Resources · Claude connector

Claude AWS API connectorWhat Claude can do in your AWS API account.

The Claude AWS API connector exposes 2 tools: 1 for reading, 1 that writes. 0 are undocumented. One suggests AWS CLI commands, the other runs them against your account with your local credentials. Below: the guardrails worth setting, and why AWS now points to a newer server.

Verified Trustpilot reviews · AI, automation & growth agency

Overview

What changes when Claude can run the AWS CLI for you

Instead of hunting through CLI reference pages for the right flags, you describe the task in plain words. This desktop extension lets Claude find the matching AWS CLI command and, if you let it, run that command on your account with the credentials already configured on your machine.

Get the right command first time. Ask how to list the buckets with public access and suggest_aws_commands returns the 5 most likely CLI commands with their full parameters, including commands released after Claude's training data stops.

Inspect your account in plain language. With call_aws, Claude executes the command and reads back the output, so you can ask which instances are running in a region without typing a line.

Change resources when your role allows it. The same tool can create, update and manage resources across AWS services. Whether it may do so depends on the IAM role behind your credentials, not on Claude.

What it will not do matters as much. A command on AWS's denylist never runs, and the server confirms changes only if you switch that option on. Nothing runs by itself either: no tool reacts to an alarm or a new resource. AWS itself now recommends its managed AWS MCP Server instead. Event-driven work belongs to automation platforms, covered from the Integrations hub.

Vocabulary

Five terms worth knowing

The vocabulary around this extension, in one minute.

Connector
A link you set up once between Claude and an account you already have, so Claude can act on it while it answers you.
Tool
One named action the connector gives Claude. Claude picks the tools it needs by itself, and the directory lists them by name.
Authorization
The access you hand over once so Claude can work on a service. Here it rests on the AWS credentials configured on your machine.
Approval
The confirmation Claude waits for before an action that changes your account, displayed in the conversation when it applies.
MCP
The common standard connectors rely on: it is what lets an assistant like Claude send commands to an outside service such as AWS.
Connect

Set up AWS API MCP Server in three steps

  1. 01

    Find the extension in Claude

    In Claude Desktop, open the settings, go to Customize, then Connectors, and look up AWS API MCP Server. It is a desktop extension, installed on Claude Desktop. On Team or Enterprise, an Owner or Primary Owner enables it first.

  2. 02

    Start the connection

    Click Connect on its row. Access then comes from the AWS profile on your computer rather than from a web sign-in. If the extension stops responding, Disconnect it and connect it again.

  3. 03

    Decide what the access covers

    The service, not Claude, sets the reach of the access. Here that means the IAM role tied to your credentials: ReadOnlyAccess keeps Claude to non-mutating commands, AdministratorAccess opens creation and deletion.

Tools

The 2 tools: one suggests, one executes

AWS API MCP Server gives Claude 2 tools: 1 that read your account, 1 that change something in it.

A clean split: one tool proposes commands, the other runs them. Names stay exactly as Claude shows them.

  • 1 read
  • 1 write

What Claude reads (1)

1 tool

One tool that proposes commands and runs nothing.

suggest_aws_commands

Turns a plain-language request into the 5 most likely AWS CLI commands, each with a description and its full set of parameters. It proposes and stops there: nothing runs against your account.

When it helps
you know what you want from a service launched recently and Claude does not know its commands yet.

Sourcegithub.com · October 1, 2026 ↗

What Claude can change (1)

1 tool

One tool that executes commands on your account, reads and writes alike. No source describes a default confirmation for it, so the rule further down applies.

call_aws

Approval: see the rule

Executes an AWS CLI command against your account and returns the result, with validation and error handling along the way. Depending on the command, it lists resources or creates, updates and deletes them.

What Claude asks for
no default confirmation is documented; the server asks only when its consent option is switched on.
When it helps
tagging a batch of instances you would otherwise update one by one.
Watch out
your IAM role, not Claude, decides what goes through.

Sourcegithub.com · October 1, 2026 ↗

Approvals

What gets checked before a command runs

By default, Claude stops and asks before each action it takes on an account for someone, right in the conversation.

