Setting up the AWS MCP Server
Connect the AWS MCP Server via OAuth or SigV4 – requirements, IAM permissions, and choosing the right authentication path.
- Skill Road
- Setting up the AWS MCP Server
Published on 09.09.2026
The AWS MCP Server runs as an AWS-managed remote service — unlike many MCP servers, there is nothing to launch locally via npx or Docker. Setup is mainly about choosing the right authentication path.
Choosing OAuth or SigV4
OAuth suits you if you want no local installation, your client only supports remote MCP servers, or you use a single AWS account. SigV4 is the right choice for terminal/IDE coding agents, for switching between multiple AWS accounts in one session, for enforcing read-only mode, or if your organization restricts browser-based OAuth sign-in.
Setting up the AWS MCP Server via OAuth
First attach the managed policy to your IAM role:
aws iam attach-role-policy \
--role-name MyRole \
--policy-arn arn:aws:iam::aws:policy/AWSMCPSignInOAuthAccessPolicy
Then configure the endpoint URL in your client, for example in Claude Code:
claude mcp add aws-mcp https://aws-mcp.us-east-1.api.aws/mcp --transport http
If your client only supports OAuth with an explicit trigger (such as Claude Desktop or Cursor), append ?oauth=initialize to the URL. On the first tool call, a browser window opens for AWS sign-in.
Setting up the AWS MCP Server via SigV4
First install the AWS CLI (2.32.0 or later) and sign in:
aws login
aws sts get-caller-identity
Then install uv and configure the MCP Proxy for AWS in your client configuration:
{
"mcpServers": {
"aws-mcp": {
"command": "uvx",
"args": [
"mcp-proxy-for-aws-cli@latest",
"https://aws-mcp.us-east-1.api.aws/mcp",
"--metadata", "AWS_REGION=us-west-2"
]
}
}
}
Replacing older AWS MCP servers
If you already have aws-api-mcp-server or aws-knowledge-mcp-server configured, remove those entries from your client configuration to avoid tool conflicts — the AWS MCP Server covers both areas of functionality.
Scoping permissions and verifying setup
Before setup, prepare an IAM role as narrow as possible, allowing only the services actually needed. After starting, test with a harmless question like "What AWS Regions are available?" to confirm tools loaded, and check CloudTrail to see which actions the agent actually performs.
Source: docs.aws.amazon.com/agent-toolkit, checked on 2026-09-05.
Frequently asked questions
Does the AWS MCP Server run locally or in the cloud?
The server runs as an AWS-managed remote endpoint in one of the supported regions. With SigV4, only a lightweight signing proxy runs locally, not the server itself.
Which AWS Regions are supported?
Currently US East (N. Virginia, us-east-1) and Europe (Frankfurt, eu-central-1). The endpoint region determines which server the client connects to.
Can I switch between multiple AWS accounts in one session?
Only with SigV4 authentication using multiple configured profiles. Per the documentation, OAuth does not support switching accounts within the same session.
What does the AWS MCP Server cost?
Per AWS, the server itself carries no additional charge. Only the AWS resources and API calls the agent actually uses through the server are billed.
How can I stop an agent from accidentally changing resources?
With SigV4 authentication you can enable read-only mode, which hides write-capable tools from the agent entirely. The IAM role used should also be scoped to only the minimal permissions needed from the start.