Service eligibility and regional restrictions
PuppyIP serves only compliant overseas businesses and their authorized personnel. Proxy services are not available in mainland China. The service may only be used for lawful business activities outside mainland China. Use of this service within mainland China is prohibited.
Hosting a proxy IP or server overseas does not change these restrictions. The service must not be provided to end users in mainland China through relaying, forwarding, sharing or resale. Before use, read the Terms of Service.
Key Takeaways
- AgentCore Memory FGAC uses OAuth/JWT, AgentCore Gateway, and Cedar to move per-user and per-tenant isolation from application code to the infrastructure layer.
- The Memory connector exposes 12 Memory operations as Cedar actions. Policies can allow or deny access by caller identity, actor data, namespace, and specific operation.
- Cedar denies by default, and forbid takes precedence over permit. A 403 does not necessarily indicate a network problem and should not be blindly addressed by expanding IAM permissions.
- actorId and namespace must still be derived consistently from trusted identity fields. Flexible namespace variables, also launched on August 28, support up to 5 keys for organizations, tenants, teams, or environments.
- Before rollout, run five test groups: valid access, cross-tenant access, missing claims, incorrect namespaces, and sensitive operations. Stop expansion if any unauthorized access or unexplained denial occurs.
The scenario: chat works, but Memory requests return 403 after enabling FGAC
After a team places AgentCore Memory behind AgentCore Gateway, chat inference still works, but reading long-term memory or writing events is denied. A more dangerous symptom is an application that checks only whether a user is signed in while letting the client submit actorId or namespace, allowing a test tenant to construct someone else's path. The costs include broken personalization, support backlogs, and authorization and compliance responsibilities arising from cross-tenant memory exposure.
The wrong instinct is to grant the execution role broader IAM permissions or treat 403 as unstable outbound networking. The correct first step is to capture the authenticated principal, redacted token claims, actorId, namespace, operation name, Gateway target, and policy decision logs for one request. Reproduce with one known sample, then determine whether the failure is in authentication, mapping, or Cedar evaluation.
Old approach and new capability: application if checks become Gateway enforcement
Previously, an application typically read the user identity, checked actorId itself, constructed a namespace, and called Memory. Any overlooked route, background job, or new interface could bypass those checks. On August 28, 2026, AWS announced FGAC support for AgentCore Memory: a Memory resource can sit behind a Gateway using OAuth JWT authentication, with Cedar restricting actor data, token-claim-derived namespaces, and specific Memory operations according to the authenticated caller.
This does not replace IAM, the Memory data model, or all business authorization. IAM still controls who can manage or call AWS resources; actorId and namespace still organize data. FGAC adds a deterministic check for every connector operation at the Gateway boundary. The official documentation says the connector exposes 12 Memory operations as Cedar actions, so policies must cover the actions actually called rather than just use a generic read or write name.
Map identity to data paths before writing Cedar policies
First establish a single trusted identity source, such as the JWT subject and tenant claim. Then define whether actorId represents a user, device, or service principal, and whether namespaces follow a pattern such as /tenant/{tenantId}/user/{sub}/. Do not authorize using fields that clients can freely change, and do not use mutable attributes such as an email display name as long-term keys.
Flexible namespace variables, launched the same day, address cases where built-in actorId, strategyId, and sessionId cannot express organizations, tenants, teams, or environments. Define namespace keys on the Memory resource, reference them in a strategy's namespace template, and supply values at runtime through CreateEvent. Each Memory resource supports up to 5 keys, and the same key can be used across multiple strategies. This capability is available in all AWS Regions where AgentCore Memory is generally available, at no additional charge. However, it only handles organization and scope; it does not validate a tenant value submitted by a client for you.
Use default deny and a minimal set of operations. Initially allow only one necessary action and one exact namespace for a test principal, then add permissions incrementally. Cedar forbid overrides permit, and the absence of any matching permit also results in denial. For candidate policies generated from natural language, read the output, validate the schema, and test in a nonproduction environment. Successful generation does not prove correct authorization.
