---
title: When to Use the AWS MCP Server, and How to Connect It
description: As of 3 October 2026 the managed AWS MCP Server has endpoints in 8 Regions, a hard cap of 10 authenticated requests per second, and two auth paths. OAuth is the single-account start. SigV4 is the one that can hide write tools and switch accounts.
url: https://www.factualminds.com/blog/aws-mcp-server-when-to-use-setup-2026/
datePublished: 2026-10-03T00:00:00.000Z
dateModified: 2026-10-03T00:00:00.000Z
author: palaniappan-p
category: Generative AI
tags: aws, model-context-protocol, agent-toolkit, ai-coding, devtools, iam
---

# When to Use the AWS MCP Server, and How to Connect It

> As of 3 October 2026 the managed AWS MCP Server has endpoints in 8 Regions, a hard cap of 10 authenticated requests per second, and two auth paths. OAuth is the single-account start. SigV4 is the one that can hide write tools and switch accounts.

On **3 October 2026**, the [AWS MCP Server endpoints page](https://docs.aws.amazon.com/general/latest/gr/aws-mcp.html) lists the managed server in **8 Regions**: Northern Virginia, Oregon, Singapore, Sydney, Tokyo, Frankfurt, Ireland, and London. At [general availability on 6 May 2026](/blog/aws-mcp-server-ga-agent-toolkit-serverless-plugin/) the list was two Regions. This post covers the endpoint, the auth path, and the jobs that belong on the agent. The Region codes are in the table below.

The numbers below are from AWS documentation checked the same day. This post does not report a customer bill, a token saving, or an engagement outcome.

## Why a managed MCP server is worth the setup

An agent that can call AWS is another principal in the account. The managed [AWS MCP Server](https://docs.aws.amazon.com/aws-mcp/latest/userguide/getting-started-aws-mcp-server.html) is how AWS wants that principal to show up.

- **The agent reads current docs at question time.** Training data misses services that shipped after the cutoff. Documentation search and skill retrieval run without AWS credentials. API calls still require a real principal. Looking up S3 Tables and creating a bucket are different actions. Only the second one needs credentials.
- **The call has a name in CloudTrail.** A command typed in a local shell is hard to separate from the human who owns the laptop. The managed server records the request, and IAM condition keys `aws:ViaAWSMCPService` and `aws:CalledViaAWSMCP` let a policy treat agent calls differently from a human using the same role. AWS documents both keys on the [Agent Toolkit product page](https://aws.amazon.com/products/developer-tools/agent-toolkit-for-aws).
- **One tool covers the catalog.** AWS states that agents can reach **300+ services** and **15,000+ API actions** through a single tool, plus a sandboxed Python environment with no local filesystem and no network. You stop maintaining a private list of wrappers that drift from the API.
- **Skills load when the task matches.** The [Agent Toolkit repo](https://github.com/aws/agent-toolkit-for-aws) ships the procedures. Our [skills guide](/blog/aws-agent-toolkit-for-aws-skills-guide/) walks the repo layout. Install or discover a skill for the task in front of you. Do not paste the whole tree into the prompt.

If `aws-api-mcp-server` or `aws-knowledge-mcp-server` is still in the client config, remove those entries and restart the client before you add `aws-mcp`. AWS recommends the switch because the older servers collide with the managed tool list, and the managed server is the one with the IAM condition keys.

## When to use it

Use the managed server when the agent needs AWS knowledge or a scoped AWS action, and a human still owns the change that spends money or opens a network path.

**Cost questions in a non-production account.** Ask for idle EBS volumes, unattached Elastic IPs, NAT gateways with no traffic, and instances larger than the size your rules file allows. Keep the tools read-only. The useful output is a list a human deletes in a reviewed change, or a pull request that changes the template. The agent describing a 500 GB `gp2` volume is a cost review. The agent calling `DeleteVolume` is an incident.

**A security review of what an agent already did.** CloudTrail on the agent role answers which principal called which API. Pair that with the condition keys above so a filter can show MCP traffic apart from console traffic. Exposure investigation inside Claude Desktop is a different product: the [Security Hub MCP app](/blog/aws-security-hub-mcp-app-preview-2026/). Use that app for findings. Use the managed AWS MCP Server for general AWS API access.

**A draft of infrastructure as code.** The job is a CDK stack, a CloudFormation template, or a Terraform plan for a known pattern (a VPC, a Lambda function in an existing VPC, an S3 lifecycle rule). The agent writes the file. A pipeline or a named human applies it. Direct CLI apply from the chat is the path that skips review.