On Team and Enterprise, owners decide whether members may let some actions through without a prompt each time, and they can cap what a connector may do for the whole organization. Claude works with the rights of the person connected and nothing beyond. For this extension, AWS adds its own layers: the IAM role behind your credentials is the primary control, a read-only mode and a consent mode can be switched on, and a security policy file can block or gate specific commands.

Plans

Which plans include it

None of the 819 sheets in the official directory states plan availability. That answer is published nowhere, connector by connector.

The general rule is public: remote connectors are open to all users on Claude, Cowork, Claude Desktop and mobile, while desktop extensions like this one install on Claude Desktop. On Team and Enterprise, an Owner or Primary Owner enables a connector before members use it. For the current state, check this extension's sheet in the official directory.

Limits

Where this extension stops

A connector is not an automation. Claude calls these tools while it answers you, so nothing fires on an alarm or a new deployment.

The partner badge in the directory is not a security audit, and Anthropic states on every sheet that it neither chooses a publisher's tools nor guarantees their behavior. Only AWS documents this extension; no Claude help page covers it. AWS's own setup guide recommends moving to the managed AWS MCP Server, which is a managed remote server and adds controls through IAM condition keys. The same directory rules apply on the Claude agility-cms connector page.

Need help

Need help connecting AWS API MCP Server to Claude?

A person reads every message.

FAQ

Questions about the Claude AWS API connector

01What can Claude do with the Claude AWS API connector?
Claude can work with your AWS account through the AWS CLI. One tool suggests the 5 most likely CLI commands for a request, with full parameters, including commands newer than Claude's training data. The other executes CLI commands and returns their output, which covers both reading resources and changing them. Everything runs locally in Claude Desktop on the AWS credentials configured on your machine, within whatever your IAM role allows.
02Can Claude create or delete AWS resources with it?
Yes, if your credentials allow it. The command tool can create, update and manage resources across AWS services, so an IAM role with AdministratorAccess permits creating, modifying and deleting. A role with ReadOnlyAccess keeps it to non-mutating commands. AWS also offers a read-only mode that restricts execution to read-only operations once you switch it on, and a policy file that blocks the exact commands you name, one by one, so they never run.
03Does Claude ask before running a command on AWS?
Not by a documented default. Claude's general rule is to ask before an action it takes on an account for someone, but no source describes a specific confirmation for this extension's tools. On the AWS side, the server can ask explicit consent before any operation that is not read-only, but that option ships switched off and needs a client that supports it. A policy file can also require consent for specific commands you list.
04Which plans is the AWS API extension available on?
No official source publishes availability plan by plan for a given connector, and the directory sheets do not show it. The published rule is that remote connectors are open to all users on Claude, Cowork, Claude Desktop and mobile, while desktop extensions install on Claude Desktop. On Team and Enterprise, an Owner or Primary Owner enables a connector first. This extension's sheet in the official directory is the place to check its current state.
05Does Claude get access to my whole AWS account?
Claude gets exactly what the configured credentials get. If your profile uses an administrator role, the extension can touch every service that role reaches; with a read-only role, it can only look. AWS built the server for a single user's credentials, run locally. Note that the server also runs with your local user's permissions and has complete access to your file system, which is broader than the AWS account itself.
06Should I still use this extension or the newer AWS MCP Server?
AWS itself points to the newer one, by name. Its documentation marks this server as superseded by the official AWS MCP Server, publishes a migration guide, and recommends switching to reduce setup and maintenance. AWS describes the managed server as remote, with less setup and maintenance effort, and with added controls through IAM condition keys. Meanwhile, this older package remains provided as is, without warranty, for development, testing and evaluation.
07Claude or an automation tool for AWS operations?
They solve different problems, so pick by job. Claude with this extension suits exploratory and one-off work: you ask, it finds the command, runs it and explains the output. Nothing continues after the conversation, and no tool reacts to an alarm, a schedule or a new resource. For tasks that must run on their own when something happens in your account, an automation platform fits that job better than a conversation does.