Service eligibility and regional restrictions
PuppyIP serves only compliant overseas businesses and their authorized personnel. Proxy services are not available in mainland China. The service may only be used for lawful business activities outside mainland China. Use of this service within mainland China is prohibited.
Hosting a proxy IP or server overseas does not change these restrictions. The service must not be provided to end users in mainland China through relaying, forwarding, sharing or resale. Before use, read the Terms of Service.
Key Takeaways
- The April 28 announcement was limited preview. The September 29 announcement and current guide establish public preview, with APIs and features still subject to change; this is not GA.
- The preview covers us-east-1, us-west-2 and us-east-2. Sessions use regional bedrock-mantle /openai/v1/agents/sessions endpoints, not normal bedrock-runtime model invocation.
- Your app creates sessions, supplies instructions and execution environments, and submits messages. BMA manages sessions and model interactions; commands and local tools run on your host or AgentCore Runtime.
- Check caller identity, session role, iam:PassRole, supported BMA models and an isolated working directory. The sample default openai.gpt-5.6-luna does not prove access for every account.
- BMA adds no service charge during preview, but inference and AWS resources remain billable. AgentCore examples create storage, networking and NAT gateways that may charge even with no active turn.
From limited preview in April to public preview in September
On April 28, 2026, AWS listed OpenAI models, Codex and Managed Agents in limited preview. Its September 29 announcement says BMA is now available in preview, and the current guide explicitly says public preview. This guide covers that scope and its documented onboarding, not all-region GA. The announcement shows a US Pacific date; its embedded publication time is September 29 at 21:10 UTC, or September 30 at 05:10 Shanghai time.
BMA uses an AWS-native Agents API co-developed with OpenAI. It retains session context and supports reusable skills and MCP-server tools. AWS describes independent IAM roles per agent, human approval for important actions and CloudTrail for supported API activity. This does not automatically authorize any script or guarantee a complete audit of every internal action.
Check region, endpoint and model eligibility separately
Preview regions are N. Virginia us-east-1, Oregon us-west-2 and Ohio us-east-2, using https://bedrock-mantle.us-east-1.api.aws, https://bedrock-mantle.us-west-2.api.aws and https://bedrock-mantle.us-east-2.api.aws. Sign requests for the actual region and bedrock-mantle service. Sessions use /openai/v1/agents/sessions; model discovery uses /v1/models.
Confirm BMA support in the region, model visibility in the region and account, and inference permissions for the session role. A model in /v1/models alone does not prove BMA compatibility. The sample defaults to openai.gpt-5.6-luna; choose within actual BMA support and account results. Preview does not use bedrock-runtime or cross-region inference profiles. The Runtime quota guide explains why Runtime metrics do not directly measure Mantle session capacity.
Separate caller identity, session role and execution environment
AWS examples require Node.js 20+, AWS CLI v2, Bash, SigV4-capable curl, jq and Codex CLI 0.154.0+ with codex exec-server. Use your organization's existing AWS credentials to confirm account and region. The identity deploying IAM/CDK, the client signing BMA requests, and the session role providing inference permissions are distinct responsibilities. The client also needs iam:PassRole to pass the session role to BMA.
Use a dedicated directory exposing only task-required files, networking and tools. Self-hosting needs a host continuously running codex exec-server. AgentCore Runtime creates execution, storage and networking resources in your AWS account. BMA manages sessions and model interaction, while tools execute in your supplied environment. Deleting a session does not automatically delete host or S3 files.
Follow the official self-hosted trial
First select a supported region, inspect your model list and IAM requirements, and review roles and permissions created by the example CDK. Next create a session in a dedicated directory and record session ID, environment ID, model and role ARN. A session ID alone proves no host connectivity. Then start codex exec-server under the same client identity and confirm SigV4 registration and WebSocket connection.
Submit a simple task without sensitive data, wait for the turn, and inspect durable items and command-execution results to confirm the expected host ran the command rather than relying on HTTP 200. Finally delete the session, stop exec-server and follow official cleanup for unused CloudFormation, AgentCore, storage and networking. Account separately for idle NAT gateway costs with AgentCore.
Preview limitations affect architecture choices
The limits page documents text session input, no subagents or cross-region inference profiles, and no supported programmatic tool calling/code mode workflow. There is no separate turn-list or individual-turn retrieval API. Track progress through documented event streams and durable items; an accepted parameter does not prove official support.
BMA's AWS bedrock-mantle API does not guarantee feature, field or release-time parity with OpenAI-hosted Agents API. Check current limits before requiring image input, multi-agent execution, cross-region routing or a mature production SLA. Public preview promises no account-specific production support, model capacity or quota.
Charges, failure diagnosis and network boundaries
No extra BMA service charge during preview does not mean a free agent. Model inference, AgentCore, storage and networking remain usage-billed. Example NAT gateways may charge with no BMA turns. Define budgets and cleanup ownership, and check bills and CloudFormation resources after a trial. GA pricing may change.
For session creation errors record region, endpoint, caller identity, request ID, model, session role and IAM errors. Check permissions and eligibility for AccessDenied or unavailable models first. Investigate exits using the connection troubleshooting guide only with DNS, TLS, WebSocket, timeout or proxy-authentication evidence. Fixed IPs and proxies grant neither model access, iam:PassRole nor quotas, and do not remove AWS charges.
Sources
- AWS: Bedrock Managed Agents preview, September 29, 2026
- AWS: limited preview of OpenAI models, Codex and Managed Agents, April 28, 2026
- Bedrock User Guide: preview overview and regional endpoints
- Bedrock User Guide: permissions and prerequisites
- Bedrock User Guide: self-hosted trial
- Bedrock User Guide: preview quotas and limitations
- Bedrock User Guide: security and IAM
- Bedrock User Guide: cleanup of example resources
Frequently Asked Questions
Is Bedrock Managed Agents GA?
No. April was limited preview; the September 29 announcement and current docs establish public preview. APIs and features may change.
Which regions support public preview?
The docs list us-east-1, us-west-2 and us-east-2. Check account model access and IAM separately; regional availability does not authorize every account for each model.
Can BMA sessions use bedrock-runtime?
Do not reuse the Runtime invocation path. Preview uses regional bedrock-mantle and /openai/v1/agents/sessions, with /v1/models for discovery.
Where do tool commands execute?
BMA manages sessions and models. Tools execute on your self-hosted host or AgentCore Runtime in your account. Limit that environment's files, network and permissions independently.
Does no BMA preview surcharge mean no bill?
No. Inference and underlying resources remain billable; storage, networking and example NAT gateways may charge while idle.
Can a proxy fix AccessDenied or missing model access?
No. Check caller identity, iam:PassRole, session role, region and account access. Investigate networking only with DNS, TLS, WebSocket or timeout evidence.