**Documentation and skill lookup before anyone has credentials.** New hires and contractors can search AWS docs and retrieve skills with no keys on the machine. That session cannot create resources. Treat it as the onboarding path, then add auth when the work needs an API.

**More than one account in a single session.** Named profiles and cross-account roles are a SigV4 feature. OAuth sign-in is one account for that session. If the agent must read from a log-archive account and describe resources in a workload account, connect with SigV4.

**Production investigation with writes hidden.** SigV4 can start in read-only mode so write-capable tools are absent from the tool list. The agent can describe, list, and search. It cannot "fix" a security group while you are still reading the alarm.

## When to skip it

Skip the managed server, or delay it, in four cases.

Your workload Region is outside the eight endpoints. Connecting to `us-east-1` so the agent can mutate `ap-south-1` resources sends that work across Regions. Write down the residency and latency decision before you install a client.

The environment cannot reach the public HTTPS endpoint. An air-gapped lab needs a different pattern. The managed server is a remote URL.

The task is one `describe` or `list` call you were going to run yourself under SSO. Standing up a proxy for a single read adds a moving part. The server pays off when the same guardrails apply to every person and every agent, or when the agent is doing multi-step work.

You already chose OAuth, and the task needs a second account. Stop and switch to SigV4. Forcing the second account through the same OAuth session is unsupported.

## Choose OAuth or SigV4

AWS documents two ways to authenticate. Pick before you paste a config.

| If this is true | Connect with |
| --- | --- |
| One AWS account, and the client can complete browser sign-in | OAuth |
| The client only accepts a remote MCP URL and cannot run a local process | OAuth |
| The session must use more than one AWS account | SigV4 |
| Write-capable tools must be hidden | SigV4 |
| The role cannot call `signin:AuthorizeOAuth2Access` or `signin:CreateOAuth2Token` | SigV4 |
| You want a default Region on the session via `AWS_REGION` | SigV4 |
| The client can run `uvx` and you already have AWS CLI credentials | SigV4 |

**OAuth** talks to the endpoint directly. No local proxy. Access tokens last **1 hour**. AWS Sign-in refreshes them for up to **12 hours**. The first tool call opens a browser. Attach `AWSMCPSignInOAuthAccessPolicy` to the role or user that will sign in, or the browser returns a 400 after login.

Context: AWS CLI, the IAM role a human will use for OAuth sign-in. Replace `MyRole`.

```bash
aws iam attach-role-policy \
  --role-name MyRole \
  --policy-arn arn:aws:iam::aws:policy/AWSMCPSignInOAuthAccessPolicy
```

Context: Claude Code CLI, OAuth, `us-east-1` endpoint. Other Regions use the same path with that Region's host.

```bash
claude mcp add aws-mcp https://aws-mcp.us-east-1.api.aws/mcp --transport http
```

Cursor, Claude Desktop, Kiro IDE, Codex, and Gemini CLI need the same URL with `?oauth=initialize` appended, or the OAuth flow never starts. Claude Code CLI, Kiro CLI 2.11 or later, and Devin use the URL without that query string. If your client is unlisted, start without the query string. Add `?oauth=initialize` when tool calls fail on credentials.

**SigV4** runs [MCP Proxy for AWS](https://docs.aws.amazon.com/aws-mcp/latest/userguide/getting-started-aws-mcp-server.html) locally. The setup guide asks for AWS CLI **2.32.0 or later**, `aws login` (credentials rotate every **15 minutes**, sessions up to **12 hours**), `aws sts get-caller-identity`, and `uv`. The endpoint Region selects which MCP server you reach. The `AWS_REGION` metadata value is the default Region for AWS operations. Leave it unset and operations default to `us-east-1`, which surprises teams who connected to Frankfurt on purpose.

> **What broke** — The [setup guide](https://docs.aws.amazon.com/aws-mcp/latest/userguide/getting-started-aws-mcp-server.html) tells you to run `uvx mcp-proxy-for-aws-cli@latest`. The [product page](https://aws.amazon.com/products/developer-tools/agent-toolkit-for-aws) shows `mcp-proxy-for-aws@1.6.3` and a one-shot `aws configure agent-toolkit` that needs AWS CLI **2.35 or later**. Paste the package name from the page you did not re-read, and the client fails on a missing command. Pin a version you have already installed. Re-check the user guide on the day you install. Treat `@latest` as the setting that changes behavior under you.

