Amazon Bedrock |
Agent |
Credentials: Access key ID and secret access key; AWS region
Optional (for agent invocation workflows):
Setup: Agents must have an alias linked to a version and an invocable URL
|
Amazon Bedrock AgentCore Runtime |
Agent |
Credentials: Access key ID and secret access key; AWS region
Account: Active AWS account with AgentCore access
-
bedrock-agentcore:ListAgentRuntimes
-
bedrock-agentcore:ListAgentRuntimeEndpoints
-
bedrock-agentcore:GetAgentCard
-
bedrock-agentcore:GetAgentRuntime
-
bedrock-agentcore:ListAgentRuntimeVersions
-
bedrock:GetAgent
-
bedrock:ListAgents
Setup: Agents must be published with an active endpoint/version
|
Anthropic Claude Managed Agents |
Agent |
Credentials: Claude API key
Account: Paid Anthropic account
|
Databricks Agent Bricks |
Agent |
Credentials: Workspace URL; client ID and client secret
Account: Databricks workspace access
Permissions: Service principal CAN_QUERY on serving endpoints; CAN_VIEW or higher on endpoint metadata APIs
Setup: Discoverable agents must be custom Unity Catalog models in READY state
|
GoDaddy ANS |
Agent |
Credentials: API key and API secret
|
Google Gemini Agent Enterprise Platform |
Agent |
Credentials: GCP project ID; service account email; private key
|
LangChain LangSmith |
Agent |
Credentials: LangSmith API key; LangSmith workspace ID
Account: LangSmith Plus plan (or higher) workspace
Setup: Optional API host for region routing (for example, US or EU cloud host)
|
Microsoft Azure Copilot |
Agent |
Credentials: Azure app registration; tenant ID, client ID, client secret
Role: Copilot Studio Scanner
Setup: App added as an Application User in Power Platform; scope set to Dataverse environment URL, https://<org-Id>.crm.dynamics.com
|
Microsoft Foundry |
Agent |
Credentials: Azure app registration; tenant ID, client ID, client secret
Account: Active Azure subscription
Setup: Project endpoint URLs (discovery is project-specific)
|
Snowflake Cortex AI |
Agent |
Credentials: Snowflake account URL; programmatic access token (PAT)
Account: Snowflake account with Cortex Agents enabled (Enterprise edition)
Role: ACCOUNTADMIN, for one-time setup only
Setup: At least one Cortex Agent created in a schema to be scanned; scanner egress IP ranges from your Anypoint deployment team (<SCANNER_EGRESS_CIDRS>)
|
Amazon API Gateway |
API |
Credentials: Access key ID and secret access key; AWS region
Permissions: IAM read-only policy for API Gateway:
-
Read permission: apigateway:GET
-
Read action group: apigateway:GET* on REST and HTTP API resources
-
Resource scope (REST APIs): arn:aws:apigateway:{region}::/restapis/*
-
Resource scope (HTTP APIs): arn:aws:apigateway:{region}::/apis/*
|
|
For web application firewall (WAF) policies, the scanner also uses software.amazon.awssdk:wafv2 and software.amazon.awssdk:route53.
|
|
Azure API Management |
API |
Credentials: Tenant ID; client ID; client secret; subscription ID; resource group; service name
Role: API Management Service Reader
|
Google Apigee |
API |
Credentials: GCP project ID; service account email; private key
Role: Apigee Read-only Admin
|
Kong Gateway |
API |
Credentials: Personal access token (PAT); Kong Gateway region
Role: Kong Control Plane Viewer
|
Akamai Security |
API Security |
Credentials: Akamai Security base URL; client ID and client secret
Permissions: Access to create service accounts in Akamai Security; access to apply Akamai correlation policy in target environments
Setup: Existing services in Portfolio catalogs for correlation targets; create a connected app in MuleSoft; configure Akamai-side sync with the MuleSoft connected app. For details, see Correlating Risk Using Akamai API Security.
|
Amazon Bedrock AgentCore MCP |
MCP |
Credentials: Access key ID and secret access key; AWS region
Account: Active AWS account
Permissions: IAM user with an inline policy that allows:
-
bedrock-agentcore:ListAgentRuntimes
-
bedrock-agentcore:GetAgentRuntime
-
bedrock-agentcore:ListAgentRuntimeVersions
-
bedrock-agentcore:ListAgentRuntimeEndpoints
-
bedrock-agentcore:InvokeAgentRuntime
Policy read permissions: Runtime read actions, including bedrock-agentcore:ListAgentRuntimes and bedrock-agentcore:GetAgentRuntime
|
Azure API Management MCP Server |
MCP |
Credentials: Tenant ID; client ID; client secret; subscription ID; resource group; service name
Role: API Management Service Reader
|
Snowflake MCP Server |
MCP |
Credentials: Snowflake account URL; programmatic access token (PAT)
Account: Snowflake Enterprise account with MCP servers enabled
|