ScreenshotNeo

BlogAI agents

How to Use the Official AWS MCP Server

Learn what AWS's managed MCP Server does, how IAM-backed execution works, which AWS Labs servers differ, and how to connect safely.

By the ScreenshotNeo team1 October 20267 min read

Short answer: The official AWS MCP Server is AWS’s managed Model Context Protocol endpoint. It gives an AI agent one AWS-managed connection for documentation and service information, plus authenticated capabilities such as AWS API calls, sandboxed Python execution, and curated skills. Documentation and service information can be used without authentication; execution capabilities use the IAM credentials already associated with the customer. Start with the live AWS MCP Server setup guide for your MCP client, then grant only the IAM permissions needed for the task.

This guide explains what the managed server is, how its identity model works, how to choose it over similarly named AWS Labs servers, and how to operate it safely. AWS’s public overview does not expose a complete client-by-client setup recipe, region list, or policy document in the material reviewed for this article. Those details change, so this article does not guess them.

1. Identify the server you mean

Several projects use nearly the same name. Verify whether a guide refers to the managed AWS MCP Server or to a local AWS Labs repository.

Server What it is Typical use Identity and hosting
AWS MCP Server AWS-managed endpoint documented in the Agent Toolkit for AWS. Documentation and service information, AWS API calls, sandboxed Python, and curated skills through one endpoint. Managed by AWS. Documentation and service information do not require authentication; execution uses your IAM identity.
AWS Knowledge MCP Server AWS Labs’ remote, AWS-hosted documentation resource. Retrieve AWS documentation and related guidance. Remote managed resource; it is different from the official endpoint.
AWS Documentation MCP Server A separate AWS Labs project that you run locally. Read, search, and inspect AWS documentation. Local process with its own prerequisites and tools.
AWS API MCP Server The older AWS Labs API server. Earlier local or self-hosted patterns for calling AWS APIs. AWS Labs marks it as superseded by the official AWS MCP Server.

The AWS Labs collection is being succeeded by the Agent Toolkit for AWS. Existing repositories may continue to work, but their README instructions describe those individual projects, not the managed endpoint.

2. Understand capabilities and identity

Unauthenticated information access

AWS describes documentation search and service information as available without authentication. This is useful when an agent needs to explain an AWS service, find a parameter, or retrieve context before proposing an action.

IAM-backed execution

AWS API calls, sandboxed Python execution, and curated skills use the customer’s existing IAM credentials. The MCP connection does not create a second AWS account or bypass IAM. The agent’s effective permissions are those of the IAM identity presented to AWS, subject to additional controls in your environment.

Use a role or user dedicated to automation. Begin with read-only permissions for discovery, then add narrowly scoped write permissions only when required. Review mutating calls before approval.

Controls and observability

AWS names IAM-based access controls, CloudWatch metrics, and CloudTrail logging for API calls. AWS states: CloudTrail logs all API calls for audit visibility. Treat these as monitoring and control capabilities, not as a guarantee that every prompt or tool selection is safe.

3. Set up the managed server without guessing

  1. Choose your MCP client. Open the current AWS setup section and select the client you use.
  2. Confirm the endpoint and region shown there. The overview reviewed here does not publish a stable endpoint or complete regional matrix.
  3. Authenticate with the intended IAM identity. Ensure the client process can obtain the role or user credentials that should authorize AWS API calls.
  4. Start with a read-only task. Ask the agent to retrieve documentation or describe a resource. Check the proposed tool call and identity in your audit trail.
  5. Add permissions deliberately. If a task needs an API write, grant only required actions and resources, then test in a non-production account.
  6. Turn on telemetry. Use CloudWatch metrics and CloudTrail records to observe calls and investigate failures.

The exact JSON or TOML block, OAuth flow, supported clients, regions, and IAM policy are intentionally left to the current AWS documentation. The fetched overview has a setup heading but does not include those details; copying values from the older AWS API MCP README can connect you to the wrong service.

4. If you meant the AWS Documentation MCP Server

The local documentation server is useful when you want documentation tools in your own process. Its AWS Labs README requires uv and Python 3.10 or newer and documents this launch command:

uvx awslabs.aws-documentation-mcp-server@latest

Its documented tools include reading documentation, searching AWS documentation, reading sections, searching table rows, getting recommendations, and, in China only, listing available services. This command starts the local AWS Documentation MCP Server; it does not configure the managed AWS MCP Server.