Context: Cursor, Claude Desktop, or Devin Desktop, SigV4. Replace `PINNED` with the version you confirmed in the user guide that day. The sample points the MCP host at `us-east-1` and sets API operations to `us-west-2`. Change both to your Regions.

```json
{
  "mcpServers": {
    "aws-mcp": {
      "command": "uvx",
      "args": [
        "mcp-proxy-for-aws-cli@PINNED",
        "https://aws-mcp.us-east-1.api.aws/mcp",
        "--metadata",
        "AWS_REGION=us-west-2"
      ]
    }
  }
}
```

If `aws configure agent-toolkit` exists on your CLI, run it and read the file it writes. If the command is missing, you are below CLI 2.35 and the manual steps in the user guide are the path.

**Recommendation:** SigV4 plus a dev-only role when the agent might see more than one account, or when a production account must not expose write tools. OAuth when the whole requirement is one account and a remote client. The trade-off is install cost. SigV4 needs the CLI, uv, and a proxy. OAuth skips that install and gives up profile switching and read-only tool hiding.

### Endpoints

Substitute the host when you are not in N. Virginia. Protocol is HTTPS.

| Region | Host |
| --- | --- |
| US East (N. Virginia) | `aws-mcp.us-east-1.api.aws` |
| US West (Oregon) | `aws-mcp.us-west-2.api.aws` |
| Asia Pacific (Singapore) | `aws-mcp.ap-southeast-1.api.aws` |
| Asia Pacific (Sydney) | `aws-mcp.ap-southeast-2.api.aws` |
| Asia Pacific (Tokyo) | `aws-mcp.ap-northeast-1.api.aws` |
| Europe (Frankfurt) | `aws-mcp.eu-central-1.api.aws` |
| Europe (Ireland) | `aws-mcp.eu-west-1.api.aws` |
| Europe (London) | `aws-mcp.eu-west-2.api.aws` |

The path is `/mcp`. Full URL shape: `https://aws-mcp.us-east-1.api.aws/mcp`.

> **Reproduce this** — Follow [Setting up the AWS MCP Server](https://docs.aws.amazon.com/aws-mcp/latest/userguide/getting-started-aws-mcp-server.html) for your client. Skills and the recommended rules file live in [`aws/agent-toolkit-for-aws`](https://github.com/aws/agent-toolkit-for-aws). After the server initializes, ask "What AWS Regions are available?" In Kiro CLI, `/tools` or `/mcp` should list `aws___search_documentation` and `aws___retrieve_skill`. The first connection can take a few minutes.

## Auth errors that block the first session

| Error | What it usually means | What to do |
| --- | --- | --- |
| `ExpiredTokenException` | The session token lapsed. Short-lived tokens often die mid-task. | `aws login` again, or `aws sso login --profile your-profile-name`. Restart the MCP client. |
| 400 page after OAuth | The principal lacks `signin:AuthorizeOAuth2Access` and `signin:CreateOAuth2Token`. | Attach `AWSMCPSignInOAuthAccessPolicy`, then sign in again. |
| `InvalidSignatureException` | SigV4 disagreed. Clock skew is a common cause. AWS requires the clock within **5 minutes**. | Check `date` against a real time source. Then restart the client. |
| No AWS credentials found | The CLI credential chain is empty. | `aws login`, confirm with `aws sts get-caller-identity`, restart the client. |

`UnrecognizedClientException` means the token is revoked, malformed, from another partition (`aws` vs `aws-cn`), or tied to a deleted user. `aws sts get-caller-identity` failing is the check. Fix credentials before you debug the MCP JSON.

## Cost

The MCP server has **no additional charge**. AWS states you pay standard prices for whatever the agent provisions or calls. A "free" agent that creates a NAT gateway, an OpenSearch domain, or a Bedrock workload is a normal AWS bill with a faster author.

Published request caps, from the [quotas page](https://docs.aws.amazon.com/agent-toolkit/latest/userguide/aws-mcp-limits.html), checked 3 October 2026:

| Quota | Default | Adjustable |
| --- | --- | --- |
| Concurrent connections per account per Region | 100 | No |
| Concurrent sessions per account per Region | 180 | Yes |
| Concurrent sessions per IAM user or role per Region | 90 | Yes |
| Authenticated requests per account per Region | 10 per second, sustained | No |
| Unauthenticated requests per source IP per Region | 5 per second, sustained | No |
| Ephemeral session storage | 8 hours | No |

Some secondary write-ups still cite 27 connections and 3 requests per second. Those figures disagree with the user guide. Use the quotas page, or the Service Quotas console entry for AWS MCP Server, on the day you set alarms.

