aws-mcp-connector
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@aws-mcp-connectorRun aws s3 ls to list my S3 buckets"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
π aws-mcp-connector
Talk to AWS CLI from an MCP-speaking agent.
A single static Go binary that speaks the Model Context Protocol
and lets an agent run AWS CLI commands: any aws <service> <operation>
invocation, across every service the CLI supports, with a read-only-by-default
safety gate on anything that mutates state.
No Python, no uv, no runtime dependency to install β just a binary and
an .mcp.json. It shells out to the aws binary already installed and
configured on the host (profile, SSO, IAM role, or static keys β whatever
the AWS CLI's own credential chain resolves) instead of reimplementing the
AWS SDK, so it gets the full breadth of the CLI for free rather than a
hand-curated subset of services.
β¨ Why this exists
An agent that only has a narrow, hand-picked set of AWS tools hits a wall the moment you need something outside that set. This connector instead wraps the AWS CLI itself, so an agent can run
aws s3 ls,aws ec2 describe-instances,aws iam list-usersβ anything the CLI can do β without waiting on a new tool to be written for it. Mutating commands are blocked by default and require both a server-level opt-in and a per-callconfirm=true, so exploring/debugging is safe out of the box.
Related MCP server: AWS MCP Server
π§° Tools
Tool | What it does | Write? |
| Run any | β (gated) |
| Show | |
| Show the AWS identity (account, ARN, user/role) the configured credentials resolve to. | |
| List named profiles configured in |
Every tool accepts an optional response_format: markdown (default,
pretty tables for a chat UI) or json (for programmatic use).
π Quickstart
Fastest path: grab a prebuilt bundle from the latest release β
download aws-mcp-connector-plugin-<version>-<os>-<arch>.zip, unzip it,
and point Cowork/Claude at the plugin/ folder inside (see step 4 of
SETUP.md). No Go toolchain required.
From source:
# 1. Build
cd go-server
go mod tidy
go build -o aws-connector-server .
cp aws-connector-server ../plugin/servers/go/
# 2. Set up auth β needs the aws CLI itself installed and configured
# (aws configure / aws sso login) β see SETUP.md
export AWS_PROFILE=default # optional, only if not using "default"
# 3. Run
./go-server/aws-connector-server # serves MCP over stdioOr make build β see the Makefile for every shortcut
(test, vet, fmt, lint, tidy).
Full walkthrough β including wiring this up as a Claude/Cowork plugin β is in SETUP.md.
π Configuration
Everything is environment variables, passed through by the plugin's
.mcp.json:
Variable | Purpose | Default |
| Named profile from | unset (default profile) |
| Default region if not set elsewhere. | AWS CLI's own default |
| Static credentials β only needed if not using a profile/SSO/role. | unset |
|
|
|
| Comma-separated allowlist of AWS CLI service names, e.g. | unset (unrestricted) |
| Path to the |
|
π§ͺ Quality bar
This isn't a toy script β it's got the same checks you'd expect from a production Go service:
β Unit tests for every input-validation path (
go test ./...)β
go vet+gofmtcleanβ golangci-lint (govet, staticcheck, errcheck, gosec, and more)
β govulncheck β no known vulnerabilities in the dependency graph
β CodeQL static security analysis on every push
β End-to-end verified against a real (or sandboxed) AWS CLI backend β not mocks
β Dependabot keeps Go modules and Actions current
All of it runs in CI on every push and PR.
π·οΈ Releases & versioning
Versions follow semver and are cut automatically by
release-please from
Conventional Commits on main:
fix: ...β patch (v0.1.0βv0.1.1)feat: ...β minor (v0.1.1βv0.2.0)feat!: .../BREAKING CHANGE:footer β major (v0.2.0βv1.0.0)
Every merged PR updates a standing "chore(main): release vX.Y.Z" PR with an auto-generated CHANGELOG.md. Merging that PR:
tags the release and publishes it on GitHub
builds and attaches zipped, ready-to-install plugin bundles for linux/darwin/windows Γ amd64/arm64
regenerates
server.jsonfrom those exact assets (fresh version + SHA-256 hashes) and publishes it to the official MCP Registry viamcp-publisher, authenticated with GitHub OIDC β no stored secrets
See .github/workflows/release-please.yml
and .github/workflows/publish-mcp-registry.yml
(also runnable by hand for an existing tag via workflow_dispatch).
