aws_call
Execute any AWS API operation via the AWS CLI by specifying kebab-case service and operation names and passing parameters as JSON.
Instructions
Run an arbitrary AWS API operation via the aws CLI. Use kebab-case service and operation names as in aws help (service='s3api', operation='list-buckets'). Pass params as a JSON object using the AWS API's PascalCase keys (e.g. {Bucket: 'foo'}); they go through --cli-input-json. Session profile/region (from aws_session_set) are used by default; override per-call when needed. Hand-written CLI commands (aws s3 cp/ls/sync, aws logs tail) and operations that stream their response to an output file (s3api get-object, bedrock-runtime invoke-model, bedrock-agentcore invoke-agent-runtime, lambda invoke) do not accept --cli-input-json and cannot run here -- use aws_lambda_invoke or aws_logs_tail where they exist, bedrock-runtime converse for text inference, otherwise your shell. Waiters work: operation 'wait instance-running'. Blob-typed members of params (KMS Plaintext, Kinesis Data, DynamoDB B) take base64 -- the server runs the CLI with --cli-binary-format base64 whatever your AWS config says. Returns parsed JSON output by default, plus the literal command that was run.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| query | No | JMESPath expression to extract a subset of the response (passed as --query). E.g. 'Buckets[].Name', 'Reservations[].Instances[].{Id:InstanceId,State:State.Name}'. Dramatically reduces output size; reach for this whenever you only need a few fields. | |
| params | No | Operation parameters as a JSON object (AWS API schema, PascalCase keys). E.g. {Bucket: 'foo', Key: 'bar'}. | |
| region | No | Override session region for this call. | |
| profile | No | Override session profile for this call. | |
| service | Yes | AWS service name in kebab-case: 's3api', 'ec2', 'iam', 'lambda', 'dynamodb', 'logs', 'sts', 'cloudformation', etc. | |
| operation | Yes | Operation name in kebab-case: 'list-buckets', 'describe-instances', 'get-caller-identity', 'put-object'. | |
| timeoutMs | No | Timeout in milliseconds. Default 60000 (60s). Raise for slow ops; lower to fail fast. | |
| outputFormat | No | Output format. Default 'json' (parsed into structured data when possible). |