Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

The official AWS MCP Server is an AWS-managed endpoint that lets an AI agent work with AWS through the Model Context Protocol (MCP). It combines AWS documentation and service information with authenticated capabilities such as AWS API calls, sandboxed Python execution and curated skills. Documentation search does not require authentication; actions that can execute against your account use the IAM credentials you provide.

This distinction matters because several projects use similar names. The managed AWS MCP Server is not the same thing as AWS Knowledge MCP Server, AWS Documentation MCP Server or the older AWS API MCP Server from AWS Labs. Choose the right service first, then follow the current AWS setup page for your MCP client rather than copying commands from an older repository.

Which AWS MCP server are you trying to use?

“Official AWS MCP Server” refers to the managed service documented in the Agent Toolkit for AWS user guide. AWS presents it as a single endpoint for agent access to AWS capabilities. The endpoint can provide information about AWS services and documentation, and—when your identity is authorized—perform API-oriented work.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Four similarly named projects are easy to confuse:

Server What it is Best understood as
AWS MCP Server AWS-managed endpoint documented by AWS One managed MCP connection combining information access and authenticated agent capabilities
AWS Knowledge MCP Server AWS Labs describes it as a remote, fully managed AWS-hosted resource Documentation and related AWS guidance
AWS Documentation MCP Server A separate locally configured AWS Labs project Documentation retrieval and search tools running in your environment
AWS API MCP Server An older AWS Labs server marked superseded A predecessor that should not be treated as the current official managed service

The AWS Labs repository says the Agent Toolkit for AWS succeeds its collection of MCP servers, plugins and skills, while the repository continues to work and accept contributions. That does not make every repository README a setup guide for the managed endpoint.

How the managed server handles identity

Unauthenticated information access

AWS says agents can search AWS documentation and retrieve service information without authentication. This is useful for explanations, architecture questions and finding relevant service guidance before you grant an agent permission to change anything.

IAM-backed execution

AWS API calls, sandboxed Python execution and curated skills use the customer’s existing IAM credentials. The server does not replace IAM. Your identity, policies and session controls determine what an execution-oriented tool can do.

Give an agent an identity appropriate to the task, review proposed write operations and avoid assuming that a natural-language request is a safe change. The exact permissions depend on the services and operations you intend to use; the overview page does not publish one universal policy that fits every deployment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Audit and monitoring

AWS describes IAM-based access controls, CloudWatch metrics and CloudTrail logging for API calls. In AWS’s wording, “CloudTrail logs all API calls for audit visibility.” Treat these as controls and observability features, not as a guarantee that every prompt, generated script or tool invocation is harmless.

Rank #2
Forvencer Server Book, 2 Zipper Pocket, Server Books for Waitress
  • Upgraded Two Zipper Pockets: Forvencer server books feature two secure zipper pockets for better organization of coins, cash, and receipts, ensuring that everything you collect has a safe and secure place
  • Smart Storage & Quick Access: Designed with 8 multi-functional compartments, the right side includes a guest receipt pad, while the left has a money pocket, ticket pocket, and credit card slot. Two small clear pockets store bills, receipts, and other visible items. A stitched pen loop ensures you always have your favorite pen ready
  • High-quality & Easy to Clean: Crafted from high-quality PU leather with heavy-duty stitching, this server book is built to last. It resists tears, scratches, and its waterproof surface makes cleaning easy with just a damp cloth or a non-chlorine sanitizer
  • Perfect Fit for Your Apron: Measuring 5” x 8”, this compact organizer is slightly smaller than other models, making it ideal for bending or sitting while carrying in your server apron. It holds everything a waitress needs—a place for everything
  • What's Included: This server organizer comes with multiple open and zippered pockets to store money, receipts, tips, etc. Clear sleeves are perfect for keeping menus or special lists while serving. Available in a variety of colors, allowing you to express yourself even when in uniform

Connect an AI client without guessing at stale settings

The current AWS overview includes a “Setting up the AWS MCP Server” section, but the page view available for this article does not expose a complete client-by-client recipe, a definitive region list or a detailed IAM policy. Those values can change. Use the live AWS setup section for your particular MCP client and verify its current requirements before deployment.

  1. Identify your MCP client. Confirm whether you are configuring Claude, Cursor or another MCP-compatible application, because configuration fields and authentication flows are client-specific.
  2. Open the current AWS setup documentation. Use the setup instructions in the Agent Toolkit for AWS user guide rather than an archived AWS Labs README. Copy the endpoint and transport details exactly as AWS currently publishes them.
  3. Choose the IAM identity. Use an IAM role or user whose permissions match the intended work. Start with read-only access when you are learning, then add narrowly scoped permissions for required operations.
  4. Configure the client’s MCP connection. Add the managed server according to the client’s current UI or configuration format. Do not substitute a local uvx command or an old HTTP deployment example unless you intentionally want a different server.
  5. Test with an information request. Ask the agent to find documentation or explain a service. This exercises the lower-risk information path before you attempt an API operation.
  6. Test authorization deliberately. If you need an API call, request a harmless read operation and inspect the proposed tool call, target account and region before approving it.
  7. Review monitoring. Confirm that the relevant CloudWatch metrics and CloudTrail records are visible to your operations team, then establish a process for reviewing unusual calls.

