Resources · Claude connector

Claude AWS connectorWhat Claude can do in your AWS account.

The Claude AWS connector exposes 9 tools: 6 for reading, 0 documented as writing, 3 undetermined. It is AWS's managed server, reached over the web. Below: what Claude looks up, what runs under your IAM identity, and what AWS leaves unsaid.

Verified Trustpilot reviews · AI, automation & growth agency

Overview

What changes when Claude works through AWS's managed server

Through this connector, Claude searches current AWS documentation and curated skills before answering, checks which regions offer a service, and, once you sign in with your IAM identity, can run scripts against your account in a sandboxed environment. Documentation and service information need no sign-in at all.

Answer from today's documentation. aws___search_documentation searches API references, best practices, service guides and skills, then aws___read_documentation pulls the page so Claude quotes it instead of guessing.

Follow AWS's own playbooks. aws___retrieve_skill returns a skill in full: the workflow, the decision points and the step-by-step procedure AWS recommends for a domain.

Plan a deployment by region. aws___list_regions and aws___get_regional_availability tell Claude where a service, feature, SDK API or CloudFormation resource is offered before you build on it.

The gaps deserve the same attention. AWS documents what aws___run_script and aws___get_presigned_url are for, but not whether they read or modify, and aws___call_aws appears in no AWS page at all. The read-only mode that hides write-capable tools is not offered through the web sign-in. And nothing runs on its own: no tool reacts to an alarm or a deployment. Event-driven work belongs to automation platforms, covered from the Integrations hub.

Vocabulary

Five words in one minute

The vocabulary around this connector.

Connector
The link you set up once between Claude and an account you already have, so Claude can work in it while answering you.
Tool
One named action the connector opens to Claude. Claude chooses on its own which tools to call, and the directory lists each by name.
Authorization
The service's own sign-in screen, here AWS Sign-in, where you grant the access Claude will use. Given per person and revocable.
Approval
The confirmation Claude waits for before an action that changes an account, shown in the conversation at the moment it matters.
MCP
The shared standard connectors are built on: it is what lets an assistant like Claude reach an outside service such as AWS.
Connect

Connect AWS to Claude in three steps

  1. 01

    Find AWS MCP in Claude

    Open Claude's settings, go to Customize, then Connectors, and look up AWS MCP. On a Team or Enterprise workspace, an Owner or Primary Owner enables the connector before members can each authenticate.

  2. 02

    Sign in on AWS's side

    Click Connect. AWS documents that a browser window to AWS Sign-in opens the first time a tool needs your account; log in with your existing credentials. If the link breaks, Disconnect and connect again.

  3. 03

    Authorize with care

    Read the consent screen before accepting. It belongs to AWS, not Claude, and your IAM permissions decide what the access reaches. AWS says tokens last 1 hour and refresh for up to 12 hours.

Tools

The 9 tools, sorted by what AWS documents

AWS MCP gives Claude 9 tools: 6 that read your account, 0 that change something in it, and 3 no official source describes.

Six read, three remain undetermined. Tool names stay exactly as Claude shows them, prefix included.

  • 6 read
  • 3 not documented

What Claude reads (6)

6 tools

Six tools that look up documentation, regions or task status and change nothing.

aws___get_regional_availability

Checks whether a service, a feature, an SDK API or a CloudFormation resource is offered in a given AWS region. Claude gets a yes or no it can plan around.

When it helps
before committing to a region for a new workload with data residency constraints.

Sourcedocs.aws.amazon.com · October 1, 2026 ↗

aws___get_tasks

Polls the progress of long-running jobs started by the script tool. When a previous call hands back a task ID still marked as working, Claude uses this to know when the result is ready.

When it helps
a cross-account inventory takes a while and you want the answer without rerunning it.

Sourcedocs.aws.amazon.com · October 1, 2026 ↗

aws___list_regions

Returns every AWS region with its identifier and its name, the reference Claude needs to quote region codes correctly in its answers.

When it helps
you remember a city, not the code, and need the exact region identifier for a template.

Sourcedocs.aws.amazon.com · October 1, 2026 ↗

aws___read_documentation

Fetches an AWS documentation page and converts it to markdown so Claude can read it in full and quote it precisely, rather than paraphrasing from memory.

When it helps
a search turned up the right service guide and you want the exact limits it states.

Sourcedocs.aws.amazon.com · October 1, 2026 ↗

aws___retrieve_skill

Brings back an AWS skill by name: workflows, context, best practices, decision frameworks and step-by-step procedures, reference material included. Use the documentation search first to find which skills exist.

When it helps
you want AWS's recommended procedure for a domain, not a generic answer.

Sourcedocs.aws.amazon.com · October 1, 2026 ↗

aws___search_documentation

Searches across all AWS documentation, from API references and service guides to best practices and skills. A topic filter narrows results to skills only.

When it helps
a newly released feature is missing from what Claude knows and you need the current page.

