The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the AWS CLI MCP Server listing page.
A Python Model Context Protocol (MCP) server that lets MCP-compatible clients inspect and operate AWS through the AWS CLI. It supports command execution with validation, command suggestions, AWS region lookup, and caller identity checks.
This server can execute AWS CLI commands using the credentials available to the process. It blocks shell operators by using subprocess.run(..., shell=False) and flags destructive-looking commands, but it cannot replace IAM least privilege or human review. Use scoped AWS profiles or roles, prefer non-production accounts for testing, and keep destructive commands on manual approval in your MCP client.
PATHWhen published to PyPI, install or run the server like a standard Python MCP package:
For local development from source:
Before running this server, install the AWS CLI using the official AWS CLI install guide, then configure credentials using the official AWS CLI sign-in guide and AWS CLI configuration guide. AWS recommends short-term credentials where possible; avoid long-term IAM user keys unless your use case requires them.
Copy the example environment file and adjust values as needed.
| Variable | Description | Default |
|---|---|---|
AWS_REGION | Default AWS region | us-east-1 |
AWS_PROFILE | AWS credentials profile | default |
AWS_MCP_WORKING_DIR | Working directory for file operations | /tmp/aws-mcp-work |
AWS_MCP_REQUIRE_CONFIRMATION | Emit warnings for destructive-looking operations | true |
AWS_MCP_LOG_LEVEL | Application log level | INFO |
From a local checkout before PyPI publication, run:
For published installs, prefer uvx. MCP servers using stdio must write protocol messages only to stdout; this server writes logs to stderr and a local file under ~/.aws-mcp-server/logs.
Most MCP clients accept this mcpServers JSON shape:
For local development from this repository, use the installed console script path instead:
VS Code uses the same command/args/env model in its MCP configuration:
| Tool | Purpose | Safety |
|---|---|---|
call_aws | Execute an AWS CLI command | Can modify AWS resources |
suggest_aws_commands | Suggest common AWS CLI commands | Read-only |
get_aws_regions | List AWS regions | Read-only |
get_caller_identity | Return current AWS identity | Read-only |
Manual AWS check, if credentials are configured:
This server is published through the standard Python MCP distribution path:
mdev-aws-mcp-serverio.github.musaddiq-dev/aws-cli-mcp-serveruvxstdioThe mcp-name marker at the top of this README is required for MCP Registry ownership verification. Users should prefer uvx mdev-aws-mcp-server in local MCP client configurations.
.env, AWS credentials, profiles, access keys, or account-specific outputs.call_aws on explicit manual approval in your MCP client.MIT