dotsagent.io
Language:English
Cloud · AWS Labs

Set up AWS API

Runs validated AWS CLI commands so an agent can inspect and change your AWS resources.

Publisher
AWS Labs Official
Run locally
uvx awslabs.aws-api-mcp-server@latest
Transports
stdio
Authentication
Your local AWS credentials from the environment or a profile, with AWS_REGION set.
Environment
AWS_REGIONREAD_OPERATIONS_ONLYREQUIRE_MUTATION_CONSENT
What it can touch
Read and write; READ_OPERATIONS_ONLY=true restricts it to reads.
Licence
Apache-2.0
Source
github.com/awslabs/mcp/tree/main/src/aws-api-mcp-server
Status
Active

Install

This server runs on your machine as a child process of the client. You need the runtime its command uses, such as Node.js for npx, uv for uvx or Docker, plus any variables listed under Environment.

Claude Code

shell
claude mcp add --scope project --env AWS_REGION=us-east-1 --env READ_OPERATIONS_ONLY=true --env REQUIRE_MUTATION_CONSENT=true aws-api -- uvx awslabs.aws-api-mcp-server@latest

Cursor

.cursor/mcp.json
{
  "mcpServers": {
    "aws-api": {
      "command": "uvx",
      "args": [
        "awslabs.aws-api-mcp-server@latest"
      ],
      "env": {
        "AWS_REGION": "us-east-1",
        "READ_OPERATIONS_ONLY": "true",
        "REQUIRE_MUTATION_CONSENT": "true"
      }
    }
  }
}

Codex

~/.codex/config.toml
[mcp_servers.aws-api]
command = "uvx"
args = ["awslabs.aws-api-mcp-server@latest"]

[mcp_servers.aws-api.env]
AWS_REGION = "us-east-1"
READ_OPERATIONS_ONLY = "true"
REQUIRE_MUTATION_CONSENT = "true"

Config for other clients →

The generated config sets READ_OPERATIONS_ONLY and REQUIRE_MUTATION_CONSENT to true; remove them only if the agent should change resources.

Other servers in cloud

Sources

  1. github.com/awslabs/mcp

Independent reference for people who build AI agents. Not affiliated with any vendor named here.

© 2026 DotsAgent · Facts checked October 1, 2026