Adding AWS as an MCP
Before you start, make sure the MCP Server is set up. See MCPs for how MCPs work.1
Open the MCPs module
Go to Activate → MCPs, click New MCP and choose AWS.
2
Name your MCP
Name your MCP and describe what it is used for. The agent reads the description to choose between MCPs of the same provider.
3
Setup access
Setup access. Generate an access key pair in AWS for the IAM user or role the agent should act as.
- Default AWS region: The AWS region used when a tool call does not specify one, e.g. us-east-1 or ca-central-1. (Required)
- Access key ID: Access key ID of the IAM user. Grant this user read-only permissions unless the write tools will be used. (Required)
- Secret access key: Secret access key matching the access key ID. (Required)
- Session token: Optional. Only needed when the access key pair is a temporary credential.
4
Select tools
Select tools. Pick the tools your agents can use. See Available tools below.
5
Save
Click Save. On Growth and Custom plans, choose who can use it; see Access levels.
Example prompts
- “List the recent executions for our data pipeline state machine.”
- “Check the logs for the cache invalidation Lambda function over the last hour.”
- “Get the current CPU utilization metrics for the production cluster.”
- “Invoke the reporting Lambda function with the daily payload.”
Available tools
Choose which of these tools your agents can use in Select tools.Read tools
Write tools
Troubleshooting
- Access expired or revoked: If your temporary session token expires or the IAM access key is revoked, the MCP shows that it needs to reconnect. Go to the MCP’s page in Nekt and update the credentials to sign in again.
- Missing permissions: The agent can only perform operations allowed by the IAM policy attached to your access key. If a tool call fails, verify the IAM identity has the required permissions for that AWS service.