Skip to main content
Glama

โ˜๏ธ AWS MCP Server

Read-only Model Context Protocol server for AWS resources โ€” multi-region, caching, audit, and AI-ready.


๐Ÿ“‹ Overview

This MCP server exposes 60+ read-only tools across AWS services: identity, EC2, S3, IAM, Cost Explorer, CloudWatch, GuardDuty, CloudTrail, ELB, WAF, Route53, ECS, EKS, RDS, Lambda, and more.

Flow

Description

๐Ÿ”Œ

MCP client connects to this server

๐Ÿ› ๏ธ

Server invokes AWS APIs (read-only)

๐Ÿ“ค

Returns resources, metrics, cost data to the AI agent


Related MCP server: aws-safe-mcp

๐Ÿ› ๏ธ Tech Stack

Layer

Technology

Purpose

โ˜๏ธ MCP Server

TypeScript, AWS SDK v3

Protocol handler, tool dispatch

๐Ÿ“ฆ Runtime

Node.js (v18+)

Execution

๐Ÿ” Auth

AWS credentials (keys, profiles, SSO)

AWS API calls


๐Ÿ—ฃ๏ธ Languages

Language

Used In

TypeScript

MCP server, tools, CLI, libs

JSON

Config (mcp-config.json), MCP schema


๐Ÿ“ Project Structure

โ”œโ”€โ”€ src/
โ”‚   โ”œโ”€โ”€ index.ts          # MCP server entry, tool dispatch, resources, prompts
โ”‚   โ”œโ”€โ”€ load-env.ts       # Loads .env before other modules
โ”‚   โ”œโ”€โ”€ clients.ts        # Shared AWS clients (one per service)
โ”‚   โ”œโ”€โ”€ cli.ts            # Local CLI for testing tools
โ”‚   โ”œโ”€โ”€ integration.test.ts
โ”‚   โ””โ”€โ”€ lib/              # config, cache, retry, audit, rate-limit, webhook, etc.
โ”œโ”€โ”€ docs/                 # TOOLS.md, IAM_PERMISSIONS.md, CONFIG.md, TROUBLESHOOTING.md
โ”œโ”€โ”€ mcp-config.json.example   # Optional: webhook, rate limit, defaults (copy to mcp-config.json)
โ”œโ”€โ”€ Dockerfile            # Container image for running the server
โ””โ”€โ”€ .env                  # AWS credentials (copy from .env.example)

โšก Capabilities

Feature

Description

Multi-region

region parameter on EC2, VPCs, RDS, Lambda tools

Pagination

max_results on list_iam_users, list_s3_buckets, list_ecs_clusters, list_dynamodb_tables, list_cloudformation_stacks

MCP resources

Browse aws://region/service/id (identity, EC2, S3, cost, RDS, Lambda, GuardDuty)

MCP prompts

AI guidance for cost, security, and resource-list queries

Caching

Optional in-memory cache (TTL via MCP_AWS_CACHE_TTL)

Retry

Exponential backoff for throttled AWS calls

Audit log

Log tool invocations when MCP_AWS_AUDIT_LOG=true

Dry-run

Mock data when MCP_AWS_DRY_RUN=true (no AWS calls)

LocalStack

Set AWS_ENDPOINT_URL=http://localhost:4566

Health check

aws_health_check tool to verify credentials

IAM policy

get_iam_policy_for_tools generates least-privilege policy

CLI

npm run cli -- get_aws_caller_identity for local testing

Config file

mcp-config.json for webhook, rate limit, defaults

estimate_cost

Rough cost estimate for EC2, Lambda, RDS, S3

scan_secrets_risks

Find Secrets Manager secrets needing attention

Tag filter

tag_filter on list_ec2_instances, list_rds_instances

SSO / cross-account

See docs/SSO_AND_CROSS_ACCOUNT.md

๐Ÿ“– Documentation: TOOLS.md ยท IAM_PERMISSIONS.md ยท CONFIG.md ยท TROUBLESHOOTING.md