A retry loop at 10 requests per second returns **429**. It does not mean you need a larger model. Back off. Authenticated calls get the account quota and the API tools. Unauthenticated calls share 5 per second per source IP and can use knowledge tools only. Authenticating is how you raise that ceiling, up to the 10 per second cap.

CloudWatch usage metrics land in the AWS/Usage namespace. CallCount counts requests. ResourceCount covers concurrent connections, account sessions, and user sessions. Requests throttled before they reach the server do not appear in CallCount. A flat graph can coexist with 429s at the edge. Alarm on the 429s in the client logs as well as on the usage metrics.

Put a size ceiling in the rules file so the draft itself refuses an oversized instance. The human who applies the change should still see the price.

## Security

Give the agent its own role per environment. Name the roles agent-dev and agent-prod-readonly so CloudTrail is readable. Deny deletes and network changes on the production role. A shared `AdministratorAccess` role removes the only boundary the protocol will honor.

Use `aws:ViaAWSMCPService` and `aws:CalledViaAWSMCP` in IAM policies and SCPs when agent traffic must follow a tighter policy than the human who owns the underlying role. AWS describes the pattern as: the human can write, the MCP path stays read-only. Read the current IAM examples in the AWS docs before you copy a statement into a stack. This post does not ship a policy document.

Read-only mode belongs on SigV4, in production and in any account where a surprise write is expensive. Dev accounts can allow a wider role, still short of admin, because the apply step is a pull request.

OAuth consent is a browser grant by a human. That is a poor fit for an unattended job. Unattended agents should use SigV4 with a role the pipeline already assumes, scoped to the account you mean.

Remove the older AWS Labs MCP servers so a confused tool call cannot bypass the condition keys you just wrote.

## Stability

Sessions are not infinite. Ephemeral compute storage is kept for **8 hours**, then reclaimed. A long coding session that depended on files in that scratch space will not find them the next morning. OAuth tokens expire in **1 hour** even though refresh can run out to 12 hours. `aws login` rotations every 15 minutes fail closed when the session hits 12 hours. Restart the client after you refresh credentials. An initialized server keeps the dead token until you do.

The connection quota of **100** per account per Region does not move. A workshop where every laptop opens a connection can hit it. Session quotas (180 per account, 90 per principal) can be raised through Service Quotas. Plan the workshop against the connection cap, because that one stays.

The MCP host Region and the `AWS_REGION` metadata value are different settings. Connecting to `eu-west-1` while leaving operations on the default `us-east-1` creates resources in the wrong Region and still looks like a successful tool call.

Pin the proxy. A floating `@latest` is how a Thursday morning breaks a config that worked Wednesday.

## Practices

AWS ships a recommended rules file in the [toolkit repo](https://github.com/aws/agent-toolkit-for-aws/tree/main/rules). It tells the agent to call AWS through the MCP server, to search for a skill before inventing a procedure, to check current docs, and to prefer infrastructure as code over a direct CLI command. Copy that file, then add the constraints for this repo.

| Agent | Where the rules go |
| --- | --- |
| Claude Code | `CLAUDE.md` in the project root |
| Codex | `AGENTS.md` in the project root |
| Cursor | `.cursor/rules/*.mdc` (for example `.cursor/rules/aws.mdc`) |
| Kiro | `.kiro/steering/*.md` |

Context: a Cursor rule at `.cursor/rules/aws.mdc`. Replace the Region, the VPC, and the tags with yours. IAM still enforces the boundary. The file only steers the draft.

```md
# Project AWS rules

- Default Region is eu-west-1. Create resources elsewhere only when the task names that Region.
- Deploy into the shared-services VPC recorded in this repo's network doc.
- Name resources {team}-{service}-{environment}-{purpose}.
- Tag every resource with Team, CostCenter, and Environment.
- Lambda runtime is Python 3.12 unless this repo already uses another runtime.
- Ask before launching anything larger than t3.medium.
- Call AWS through the AWS MCP Server. Search skills before you invent a procedure. Prefer infrastructure as code over a direct CLI apply.
```

That size line is the cost control you can check in review. The tag line is how finance attributes the resource the agent proposed. The Region line is how you stop a Frankfurt workload from landing in Virginia because the metadata default won.