Sourcedocs.aws.amazon.com · October 1, 2026 ↗

Undetermined (3)

3 tools

No official source says whether these three read or modify your account. Two have a purpose described by AWS, one has nothing at all. The approval rule below applies to each.

aws___call_aws

The directory lists this name and nothing else. AWS's page describing the server's tools leaves it out, so there is no source to say what it covers or returns.

Watch out
whatever it does, the general approval rule below applies to it.

aws___get_presigned_url

AWS says it generates pre-signed Amazon S3 URLs for uploading or downloading files, or for a CLI command that expects a local file path. No source says whether using it leaves your account unchanged.

Watch out
treat it under the approval rule below.

aws___run_script

According to AWS, it runs Python code in a sandbox with AWS API access, for listing resources, parallel or multi-step calls and cross-service checks. Whether those calls stay read-only is not documented.

Watch out
your IAM permissions, not this page, set what it may reach.
Approvals

What Claude asks, and what AWS controls

By default, Claude stops and asks for confirmation before each action it takes on an account for someone, inside the conversation.

On Team and Enterprise, workspace owners decide whether members may let some actions pass without a prompt each time, and they can cap what a connector may do for the whole organization, reads on and writes off for instance. Claude works with the rights of the person connected and nothing more. AWS adds its own controls: API calls run under your existing IAM credentials, IAM-based access controls apply to every capability, and CloudTrail logs all API calls for audit.

Plans

Which plans include it

None of the 819 sheets in the official directory states plan availability. Nobody publishes that answer connector by connector.

The general rule is public: remote connectors such as this one are open to all users on Claude, Cowork, Claude Desktop and mobile. On Team and Enterprise, an Owner or Primary Owner enables a connector for the organization before members can authenticate. For the live state, open the AWS MCP sheet in the official directory.

Limits

Where this connector stops

A connector is not an automation. Claude calls these tools while it answers you, so nothing starts when an alarm fires or a stack finishes deploying.

The partner badge is not a security audit, and Anthropic states on every sheet that it neither chooses a publisher's tools nor guarantees their behavior. Only AWS documents this connector; no Claude help page covers it. AWS presents it as the successor of its older AWS API MCP Server, a separate desktop extension. If you still run that extension, AWS recommends switching. Similar directory rules apply on the Claude adobe-workfront connector page.

Need help

Need help connecting AWS MCP to Claude?

A person reads every message.

FAQ

Questions about the Claude AWS connector

01What can Claude do with the Claude AWS connector?
Claude can search and read current AWS documentation, retrieve AWS skills with their step-by-step procedures, list regions and check where a service or feature is available, and follow the status of long-running tasks. AWS also describes a sandboxed script tool with AWS API access and a tool that creates pre-signed S3 links. In total the connector lists nine tools, six documented as reading and three whose effect on your account no source spells out.
02Can Claude change resources in my AWS account with it?
No source answers that clearly. None of the nine tools is documented as writing. AWS describes the script tool as running Python with AWS API access, for tasks such as listing resources and checking their properties, without saying whether calls stay read-only, and the decision guide mentions write-capable tools that a read-only mode can hide. In practice, AWS names IAM-based access controls as what governs every capability, and CloudTrail logs every call.
03Does Claude ask before it acts on AWS?
No source describes a confirmation for any AWS MCP tool. Claude's general rule applies: by default it asks before an action it takes on an account for someone. On the AWS side, the controls are identity based. API calls, scripts and skills run under your existing IAM credentials, IAM-based access controls apply, and CloudTrail logs every API call. On Team and Enterprise, owners can also restrict what the connector may do for everyone.
04Which plans is the AWS connector available on?
No official source publishes availability plan by plan for a single connector, and the directory sheets do not show it. The public rule is that remote connectors like this one are open to all users on Claude, Cowork, Claude Desktop and mobile, with an Owner or Primary Owner enabling them first on Team and Enterprise. The AWS MCP sheet in the official directory is the only place showing the current state for your account.
05Does Claude see my entire AWS account?
It sees what your IAM identity can reach. Documentation search and service information work without authentication, but API calls, sandboxed scripts and skills run with the credentials you signed in with. A tightly scoped IAM role keeps Claude just as tightly scoped in what it can reach. AWS also offers a mode that hides write-capable tools from the assistant entirely, but only with SigV4 signing through a local proxy, not with the web sign-in.
06Why does sign-in end on a 400 error page?
AWS documents this exact case: your IAM role or user is missing the OAuth permissions the sign-in flow needs. The fix it gives is to attach the AWSMCPSignInOAuthAccessPolicy managed policy to that role or user, then try again. Once signed in, AWS says access tokens stay valid for 1 hour and are refreshed by AWS Sign-in for up to 12 hours. The fix sits on the IAM side, in your AWS account, not in Claude's settings.
07Claude or an automation tool for AWS work?
They answer different needs, so the choice depends on the job. Claude with this connector suits research and hands-on questions: read the documentation, check a region, follow an AWS skill, run an investigation script under your IAM identity. Nothing continues once the conversation ends, and no tool reacts to an alarm or a schedule. For work that must run on its own when something happens in your account, an automation platform fits better.