aws_ssm_get_parameter
Retrieve AWS Systems Manager parameter values from the AWS MCP Server, including decrypted SecureString parameters with proper authorization for sensitive data access.
Instructions
Get the value of an SSM parameter. SecureString values are decrypted.
Input Schema
TableJSON Schema
| Name | Required | Description | Default |
|---|---|---|---|
| profile | No | AWS profile name from ~/.aws/config (e.g., 'default', 'production') | |
| region | No | AWS region override (e.g., 'us-east-1', 'sa-east-1') | |
| sensitive_access_token | No | Out-of-band approval token configured in AWS_MCP_SENSITIVE_ACCESS_TOKEN. Required for operations that can return decrypted or secret values. | |
| sensitive_access_reason | No | Short human reason for retrieving sensitive data. Required for auditability. | |
| sensitive_access_acknowledged | No | Must be true to confirm that the response may contain secret or decrypted data. | |
| name | Yes | Parameter name or ARN | |
| with_decryption | No | Decrypt SecureString values (default: false) |