## What to do this week

1. Confirm the account's Region is one of the eight hosts. If it is not, write down the residency decision before anyone installs a client.
2. Delete `aws-api-mcp-server` and `aws-knowledge-mcp-server` from the MCP config. Restart the client.
3. Pick auth. OAuth for one account and a remote client. SigV4 for multiple accounts, read-only mode, or a default `AWS_REGION`.
4. On SigV4, pin the proxy version after you confirm the package name in the user guide. On OAuth, attach `AWSMCPSignInOAuthAccessPolicy`.
5. Create a dev role for the agent. Keep production on a SigV4 profile with write tools hidden.
6. Add the rules file for the editor you actually use. Set Region, tags, and the instance-size ceiling.
7. Ask "What AWS Regions are available?" and confirm `aws___search_documentation` is loaded.
8. Alarm when connections approach 100 per Region, and watch client logs for 429s. `CallCount` misses requests that were throttled in front of the server.

### If you only do one thing

Create the dev-only role and connect that role with SigV4 if the agent can see more than one account or if any account is production. Use OAuth only when a single account and a remote client are the whole requirement.

## What this post does not cover

- Hosting your own MCP server on Bedrock AgentCore Runtime. That is a different surface from the managed AWS MCP Server.
- The Security Hub MCP app for exposure findings. Linked above, not repeated here.
- A current count of `SKILL.md` files. The catalog moves. Clone [`aws/agent-toolkit-for-aws`](https://github.com/aws/agent-toolkit-for-aws) and count it, or read the [skills guide](/blog/aws-agent-toolkit-for-aws-skills-guide/) for the layout and a pinned snapshot.
- A measured customer bill. The prices in this post are AWS list facts: no server charge, standard resource prices, and the quotas in the table.
- The model vendor's terms. CloudTrail covers the AWS API call. It does not cover what the coding assistant retained from the prompt.

## Related reading

- [AWS MCP Server hits GA](/blog/aws-mcp-server-ga-agent-toolkit-serverless-plugin/) covers the 6 May 2026 announcement and the serverless agent plugin. The Region count there is the GA count.
- [Agent Toolkit skills, plugins, and rules](/blog/aws-agent-toolkit-for-aws-skills-guide/) covers the repo. Recount skills before you quote a number.
- [Kiro and AWS agentic coding](/blog/kiro-ide-aws-agentic-coding/) covers the IDE side of the same clients.

**Need a dev-only agent role, a read-only production boundary, or a rules file the team will keep?** [FactualMinds is an AWS Select Tier Services Partner](/aws-partner/). [Tell us which account the agent should touch first](/contact-us/).

## FAQ

### When is OAuth the wrong way to connect the AWS MCP Server?
Use SigV4 when the same session must switch AWS accounts, when write-capable tools must be hidden, when the role cannot call signin:AuthorizeOAuth2Access or signin:CreateOAuth2Token, or when you need a default AWS_REGION on the session. OAuth fits one account and a client that can complete browser sign-in. It cannot switch named profiles, and it cannot hide write tools.

### What goes wrong if the older AWS API or Knowledge MCP servers stay in the client config?
AWS recommends removing aws-api-mcp-server and aws-knowledge-mcp-server before you add the managed AWS MCP Server. Two AWS tool lists in one client make the agent pick the wrong server, and you lose the IAM condition keys that mark a call as coming through the managed server. Restart the client after you delete the old entries.

### Does the AWS MCP Server add a charge of its own?
AWS lists Agent Toolkit for AWS, including the managed MCP server, at no additional charge. You pay standard prices for the AWS resources the agent provisions or calls, such as a NAT gateway it creates or a Bedrock request it makes. Budget for that usage. The server fee is zero.

### What happens when an agent exceeds 10 authenticated requests per second?
The account is throttled with HTTP 429. The authenticated quota is 10 sustained requests per second per account per Region, and it is not adjustable. A retry loop against that cap wastes the session. Unauthenticated calls have a separate cap of 5 per second per source IP, and they can use only the knowledge tools.

### Can a session with no AWS credentials call AWS APIs through the MCP server?
No. Unauthenticated access is limited to read-only knowledge tools such as documentation search, documentation retrieval, and regional availability. Tools that run AWS API calls or execute scripts require SigV4 or OAuth. Docs search is the path that works before anyone configures credentials.

### Does read-only mode work if we signed in with OAuth?
Read-only mode, which hides write-capable tools from the agent, is a SigV4 option in the setup guide. OAuth does not offer it. For a production account, connect with SigV4, hide write tools, and keep a separate dev role for changes a human will review.

---

*Source: https://www.factualminds.com/blog/aws-mcp-server-when-to-use-setup-2026/*
