- Home
- Resources
- Integrations
- AWS MCP
Claude AWS connectorWhat Claude can do in your AWS account.
The Claude AWS connector exposes 9 tools: 6 for reading, 0 documented as writing, 3 undetermined. It is AWS's managed server, reached over the web. Below: what Claude looks up, what runs under your IAM identity, and what AWS leaves unsaid.
Verified Trustpilot reviews · AI, automation & growth agency
What changes when Claude works through AWS's managed server
Through this connector, Claude searches current AWS documentation and curated skills before answering, checks which regions offer a service, and, once you sign in with your IAM identity, can run scripts against your account in a sandboxed environment. Documentation and service information need no sign-in at all.
Answer from today's documentation. aws___search_documentation searches API references, best practices, service guides and skills, then aws___read_documentation pulls the page so Claude quotes it instead of guessing.
Follow AWS's own playbooks. aws___retrieve_skill returns a skill in full: the workflow, the decision points and the step-by-step procedure AWS recommends for a domain.
Plan a deployment by region. aws___list_regions and aws___get_regional_availability tell Claude where a service, feature, SDK API or CloudFormation resource is offered before you build on it.
The gaps deserve the same attention. AWS documents what aws___run_script and aws___get_presigned_url are for, but not whether they read or modify, and aws___call_aws appears in no AWS page at all. The read-only mode that hides write-capable tools is not offered through the web sign-in. And nothing runs on its own: no tool reacts to an alarm or a deployment. Event-driven work belongs to automation platforms, covered from the Integrations hub.
Five words in one minute
The vocabulary around this connector.
- Connector
- The link you set up once between Claude and an account you already have, so Claude can work in it while answering you.
- Tool
- One named action the connector opens to Claude. Claude chooses on its own which tools to call, and the directory lists each by name.
- Authorization
- The service's own sign-in screen, here AWS Sign-in, where you grant the access Claude will use. Given per person and revocable.
- Approval
- The confirmation Claude waits for before an action that changes an account, shown in the conversation at the moment it matters.
- MCP
- The shared standard connectors are built on: it is what lets an assistant like Claude reach an outside service such as AWS.
Connect AWS to Claude in three steps
- 01
Find AWS MCP in Claude
Open Claude's settings, go to Customize, then Connectors, and look up AWS MCP. On a Team or Enterprise workspace, an Owner or Primary Owner enables the connector before members can each authenticate.
- 02
Sign in on AWS's side
Click Connect. AWS documents that a browser window to AWS Sign-in opens the first time a tool needs your account; log in with your existing credentials. If the link breaks, Disconnect and connect again.
- 03
Authorize with care
Read the consent screen before accepting. It belongs to AWS, not Claude, and your IAM permissions decide what the access reaches. AWS says tokens last 1 hour and refresh for up to 12 hours.
The 9 tools, sorted by what AWS documents
AWS MCP gives Claude 9 tools: 6 that read your account, 0 that change something in it, and 3 no official source describes.
Six read, three remain undetermined. Tool names stay exactly as Claude shows them, prefix included.
- 6 read
- 3 not documented
What Claude reads (6)
6 toolsSix tools that look up documentation, regions or task status and change nothing.
aws___get_regional_availability
Checks whether a service, a feature, an SDK API or a CloudFormation resource is offered in a given AWS region. Claude gets a yes or no it can plan around.
aws___get_tasks
Polls the progress of long-running jobs started by the script tool. When a previous call hands back a task ID still marked as working, Claude uses this to know when the result is ready.
aws___list_regions
Returns every AWS region with its identifier and its name, the reference Claude needs to quote region codes correctly in its answers.
aws___read_documentation
Fetches an AWS documentation page and converts it to markdown so Claude can read it in full and quote it precisely, rather than paraphrasing from memory.
aws___retrieve_skill
Brings back an AWS skill by name: workflows, context, best practices, decision frameworks and step-by-step procedures, reference material included. Use the documentation search first to find which skills exist.
aws___search_documentation
Searches across all AWS documentation, from API references and service guides to best practices and skills. A topic filter narrows results to skills only.
Undetermined (3)
3 toolsNo official source says whether these three read or modify your account. Two have a purpose described by AWS, one has nothing at all. The approval rule below applies to each.
aws___call_aws
The directory lists this name and nothing else. AWS's page describing the server's tools leaves it out, so there is no source to say what it covers or returns.
aws___get_presigned_url
AWS says it generates pre-signed Amazon S3 URLs for uploading or downloading files, or for a CLI command that expects a local file path. No source says whether using it leaves your account unchanged.
aws___run_script
According to AWS, it runs Python code in a sandbox with AWS API access, for listing resources, parallel or multi-step calls and cross-service checks. Whether those calls stay read-only is not documented.
What Claude asks, and what AWS controls
By default, Claude stops and asks for confirmation before each action it takes on an account for someone, inside the conversation.
On Team and Enterprise, workspace owners decide whether members may let some actions pass without a prompt each time, and they can cap what a connector may do for the whole organization, reads on and writes off for instance. Claude works with the rights of the person connected and nothing more. AWS adds its own controls: API calls run under your existing IAM credentials, IAM-based access controls apply to every capability, and CloudTrail logs all API calls for audit.
Which plans include it
None of the 819 sheets in the official directory states plan availability. Nobody publishes that answer connector by connector.
The general rule is public: remote connectors such as this one are open to all users on Claude, Cowork, Claude Desktop and mobile. On Team and Enterprise, an Owner or Primary Owner enables a connector for the organization before members can authenticate. For the live state, open the AWS MCP sheet in the official directory.
Where this connector stops
A connector is not an automation. Claude calls these tools while it answers you, so nothing starts when an alarm fires or a stack finishes deploying.
The partner badge is not a security audit, and Anthropic states on every sheet that it neither chooses a publisher's tools nor guarantees their behavior. Only AWS documents this connector; no Claude help page covers it. AWS presents it as the successor of its older AWS API MCP Server, a separate desktop extension. If you still run that extension, AWS recommends switching. Similar directory rules apply on the Claude adobe-workfront connector page.
Need help connecting AWS MCP to Claude?
A person reads every message.