`, `--language` (`Python` or `TypeScript`), `--framework` (the help list includes `Strands`, `LangChain_LangGraph`, `GoogleADK`, `OpenAIAgents`, `VercelAI`), and `--model-provider` (`Bedrock`, `Anthropic`, `OpenAI`, `Gemini`). `--api-key` puts a key on the command line. Prefer a provider that uses the AWS identity you already checked, and do not put production keys in shell history.

`agentcore dev` starts a local server. Default port in help is `8080`. `--skip-deploy` skips automatic resource deployment. `--no-traces` disables local OTEL trace collection. `--no-browser` stays in the terminal. A dev command that deploys without `--skip-deploy` is **remote mutation** and **potential cost impact**. Read `agentcore dev --help` and watch the first lines of output for account and region.

`agentcore deploy` help text says it deploys project infrastructure to AWS via CDK. **Remote mutation** and **potential cost impact**. Run `agentcore deploy --help` before you add flags this page does not list.

`agentcore invoke` sends a prompt to a deployed endpoint. `--session-id` continues a session. `--prompt-file` keeps a long prompt out of the process list. The prompt can contain customer data. The reply can too.

`agentcore status` shows deployed resource status. **Read-only** relative to the agent, though it calls AWS.

`agentcore logs` can stream or search. `--since 1h`, `--level error`, and `--json` were in the 0.30.0 help. Logs are production data.

`agentcore traces list` and `agentcore traces get TRACE_ID` download traces. Traces show tool calls. A tool call that refunded an order is an audit record. Store it. Do not post it raw.

`agentcore validate` checks `agentcore/` config. `--json` is for scripts. Run it before deploy.

`agentcore evals` and `agentcore run` deal with evaluations. They can spend model tokens. **Potential cost impact.**

`agentcore export` exports a harness to a Strands runtime agent. Read the help. It writes files. **Local change.**

## Scenario: a support agent retrieves bad product data or calls the wrong tool

1. `aws sts get-caller-identity` and the region. Confirm the sandbox or the production account out loud.
2. `agentcore status` and, if you need the API record, `aws bedrock-agentcore-control get-agent-runtime` or `get-harness` with the id from status. Help lists the id flags. Do not guess them.
3. `agentcore logs --since 1h --level error --json` and `agentcore traces list`. Find the turn where retrieval returned the wrong SKU or the tool name was not on the allow list.
4. If the failure is `AccessDenied`, the missing action is in the error. Fix the role. Do not attach administrator to the runtime role.
5. If retrieval is empty, inspect the knowledge base or gateway target with a get command. A sync or ingestion job that failed is a control-plane fact, not a prompt problem.
6. `agentcore validate`, then a sandbox invoke with a fixed question whose answer you already know.
7. Re-run the eval set (`agentcore evals` or a batch evaluation you already created) before you call production healthy.

Refunds, order edits, and payments stay behind a human approval step. The [human-in-the-loop](/blog/human-in-the-loop-ai-agents-ecommerce-2026/) post is the product rule. A CLI invoke that passes is not that approval.

## IAM, cost, and output limits

Least privilege means the runtime role can call the model and the tools you named, and cannot `s3:DeleteBucket` or change orders unless a reviewed tool does so. Test with `iam simulate-principal-policy` from the [AWS CLI](/blog/mastering-aws-cli/) article when you are unsure.

Token and latency limits are model-specific. `count-tokens` is the CLI check when the operation accepts your payload. A 400 from `converse` that says the input is too long is the enforcement. Truncating customer text silently is a product bug. Log the refusal.

Timeouts and retries belong in the application. The CLI is a single call. A shell loop that retries `invoke-model` without a cap is a bill.

Region: list models in the region you will deploy. A model id from another region fails or routes differently when you use an inference profile. Read `get-inference-profile` before you hard-code an id an agent suggested.

## Working with a coding agent

Ask the coding agent to run `sts get-caller-identity`, `agentcore --version`, and `agentcore validate`. Ask it to show the control-plane get, not to create a runtime, until you have named the account. Refuse `--api-key` on the command line and refuse `delete-memory-record` or `delete-agent-runtime` without a read of what will be removed. After deploy, you run `agentcore status` and one eval question yourself.

Coding-agent CLIs are the [next article](/blog/mastering-ai-agent-tools/). They are not this runtime.

