In-depth architectural comparison of the MCP Server Aws Sso and AWS MCP Server MCP servers. Compare execution transports, security boundaries, tool capabilities, quality scores, and ready-to-paste client installation snippets for Claude, Cursor, Windsurf, and VS Code.
At a Glance & Executive Verdict
MCP Server Aws Sso
Cloud Platforms · Local stdio
Quality: 63/100 (Good) | Auth: OAuth 2.0
AWS MCP Server
Cloud Platforms · Local stdio
Quality: 53/100 (Good) | Auth: No auth required
Verdict Summary: Choose MCP Server Aws Sso if you need specialized Cloud Platforms tools running via a local process. Choose AWS MCP Server if your workspace requires Cloud Platforms integration with local subprocess execution. Both servers can be configured concurrently in your client's mcpServers manifest.
Which MCP Server Should You Choose?
Choose MCP Server Aws Sso when:
You need dedicated capabilities in the Cloud Platforms domain.
You prefer local stdio subprocess transport architecture.
Your security boundary fits: OAuth 2.0 (Free / Open Source).
You have access to required keys: AWS_SSO_START_URL, AWS_SSO_REGION, AWS_REGION.
AWS Single Sign-On (SSO) integration enabling AI systems to securely interact with AWS resources by initiating SSO login, listing accounts/roles, and executing AWS CLI commands using temporary credentials.
AWS MCP server — call any AWS API from AI assistants, with first-class SSO re-login
Initiate AWS SSO device authorization flow to obtain temporary credentials.
This flow works as follows:
1. Generates a unique user verification code and authentication URL
2. Opens a browser to AWS SSO login page (if `launchBrowser: true`)
3. You enter the verification code and complete AWS SSO login
4. Background polling automatically collects and caches the token
5. The cached token is used by other AWS SSO tools
**IMPORTANT FOR AI ASSISTANTS**: When the tool returns authentication instructions:
- ALWAYS check if a browser window opened automatically
- If browser opened: Guide the user to complete authentication
- If no browser opened: Instruct user to manually open the URL and enter code
- Always provide both the verification code and URL as backup
Prerequisites:
- AWS SSO must be configured with a start URL and region
- Browser access is required for authentication
- You must have an AWS SSO account with appropriate permissions
Returns: Authentication status, session details, verification code and URL
aws_sso_status
Check current AWS SSO authentication status.
Verifies if a valid cached token exists and its expiration time. Does NOT perform authentication - only checks status. If no valid token exists, instructs you to run `aws_sso_login`.
Use before calling `aws_sso_ls_accounts` or `aws_sso_exec_command`.
Returns: Authentication status, session details, expiration time, next steps
aws_sso_ls_accounts
List all AWS accounts and roles accessible through AWS SSO.
Provides essential information needed for `aws_sso_exec_command`:
- Fetches all accessible accounts with IDs, names, and emails
- Retrieves all available roles for each account
- Handles pagination internally
- Caches account and role information
Prerequisites:
- MUST first authenticate using `aws_sso_login`
- AWS SSO must be configured with a start URL and region
Returns: Account list with IDs, names, roles, and session status
Ready-to-Paste Client Configurations
Paste either (or both) of these JSON server blocks into your client config file (e.g. claude_desktop_config.json or ~/.cursor/mcp.json).
MCP Server Aws Sso is categorized under Cloud Platforms and uses a local stdio subprocess. In contrast, AWS MCP Server belongs to Cloud Platforms using local stdio subprocess. Select MCP Server Aws Sso when you need capabilities focused on cloud platforms and AWS MCP Server when you require tools for cloud platforms.
Execute AWS CLI command using temporary credentials from AWS SSO.
Workflow:
1. Verifies valid AWS SSO authentication token
2. Obtains temporary credentials for account and role
3. Executes the AWS CLI command
4. Caches credentials for future use (1 hour)
Prerequisites:
- MUST first authenticate using `aws_sso_login`
- AWS CLI MUST be installed on the system
- AWS SSO must be configured
Required: `accountId`, `roleName`, `command`
Optional: `region`
Returns: Execution context, command output, errors, exit code
aws_sso_ec2_exec_command
Execute shell command on EC2 instance via SSM using AWS SSO credentials.
No SSH access or inbound ports required. Uses SSM's RunShellScript document.
Prerequisites:
- MUST first authenticate using `aws_sso_login`
- EC2 instance MUST have SSM Agent installed
- Instance needs IAM role with AmazonSSMManagedInstanceCore policy
- Your role needs `ssm:SendCommand` and `ssm:GetCommandInvocation` permissions
Required: `instanceId`, `accountId`, `roleName`, `command`
Optional: `region`
Returns: Execution context, command output, errors, troubleshooting guidance
AWS MCP Server Tools (28)
aws_whoami
Current identity (account, ARN) + SSO token expiry countdown. Call this first.
aws_login_start
Start `aws sso login --no-browser --use-device-code`, returns a verification URL + short code and a `sessionId`. (`--use-device-code` is omitted on AWS CLI older than 2.22.0, where the device grant is already the default.)
aws_login_complete
Block until the SSO subprocess finishes (you auth in your browser), returns the new identity.
aws_refresh_if_expiring_soon
Check the cached SSO token and auto-start a refresh when < `thresholdMinutes` remain (default 10). One round-trip for "am I about to expire? if so, re-login."
aws_session_set
Set the default profile and/or region for the rest of this MCP session. "Switch to prod," "use us-west-2."
aws_session_get
Show the current session defaults and where each value came from (`session`/`env`/`default`).
aws_session_clear
Remove session profile/region overrides so env vars / defaults take over again. No args clears both.
aws_list_profiles
List profiles configured in `~/.aws/config` -- names, regions, and SSO metadata. Use before switching profiles or when an SSO error names one you haven't seen.
aws_assume_role
Call STS AssumeRole with your current identity and stash the temp creds as a new profile (`mcp-<sessionName>`) in `~/.aws/credentials`. Use for cross-account access. The secret/session token stay on disk -- not returned to the model. Optional `timeoutMs` (default 120s) for slow SAML / `credential_p…
aws_call
Run any AWS API operation. `service: 's3api', operation: 'list-buckets'`, optional `params` (PascalCase JSON), optional `query` (JMESPath). Returns parsed JSON. Hand-written CLI commands (`s3 cp/ls/sync`, `logs tail`) and operations that stream their response to a file (`s3api get-object`, `bedrock…
aws_paginate
Fetch one page of a paginated list/describe operation. Supports `query` too. Returns `nextToken`/`hasMore`; call again with the token to continue.
aws_logs_tail
Fetch the newest CloudWatch Logs events for one log group (FilterLogEvents via `aws logs filter-log-events`), with `since`, `filterPattern` and stream-name filters; returns `{timestamp, logStreamName, message}` objects, oldest first. Bounded by `maxEvents` (default 500, max 10000): a busier window…