AWS MCP server
Last verified: 2026-09
Call AWS APIs with the default credential chain.
Community Cloud & infra Needs a secret Claude Desktop, Cursor, Windsurf, Claude Code
What it does
AWS Labs publishes a suite of MCP servers (this listing uses the core entry). Each server covers a slice (docs, CDK, pricing, a service). The monorepo README is an index, not one tool list. Use a named profile with least privilege.
It sits in Cloud & infra: Most of these are admin APIs.
Good for
- Start with awslabs.core-mcp-server or the docs server, not a write service.
- Use AWS_PROFILE=sandbox, never the org-management account.
- Ask a docs/API question before you install a service-specific write server.
- Stop if you only needed SQL on RDS — that is Postgres.
Tools
- core / docs / service-specific tools — Depends on which awslabs.* server you launch. Read the monorepo table and start with one server.
Config (Claude Desktop / Cursor / Windsurf)
Paste the JSON below. Same mcpServers shape. Replace placeholder paths and secrets.
Windows paths look like C:\\Users\\you\\project, not /path/to.
Host-side steps →
Claude Desktop
| OS | Config file |
|---|---|
| macOS | ~/Library/Application Support/Claude/claude_desktop_config.json |
| Windows | %APPDATA%\Claude\claude_desktop_config.json
(usually C:\Users\<you>\AppData\Roaming\Claude\) |
| Linux | ~/.config/Claude/claude_desktop_config.json |
Cursor
| Scope | macOS / Linux | Windows |
|---|---|---|
| This project | .cursor/mcp.json in the repo root | |
| This user | ~/.cursor/mcp.json |
%USERPROFILE%\.cursor\mcp.json |
Windsurf
| OS | Config file |
|---|---|
| macOS / Linux | ~/.codeium/windsurf/mcp_config.json |
| Windows | %USERPROFILE%\.codeium\windsurf\mcp_config.json |
{
"mcpServers": {
"aws": {
"command": "uvx",
"args": [
"awslabs.core-mcp-server"
],
"env": {
"AWS_PROFILE": "sandbox"
}
}
}
}
Windsurf remote MCP: use serverUrl instead of url if the block below is HTTP.
One-liner: uvx awslabs.core-mcp-server
Secrets it wants: AWS_PROFILE or standard AWS env
How to get started
- aws login or set AWS_PROFILE to a sandbox account.
- Start with awslabs.core-mcp-server or the docs server, not a write-capable service server.
- Do not use the org-management account.
Access risk
Standard AWS env + a write tool can create spend and delete resources.
When to skip it
Skip it for a single RDS query (Postgres) or for Kubernetes already running on EKS (use Kubernetes MCP).
Instead: Google Cloud, Azure, Kubernetes.
Vs alternatives
| Server | Official? | Needs a secret? | Best for |
|---|---|---|---|
| AWS | No | Yes | Call AWS APIs with the default credential chain. |
| Google Cloud | No | Yes | Call selected GCP APIs. |
| Azure | No | Yes | Azure Resource Manager via MCP. |
| Kubernetes | No | Yes | kubectl-style cluster access. |
More in Cloud & infra
FAQ
Is this one tool list?
No. awslabs/mcp is a suite. This listing launches the core entry. Read the monorepo table and add one server at a time.
What identity?
The default credential chain / AWS_PROFILE. Write tools plus admin keys create spend and delete resources.
AWS or aws-kb?
aws-kb is Bedrock Knowledge Base retrieval, not account admin.
AWS or Kubernetes on EKS?
If the question is pods, use Kubernetes MCP with a sandbox kubeconfig — not account-root AWS.