Cloud ops#Cloud

AWS MCP Server: every AWS API through one endpoint

AWS's managed MCP server: one authenticated endpoint for 300+ services, sandboxed scripts and live docs search, governed by IAM and logged in CloudTrail.

Project and installation docs

View project

https://github.com/aws/agent-toolkit-for-aws

AWS has more than 300 services, models rarely keep up with their API changes, and letting an agent improvise CLI commands is hard to audit. AWS MCP Server is a remote server that AWS hosts: the agent calls any AWS API through one authenticated endpoint, runs multi-step jobs as Python scripts in an isolated environment, and searches current official documentation. It ships with the Agent Toolkit for AWS, whose repository had about 2.8k stars as of 2026-10-06.

What it does

  • Full API coverage: one endpoint for 300+ AWS services, to inspect resources, change configuration and run operations.
  • Sandboxed scripts: the agent can run Python in an isolated environment for tasks that take many calls.
  • Live documentation: search and read current AWS docs, API references and service capabilities, with no authentication needed for that part.
  • Enterprise controls: CloudWatch metrics, IAM condition keys that tell agent actions apart from human ones, and CloudTrail audit logs.
  • Bundled skills: the toolkit’s plugins, starting with aws-core, package the MCP config together with skills for CDK, CloudFormation, serverless and more.

Who it’s for

  • Developers using Claude Code, Codex or Cursor to deploy on AWS or debug resource configuration.
  • Platform and security teams who need an audit trail of what agents did in the cloud.

Setup

Needs uv, and local AWS credentials for API calls and scripts. In Claude Code, install the official plugin:

/plugin install aws-core@claude-plugins-official

Other clients add the MCP config (the README’s example is for Kiro):

{
  "mcpServers": {
    "aws": {
      "command": "uvx",
      "args": [
        "mcp-proxy-for-aws-cli@latest",
        "https://aws-mcp.us-east-1.api.aws/mcp",
        "--metadata",
        "AWS_REGION=us-west-2"
      ]
    }
  }
}

Our take

AWS’s MCP story used to be dozens of open source servers in awslabs/mcp. AWS now points to this managed server as the place to start, and marks the old AWS API MCP Server as superseded. The reason to pick it is governance: calls go through IAM, land in CloudTrail and can be constrained for agents specifically with condition keys, none of which you get from an agent typing CLI commands. The trade-off is that requests pass through an AWS-hosted endpoint whose server code isn’t in the repo. The risk is plain too: full API access means it can create and delete resources and run up bills, so give it a least-privilege IAM role and try it in a test account first. The Agent Toolkit repository is licensed Apache-2.0.