Capstone Live Agent Security Lab
Instructor guide → Not signed in

Sign in to the Security Lab

Pick a customer to sign in as. Whoever you authenticate as becomes the agent's actorId — and that identity, not the prompt, decides what the agent is allowed to read.

1 you pick a persona here  →  2 Amazon Cognito collects the password on its own page  →  3 it returns a signed JWT  →  4 Amazon Bedrock AgentCore Runtime validates it and the agent reads the identity from the token

This page never sees your password. It only ever holds the token Cognito issues, and the agent trusts the token — not this UI.

Authentication powered by Amazon Cognito · user pool us-west-2_y41jdYgmH