{"name":"agentcore-auth-lab","purpose":"Compare authentication systems for calling Amazon Bedrock AgentCore: AWS IAM, and any OpenID Connect provider so far.","guard":"Every route except this one and /api/health needs the x-lab-token header.","jwt":"JWT strategies also take the end user's token in Authorization: Bearer.","console":"Open /console in a browser for a simple page that invokes an agent through this API.","endpoints":{"GET /api/health":"Liveness. No AWS calls.","GET /api/strategies":"Authentication strategies, what each proves, and whether it is configured.","GET /api/strategies/{id}/identity":"Which principal or user a strategy authenticates as.","POST /api/strategies/{id}/invoke":"Invoke an AgentCore Runtime using that strategy.","POST /api/agent/prompts":"Send a user prompt. The backend adds its instruction and answers 202 with a job ID.","GET /api/agent/prompts/{jobId}":"Poll a prompt job: pending, then done with the reply or error.","GET /api/agent/instruction":"Read-only view of the instruction the backend adds to prompts.","GET /api/agentcore/runtimes":"List AgentCore Runtimes (control plane, always IAM)."}}