## Five labs

1. Run `check-clis.sh`. Record both versions. If `agentcore=absent`, install from the project docs, not from a random script, and re-run.
2. `aws bedrock help` and write down one control-plane read and one data-plane command from `aws bedrock-runtime help`.
3. In a sandbox, `aws bedrock list-foundation-models --no-cli-pager` and confirm the region. **Read-only.** Stop if the account is production.
4. `agentcore create --help` and read `--defaults` and `--model-provider`. Create a project only in an empty directory you can delete. Do not pass a production API key.
5. `agentcore validate` in that project. Expected: a pass or a specific config error. Fix the config. Do not `deploy` until lab 3's account is the one you intend.

Progression: name the binary, list models in the right region, validate a project, invoke in a sandbox, then trace one tool call.

## What this post does not cover

Full AgentCore architecture, pricing math beyond the two cited posts, and Data Automation. Model choice and harness design stay in the production guide linked above. This page will drift when `agentcore --help` changes. The version pin is 0.30.0.

## What to do this week

1. Run the version script and save the output next to your runbook.
2. Search the repo for `bedrock-agent create-agent` and mark those paths as Classic.
3. Put `sts get-caller-identity` in front of any deploy script the coding agent generated.
4. Pick one support question with a known SKU and decide how you will eval it before the next deploy.

## Quick reference

| I need to | Command | Risk |
| --- | --- | --- |
| See CLI versions | `aws --version` and `agentcore --version` | **Read-only** |
| List models | `aws bedrock list-foundation-models` | **Read-only** |
| Call a model | `aws bedrock-runtime converse` | **Potential cost impact** |
| Inspect a runtime | `get-agent-runtime` or `agentcore status` | **Read-only** |
| Create a runtime | `create-agent-runtime` or `agentcore deploy` | **Potential cost impact** |
| Read a failure | `agentcore logs` and `agentcore traces` | **Read-only**, sensitive |

You should be able to name which binary you are using, refuse Agents Classic for a new agent, and separate a control-plane get from an invoke that spends money.

## Further reading

- [AWS CLI bedrock](https://docs.aws.amazon.com/cli/latest/reference/bedrock/)
- [bedrock-runtime](https://docs.aws.amazon.com/cli/latest/reference/bedrock-runtime/)
- [bedrock-agent](https://docs.aws.amazon.com/cli/latest/reference/bedrock-agent/)
- [bedrock-agentcore](https://docs.aws.amazon.com/cli/latest/reference/bedrock-agentcore/)
- [bedrock-agentcore-control](https://docs.aws.amazon.com/cli/latest/reference/bedrock-agentcore-control/)
- [AgentCore developer guide](https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/)
- [agentcore-cli](https://github.com/aws/agentcore-cli)
- Series: [Git](/blog/mastering-git-commands/), [Linux](/blog/mastering-linux-commands/), [AWS CLI](/blog/mastering-aws-cli/), [Docker](/blog/mastering-docker-commands/), [Kubernetes](/blog/mastering-kubernetes-commands/), [AI agent tools](/blog/mastering-ai-agent-tools/)

[Contact us](/contact-us/) or start at [AI agents](/ai-agents/) if the next step is a scoped support or catalog agent, not another CLI flag. The field guide is [eCommerce AI agents](/resources/ecommerce-ai-agents/). We are an AWS Select Tier Services Partner. That is not an Agentic AI Competency.

## FAQ

### Is there an official bedrock-cli binary?
Not as a separate product name you should assume. On 11 October 2026 the tools on this machine were the AWS CLI, with several bedrock namespaces, and the AgentCore CLI binary named agentcore at version 0.30.0. Check aws help and agentcore --help before you copy a command from an old gist.


### When should a new project avoid Agents Classic?
When it is a new customer or a new agent. AWS CLI 2.37.12 help text says Amazon Bedrock Agents, now Agents Classic, is no longer open to new customers and points at AgentCore. Existing customers can keep running what they have. The site lifecycle note dates that maintenance change at 30 July 2026.


### Does every AgentCore feature have a CLI command?
No. The AWS CLI exposes control-plane and data-plane APIs that exist as operations. The agentcore binary exposes project, deploy, logs, traces, and eval commands in version 0.30.0. A missing subcommand means you use the API, an SDK, or the console, not that you should invent a flag.


### What is the expensive mistake with invoke-model?
Calling a model, or creating provisioned throughput, in the wrong account or region. sts get-caller-identity and the region come first. Provisioned throughput and some runtime creates are billable even when the demo looks idle.


### Can the CLI print a secret from a tool call?
Yes, if the model or the log line contains one. Treat logs and traces as sensitive. Do not paste them into a ticket unredacted. Do not put API keys in agentcore create --api-key on a shared shell history if you can avoid it.


---

*Source: https://www.factualminds.com/blog/mastering-bedrock-cli/*