Because the overview reviewed here does not state all regions or supported clients, do not infer availability from the older server’s README. If your client cannot connect, check AWS’s current compatibility and regional notes first.

If you actually need the AWS Documentation MCP Server

The AWS Documentation MCP Server is a different, locally run project. Its README documents a configuration using uvx awslabs.aws-documentation-mcp-server@latest. It requires uv and Python 3.10 or newer. Its documented tools include reading documentation, searching AWS documentation, reading sections, searching table rows and getting recommendations; a service-listing capability is documented for China only.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That local package is appropriate when you specifically want documentation retrieval in your own MCP environment. It is not a substitute for the managed AWS MCP Server’s authenticated API, sandbox and curated-skill capabilities.

What changed with the AWS API MCP Server?

The AWS Labs AWS API MCP Server README labels that project as superseded by the official AWS MCP Server and points readers to a migration guide. An old article that tells you to install or expose that predecessor is therefore not describing the current official path.

Do not copy its local credential handling, HTTP deployment settings or transport assumptions into a managed-service configuration. Its self-hosted HTTP guidance—bind to localhost where possible, restrict network access and use HTTPS/TLS—applies to that older deployment model.

AWS Labs also recorded that Server-Sent Events (SSE) support was removed from its MCP servers in the latest major versions on May 26, 2025. That notice concerns the repository’s servers, not necessarily the managed AWS MCP Server, so it should not be used to infer the managed endpoint’s transport.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Security checklist before enabling write access

  • Use a dedicated IAM identity with only the services and actions required for the task.
  • Begin with read-only requests and verify the account, region, resource and operation shown by the client.
  • Require human approval for destructive, financial or production changes.
  • Keep credentials in the client’s supported secure mechanism; never paste long-lived keys into prompts or source files.
  • Review CloudTrail API-call records and CloudWatch metrics after testing.
  • Separate experimentation from production accounts or roles where practical.
  • Revoke or reduce permissions when a project ends.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting

The client cannot connect

First verify that you followed the managed-server setup for your specific client. A local command from the AWS Documentation MCP Server or AWS API MCP Server will not configure the managed endpoint. Then check the current AWS region and client-compatibility information, which are not fixed by the overview page.

Documentation works but API calls fail

This usually indicates an identity or policy boundary: documentation access can work without authentication, while API calls require your IAM credentials. Inspect which identity the client is using, confirm that it belongs to the intended account and add only the missing, task-specific permission.

A request is denied in the wrong account or region

Stop and verify the active IAM identity, account and region before retrying. Do not broaden permissions simply because a request failed; first determine whether the agent selected the wrong target.

An old tutorial mentions a local HTTP server

Check its publication date and project name. If it describes AWS API MCP Server, treat it as predecessor documentation and use the migration guidance linked by AWS Labs. If you intentionally run that older server, apply its localhost, network restriction and TLS warnings; those instructions do not define the managed service.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The agent proposes an unsafe change

Decline the tool call, inspect the generated parameters and narrow the IAM role or prompt scope. CloudTrail provides an audit trail, but logging does not undo a destructive operation.

Or skip the browser setup

If your project also needs rendered website captures for agent workflows, ScreenshotNeo offers a separate screenshot API and MCP server. One GET request returns PNG, JPEG, WebP or PDF. It accepts cookie and consent banners before capture and removes more than 60 known consent platforms, newsletter popups and chat widgets. Bot checks, blank pages, timeouts, failed loads and cache hits are not billed, and response headers identify the page verdict and billing result.

cURL:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

See the ScreenshotNeo documentation for the complete option set, including full-page and element capture, device presets, dark mode, PDFs, custom CSS and JavaScript, waits, blocking rules, headers, cookies, geolocation, caching, signed links, asynchronous jobs, bulk capture and usage reporting. Its MCP server provides take_screenshot, get_page_info and capture_pdf for Claude, Cursor and other MCP clients.

The free plan includes 1,000 screenshots per month with no card. Paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Bottom line

Use the AWS-managed MCP Server when you want one AWS-supported MCP connection that combines public AWS information access with IAM-authorized agent capabilities. Keep the AWS Knowledge, AWS Documentation and superseded AWS API servers separate in your mental model, and obtain current client, region and permission details from AWS’s live setup documentation rather than an old README.

Frequently Asked Questions

Does the official AWS MCP Server replace IAM?

No. Execution-oriented capabilities use your existing IAM credentials, so permissions and identity selection remain your responsibility.

Can I use the AWS Documentation MCP Server instead?

Yes, if you specifically want its locally run documentation tools. It is a separate project and does not provide the managed server’s full capability set.

Is the AWS API MCP Server still the recommended installation?

No. AWS Labs marks it as superseded by the official AWS MCP Server.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.