5. Migration from the AWS API MCP Server

If an older article tells you to install awslabs.aws-api-mcp-server, check its status first. AWS Labs labels that project superseded by the official AWS MCP Server and links to a migration guide. Do not copy its local credentials, HTTP deployment settings, or tool names as if they were the managed service.

The predecessor README’s HTTP guidance is specifically for self-hosting: it recommends serving a single customer, binding to localhost where possible, restricting network access, and using HTTPS/TLS.

6. A practical first-session checklist

  • Write down the task and whether it needs read or write access.
  • Use a dedicated IAM identity and verify its account and role.
  • Ask for documentation first; inspect the proposed API call second.
  • Require human approval for destructive or production changes.
  • Confirm CloudTrail records appear for an allowed API call.
  • Set a time limit and cancellation path for long-running agent work.

7. Troubleshooting

Symptom Likely cause Fix
Documentation search works, but an API call is denied. Information tools are unauthenticated while execution uses IAM. Check the active IAM identity and grant the minimum required action.
The client cannot connect. Wrong endpoint, region, or client configuration copied from an older server. Reopen the current AWS setup section for your client and replace server-specific values.
A guide asks you to run uvx. You may be reading instructions for a local AWS Labs server. Confirm the server name before proceeding.
Credentials appear valid but calls fail. Wrong account, expired credentials, permission boundary, or SCP. Inspect the active identity, account, region, boundary, and organization controls.
A tool call returns a validation error. Invalid AWS parameter or API-version mismatch. Retrieve service documentation and retry with a small read-only request.
Calls are slow or time out. Long AWS operation or large response. Limit scope, paginate results, and set suitable client timeouts.
You cannot find an audit record. The call did not reach AWS or the wrong account or region was queried. Check client logs and search CloudTrail with the identity and time window.

8. Performance, reliability, and cost

Performance

Keep prompts and result sets narrow. Ask for one service, account, region, or resource class at a time. Paginate large responses and avoid repeatedly fetching identical context.

Reliability

Prefer read-before-write checks and idempotent operations where available. After an unknown timeout, inspect state before retrying. Record the request, target account, region, IAM identity, and resulting resource identifiers.

Cost

The supplied AWS overview does not provide a managed MCP price or usage benchmark. AWS API calls, CloudWatch, CloudTrail, and invoked services can have their own pricing. Check current AWS pricing pages and configure budgets or alerts.

9. Or skip the browser setup

If your agent workflow also needs clean screenshots of AWS documentation, dashboards, or runbooks, ScreenshotNeo provides a single HTTP request instead of maintaining a browser worker.

It removes cookie and consent banners, newsletter popups, and chat widgets before capture. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, and the response reports the page verdict and billing status. ScreenshotNeo also offers an MCP server with take_screenshot, get_page_info, and capture_pdf for Claude, Cursor, and other MCP clients. The free plan includes 1,000 screenshots per month without a card; paid plans start at $5 for 3,000 screenshots. See the ScreenshotNeo API docs for all options.

cURL

curl -G 'https://api.screenshotneo.com/v1/shot' -d access_key=YOUR_API_KEY --data-urlencode url=https://docs.aws.amazon.com -o shot.webp

Python

import requests
r = requests.get('https://api.screenshotneo.com/v1/shot', params={'access_key': 'YOUR_API_KEY', 'url': 'https://docs.aws.amazon.com'}, timeout=90)
open('shot.webp', 'wb').write(r.content)

Node.js

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://docs.aws.amazon.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

Create a free ScreenshotNeo account for 1,000 screenshots each month with no card.

10. FAQ

Is the official server the same as AWS Knowledge MCP Server?

No. AWS Knowledge MCP Server is a separate AWS Labs remote documentation resource. The official AWS MCP Server is the AWS-managed endpoint that combines information access with authenticated execution.

Can an agent call AWS APIs without IAM permissions?

No. AWS API calls use the customer’s IAM credentials. Unauthenticated documentation access does not imply unauthenticated resource access.

Should I uninstall the AWS Labs servers?

Not automatically. Keep a local server when its documented tools fit your need, but treat AWS API MCP Server as superseded and follow migration guidance before starting new work.

Where are the exact regions and policies?

Use the current AWS setup documentation for your MCP client and account. The overview used here did not expose a complete region list or IAM policy.