Five test groups: prove both allowed access and the absence of unauthorized access
First, have a valid user read and write their own actor and namespace. Second, replace only the tenant or actorId; access must be denied. Third, remove or tamper with a required claim; authentication or the policy layer must reject it. Fourth, keep the user unchanged but switch to an unauthorized namespace; access must be denied. Fifth, build an allow matrix for the 12 connector actions and confirm that only the create, read, retrieve, or delete operations genuinely required by the application are enabled.
For each group, record the expected result, actual status, Gateway and policy versions, CloudWatch decision evidence, and any data side effects. Acceptance is not simply “the main flow returns 200.” Valid samples must consistently pass, all cross-tenant and missing-claim samples must consistently fail, and the team must be able to explain each denial.
A 403 troubleshooting tree and stop conditions
First determine whether the request reached Gateway. DNS, TLS, and connection timeouts occur before policy evaluation. If there is an explicit authorization denial, inspect the JWT audience, issuer, expiry, and required claims. After authentication passes, check principal tags, the action name, Gateway resource, and namespace conditions. Finally, look for a higher-priority forbid, spelling errors, type mismatches, or a missing permit. Change one variable at a time and replay the fixed sample.
Immediately stop expansion if any cross-tenant access succeeds, logs are missing, an allow decision cannot be explained, delete operations have excessive scope, or test and production identity mappings differ. Rollback should restore the previous verified policy and Gateway configuration, not disable FGAC. If service can only be restored through a global permit, keep it unavailable or degrade to a mode that does not read or write long-term memory, and obtain review from the security owner.
Scope, common misconceptions, and the role of networking
This capability suits AgentCore applications with multiple users, multiple tenants, or different Memory operation permissions for different callers. A single-tenant prototype can also use it, but should weigh the cost of maintaining Gateway, policies, and auditing. Do not conflate AgentCore Policy's general tool-call capabilities with this Memory connector FGAC feature, or infer Regions, pricing, or plan availability not stated by the official documentation. Verify actual service and documentation availability in the target Region before rollout.
Misconceptions include assuming actorId inherently equals the authenticated user, IAM Allow overrides Cedar Deny, permit cancels forbid, or changing the egress IP fixes an authorization denial. Consult the proxy connection troubleshooting checklist only when requests do not reach Gateway and independent evidence shows DNS, TLS, or connection timeouts. PuppyIP cannot correct JWTs, Cedar policies, or tenant mappings.
Sources
Frequently Asked Questions
When was AgentCore Memory FGAC released?
AWS What's New published the announcement on August 28, 2026, using the wording “AgentCore Memory now supports fine-grained access control.” The page does not list Region-by-Region or additional plan coverage, so the target Region still needs verification before rollout.
Does FGAC replace IAM?
No. IAM continues to control AWS resource and management-plane permissions. Through Gateway and Cedar, FGAC adds data-plane authorization based on the authenticated caller, namespace, actor data, and specific Memory operation.
Why does a request still return 403 after adding permit?
The action, principal, resource, or conditions may not match, or a forbid may apply. Cedar denies by default and gives forbid precedence. Check the actual connector action and decision logs item by item.
Can actorId or custom namespace variables directly use client-supplied values?
Do not directly treat unverified client fields as the authorized identity. Custom namespace variables can represent organizations, tenants, teams, or environments, but should still be consistently derived from or strictly bound to trusted identities such as verified JWT claims. Cross-tenant negative tests must demonstrate that they cannot be forged.
What is the minimum testing needed before a policy goes live?
At minimum, test access to the user's own data, cross-tenant access, missing or tampered claims, incorrect namespaces, and every Memory action actually used. Negative samples must consistently be denied.
Can changing IP address resolve AgentCore Memory 403 errors?
It cannot resolve authentication or Cedar denials after a request reaches Gateway. Network troubleshooting is a separate step only when transport evidence such as DNS, TLS, or connection timeouts exists.