AWS Knowledge Base MCP server
Last verified: 2026-09
Query an Amazon Bedrock knowledge base.
Official reference Cloud & infra Needs a secret Claude Desktop, Cursor, Windsurf, Claude Code, VS Code
What it does
Queries an Amazon Bedrock knowledge base and returns chunks. Read-only on the KB you configure. You still need AWS credentials that can call Bedrock.
It sits in Cloud & infra: Most of these are admin APIs.
Good for
- Query an Amazon Bedrock knowledge base you already populated.
- Retrieve internal docs the KB was built from — not create VPCs.
- Keep the IAM role to that KB only.
- Skip it if the docs are already in Notion or Drive.
Tools
- retrieve_from_aws_kb — Semantic retrieve over the knowledge base.
Config (Claude Desktop / Cursor / Windsurf)
Paste the JSON below. Same mcpServers shape. Replace placeholder paths and secrets.
Windows paths look like C:\\Users\\you\\project, not /path/to.
Host-side steps →
Claude Desktop
| OS | Config file |
|---|---|
| macOS | ~/Library/Application Support/Claude/claude_desktop_config.json |
| Windows | %APPDATA%\Claude\claude_desktop_config.json
(usually C:\Users\<you>\AppData\Roaming\Claude\) |
| Linux | ~/.config/Claude/claude_desktop_config.json |
Cursor
| Scope | macOS / Linux | Windows |
|---|---|---|
| This project | .cursor/mcp.json in the repo root | |
| This user | ~/.cursor/mcp.json |
%USERPROFILE%\.cursor\mcp.json |
Windsurf
| OS | Config file |
|---|---|
| macOS / Linux | ~/.codeium/windsurf/mcp_config.json |
| Windows | %USERPROFILE%\.codeium\windsurf\mcp_config.json |
{
"mcpServers": {
"aws_kb": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-aws-kb-retrieval"
],
"env": {
"AWS_PROFILE": "mcp-readonly",
"AWS_REGION": "us-east-1"
}
}
}
}
Windsurf remote MCP: use serverUrl instead of url if the block below is HTTP.
One-liner: npx -y @modelcontextprotocol/server-aws-kb-retrieval
Secrets it wants: AWS credentials, knowledge base id
How to get started
- Create a Bedrock knowledge base and note its id.
- Use an IAM role that can only Retrieve on that KB.
- Set the standard AWS env (or a profile) plus the KB id your install expects.
Access risk
Over-broad IAM can list other KBs or invoke models you pay for. Retrieval can surface internal docs.
When to skip it
Skip it if the docs are public (Context7, Fetch) or already in a repo (Filesystem).
Instead: Context7, Fetch, Filesystem.
Vs alternatives
| Server | Official? | Needs a secret? | Best for |
|---|---|---|---|
| AWS Knowledge Base | Yes | Yes | Query an Amazon Bedrock knowledge base. |
| Context7 | No | Yes | Up-to-date library docs pulled into the prompt. |
| Fetch | Yes | Yes | Fetch a URL and turn the page into readable text. |
| Filesystem | Yes | No | Read and write files inside a folder you choose. |
More in Cloud & infra
FAQ
Is this AWS admin?
No. Retrieval. Different risk: it surfaces whatever was indexed, including things you forgot you ingested.
Official?
Anthropic reference server for AWS KB retrieve.
What gets exposed?
Chunks from the knowledge base. Treat the KB as public-to-the-model.
AWS-KB or Filesystem?
Filesystem if the files are local. KB if they were already ingested into Bedrock.