π Layout
aws-mcp-connector/
βββ README.md β you are here
βββ SETUP.md β step-by-step setup guide
βββ CONTRIBUTING.md β how to contribute
βββ CODE_OF_CONDUCT.md
βββ SECURITY.md β vulnerability reporting
βββ CODEOWNERS
βββ LICENSE β MIT
βββ Makefile β build / test / lint shortcuts
βββ .golangci.yml β lint rules
βββ release-please-config.json β semver/changelog automation config
βββ .release-please-manifest.json
βββ server.json β MCP Registry manifest (regenerated fresh per release by CI)
βββ scripts/
β βββ render-server-json.sh β rebuilds server.json from a release's zip assets
βββ .github/
β βββ workflows/
β β βββ ci.yml β build, vet, test, lint, govulncheck
β β βββ codeql.yml β security scanning
β β βββ pr-title.yml β Conventional Commits PR title check
β β βββ release-please.yml β version PRs, tagging, GitHub releases
β β βββ publish-mcp-registry.yml β publishes server.json to the MCP Registry
β β βββ rebuild-release-assets.yml β manual re-attach fallback
β βββ ISSUE_TEMPLATE/
β βββ PULL_REQUEST_TEMPLATE.md
β βββ dependabot.yml
βββ go-server/ β the MCP server source
β βββ main.go
β βββ main_test.go
β βββ go.mod / go.sum
β βββ README.md
βββ plugin/ β installable Cowork/Claude plugin
βββ .claude-plugin/plugin.json
βββ .mcp.json β holds credentials locally β never commit real ones
βββ servers/go/ β compiled binary goes hereπ€ Contributing
PRs and issues are very welcome β see CONTRIBUTING.md for the full guide (setup, coding conventions, how to add a new tool) and the Code of Conduct.
main is protected: every change, including the maintainer's, lands via
pull request with CI green. PR titles must follow
Conventional Commits β that's what
drives the automatic versioning above.
Found a security issue? Please follow SECURITY.md instead of opening a public issue.
π License
MIT Β© FerhatDundar
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Alicense-qualityCmaintenanceA lightweight service that enables AI assistants to execute AWS CLI commands through the Model Context Protocol (MCP), allowing AI tools to retrieve AWS documentation and interact with AWS services.Last updated185MIT
- Alicense-qualityDmaintenanceEnables AI assistants to execute AWS CLI commands and access AWS documentation, resources, and prompt templates through the Model Context Protocol with support for Unix pipes and secure Docker-based deployment.Last updatedMIT
- Alicense-quality-maintenanceEnables AI assistants to execute AWS CLI commands and retrieve service documentation through the Model Context Protocol. It supports Unix pipes for output filtering and provides pre-defined prompt templates for common cloud management tasks.Last updated
- Alicense-qualityBmaintenanceProvides a comprehensive suite of tools for interacting with AWS services like S3, EC2, and Lambda using natural language commands. It enables AI assistants to inspect, manage, and operate AWS resources directly through the Model Context Protocol using your local credentials.Last updated151Apache 2.0
Related MCP Connectors
A paid remote MCP for Context7 MCP docs, built to return verdicts, receipts, usage logs, and audit-r
Read-only Remote MCP for externally grounded AI agent trust receipts.
Remote MCP for Copilot CLI switch gate MCP, structured receipts, audit logs, and reviewer-ready evid
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/FerhatDundar/aws-mcp-connector'
If you have feedback or need assistance with the MCP directory API, please join our Discord server