๐Ÿš€ Quick Start

# 1. Configure environment
cp .env.example .env   # Add AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_REGION

# 2. Install and build
npm install
npm run build

# 3. Test locally (dry-run, no AWS calls)
MCP_AWS_DRY_RUN=true npm run cli -- get_aws_caller_identity

MCP Client Configuration

{
  "mcpServers": {
    "aws-mcp": {
      "command": "node",
      "args": ["/absolute/path/to/dist/index.js"],
      "env": {
        "AWS_ACCESS_KEY_ID": "YOUR_ACCESS_KEY",
        "AWS_SECRET_ACCESS_KEY": "YOUR_SECRET_KEY",
        "AWS_REGION": "us-east-1"
      }
    }
  }
}

๐Ÿ“ฆ Sharing with Your Team

Option A: Git

  1. Push to a private repo.

  2. Team clones, runs npm install && npm run build.

  3. Point MCP client at dist/index.js (absolute path).

Option B: Package (.tgz)

npm pack   # Creates mcp-server-aws-1.0.0.tgz
npm install -g mcp-server-aws-1.0.0.tgz

Then configure MCP client with "command": "mcp-server-aws".

Option C: Docker

docker build -t mcp-server-aws .
docker run -e AWS_ACCESS_KEY_ID -e AWS_SECRET_ACCESS_KEY -e AWS_REGION mcp-server-aws

๐Ÿ”ง Development

npm run dev        # Watch mode
npm run typecheck  # TypeScript check (no emit)
npm run cli -- <tool> [--arg key=value]   # Test tools locally
npm run lint       # ESLint
npm run format     # Prettier
npm test           # Unit + integration tests (28 tests)

Release: Push a tag (e.g. v1.0.1) to trigger a GitHub release with built artifacts.


๐Ÿ‘ค Author

Sergio Sediq

Maintenance

ActivityInactive
ResponsivenessNo issues

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

  • The AWS Knowledge MCP server is a fully managed remote Model Context Protocol server that provides real-time access to official AWS content in an LLM-compatible format. It offers structured access to AWS documentation, code samples, blog posts, What's New announcements, Well-Architected best practices, and regional availability information for AWS APIs and CloudFormation resources. Key capabilities include searching and reading documentation in markdown format, getting content recommendations, listing AWS regions, and checking regional availability for services and features.

  • Read-only MCP access to a documented IT fleet: state, changes, posture. 15 tools.

  • The Remote MCP server acts as a standardized bridge between LLM applications (like Claude, ChatGPT, and Cursor) and external services, enabling AI agents to access external tools and resources. Its primary capability is providing a centralized search tool to discover other MCP servers and their respective tools. Unlike local implementations, it runs remotely with OAuth authentication and permission controls for security.

  • The HubSpot MCP Server acts as a bridge that enables AI assistants and Large Language Models to securely interact with HubSpot CRM data through natural conversation, without requiring users to understand complex API structures. It provides read-only access to standard CRM objects (contacts, companies, deals, tickets, products, invoices, and more) and their associations, secured via OAuth 2.0, allowing AI agents to perform tasks like summarizing deals, fetching company updates, and looking up record changes.

Related MCP Servers

  • A
    license
    Not graded
    quality
    D
    maintenance
    A Model Context Protocol server that connects AI assistants like Claude to AWS security services, allowing them to autonomously query, inspect, and analyze AWS infrastructure for security issues and misconfigurations.
    84
    Apache 2.0
  • A
    license
    Not graded
    quality
    C
    maintenance
    A read-only MCP server for safe, structured investigation of AWS serverless resources, providing curated tools for tracing dependencies, permissions, and failures without exposing raw SDK access.
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    A Model Context Protocol (MCP) server that enables AI assistants to perform comprehensive AWS security analysis through natural language queries, bridging AI with AWS security services.
    2
    Apache 2.0
  • A
    license
    Not graded
    quality
    C
    maintenance
    A read-only MCP server that lets an LLM inspect an AWS account โ€” list EC2 instances, S3 buckets, IAM users, and cost โ€” with a structural guarantee against any mutations.
    MIT

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/SergioSediq/aws-mcp-server'

If you have feedback or need assistance with the MCP directory API, please join our Discord server