Bedrock Managed Agents OpenAI vs the Agents API

This research library uses AI-assisted source research and drafting. Linked sources support product claims; analysis and proposed exercises are our interpretation. Unless an article documents a test and its results, do not read it as a hands-on review or an independently verified benchmark.
Bedrock Managed Agents, powered by OpenAI, is a limited-preview AWS service that runs the OpenAI agent harness and model inference inside Amazon Bedrock. OpenAI announced it at DevDay on 29 September 2026 as the AWS-native sibling of the Agents API. OpenAI's Bedrock Managed Agents comparison page is the clearest primary source, and it frames the choice around where the loop runs and how you authenticate.
Short version: pick the Agents API when you want OpenAI to host the agent and you already work with OpenAI project keys. Pick Bedrock Managed Agents when your agents must stay inside AWS, sign requests with IAM, and sit next to AWS data and compute.
What Bedrock Managed Agents actually runs
The DevDay recap says OpenAI worked with Amazon to take the core Agents API capabilities and add customization so agents work natively in AWS. The goal is OpenAI agents that run entirely in AWS and connect to AWS resources.
The AWS product page adds a few specifics. The managed runtime handles inference, memory and skills within your environment. Every agent gets its own identity and logs every action for auditability. All inference runs on Amazon Bedrock, and AWS states that your data never leaves AWS.
Bedrock AgentCore is the default compute environment. AWS says AgentCore and Bedrock Managed Agents will add authorization policy enforcement, agent and tool discovery, and observability and evaluation. Read "will" literally: those are roadmap items, not launch features.
Status matters here. The AWS page labels the service a limited preview and offers a "Sign up for updates" form. It does not list a price, supported Regions, or service limits. OpenAI's docs tell you to check AWS documentation for all of those.
Bedrock Managed Agents vs the Agents API
Both services use agents and sessions. The differences sit in the plumbing. This table follows OpenAI's comparison page:
| Area | OpenAI Agents API | Bedrock Managed Agents |
|---|---|---|
| Agent loop | Managed by OpenAI | Hosted in Amazon Bedrock |
| Model inference | OpenAI API | Amazon Bedrock |
| API endpoint | OpenAI API | Amazon Bedrock service endpoint |
| Execution environment | OpenAI-hosted sandbox, self-hosted sandbox, or no sandbox | AgentCore Runtime or self-hosted compute |
| API authentication | OpenAI project API key | AWS IAM credentials with SigV4 signing |
| Launch status | Public beta since 10 September 2026 | Limited preview |
One detail catches people out. A self-hosted sandbox on the Agents API only moves where commands and tools run. The harness and model inference still use the OpenAI service. If your requirement is "inference stays in AWS", a self-hosted executor does not meet it.
OpenAI also warns that shared concepts do not mean identical API contracts or feature availability. Do not copy Agents API code into a Bedrock project and expect it to run. Check the AWS guidance for the endpoint, supported models, tools and environment configuration first.
When should you pick which?
Use these questions in order. The first "yes" usually decides it.
- Does policy require model inference and agent state to stay in AWS? Pick Bedrock Managed Agents and join the preview.
- Do your services authenticate with IAM roles today, with no OpenAI keys allowed? Bedrock Managed Agents fits that model.
- Do you need to ship this quarter on an API you can call today? The Agents API is in public beta with docs, SDKs and examples.
- Do you need computer use, OpenAI-hosted sandboxes, or partner sandboxes such as Cloudflare, E2B or Modal? Those are documented for the Agents API. Confirm Bedrock support before planning around them.
- Do you want to keep your compute but accept OpenAI inference? Use the Agents API with a self-hosted sandbox.
Pricing differs in kind too. Agents API model usage is billed at the model's API rates, and OpenAI-hosted sandboxes use standard container rates. For Bedrock, AWS handles billing, and the managed agents price is not published yet.
What an Agents API session with your own compute looks like
If you want to test the loop today, the self-hosted path is the closest thing to "my infrastructure, OpenAI harness". From the self-hosted sandbox guide:
import OpenAI from "openai";
const client = new OpenAI();
const session = await client.beta.agents.sessions.create({
agent: {
model: "gpt-6-astra",
instructions:
"You are a helpful coding assistant. Write clean code and verify that it works.",
},
environment: {
type: "self_hosted",
workspace_directory: "/workspace",
},
});
Inside the environment you run codex exec-server, the executor. It connects outbound to https://api.openai.com and wss://codex-cloud-environments.chatgpt.com. It authenticates with a separate environment key passed in as CODEX_API_KEY, and that key can only connect environments. Keep your application's OPENAI_API_KEY outside the sandbox, because agent-generated code can read whatever the environment holds.
Can Codex use OpenAI models on AWS today?
Yes, but that is a different product from Bedrock Managed Agents. Local Codex surfaces can send model requests to Amazon Bedrock instead of the OpenAI Responses API. The Codex Amazon Bedrock guide shows the provider setting in ~/.codex/config.toml:
model_provider = "amazon-bedrock-runtime"
model = "global.openai.gpt-6-astra"
Use amazon-bedrock-runtime for cross-Region inference, or amazon-bedrock for in-Region inference on the Mantle endpoint. Authentication uses a Bedrock API key or the standard AWS SDK credential chain, including aws sso login --profile. Open /status in the Codex CLI to confirm the provider.
The limits are real. Hosted ChatGPT Work on the web, Codex cloud, Fast mode, image generation and web search are not available on this path. Local features such as /review, worktrees, skills, MCP and AGENTS.md work. We have written about a Codex CLI billing surprise on Bedrock, so watch cache-write costs in your first week.
A practical workflow: while you wait for preview access, use Codex CLI on the Bedrock provider to draft and test the instructions, skills and MCP tools your managed agent will need. Run it under the same AWS profile the agent will use. You then arrive at the preview with tested instructions and a clear list of AWS permissions, rather than a blank page.
If your team is deciding how Codex agents should run inside your cloud boundary, our Codex training for teams works through that decision on your own repositories.
Next step: sign up on the AWS page, then write down which of the five questions above your security team answers "yes" to.