> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nekt.com/llms.txt
> Use this file to discover all available pages before exploring further.

# AWS as an MCP

> Let your AI agents use AWS in real time through the Nekt MCP Gateway.

AWS is a comprehensive cloud computing platform. By attaching AWS as an MCP, your agents can inspect and manage your Step Functions executions, CloudWatch metrics, CloudWatch Logs, and Lambda functions directly from a conversation.

| | Available |
| :- | :- |
| **Nekt Express** | Yes |
| **GCP** | Yes |
| **AWS** | Yes |

## Adding AWS as an MCP

Before you start, make sure the [MCP Server](/mcp-server/setup) is set up. See [MCPs](/mcps/overview) for how MCPs work.

<Steps>
  <Step title="Open the MCPs module">
    Go to **Activate → [MCPs](https://app.nekt.ai/mcps)**, click **New MCP** and choose **AWS**.
  </Step>

  <Step title="Name your MCP">
    **Name your MCP** and describe what it is used for. The agent reads the description to choose between MCPs of the same provider.
  </Step>

  <Step title="Setup access">
    **Setup access**. Generate an access key pair in AWS for the IAM user or role the agent should act as.

    * **Default AWS region**: The AWS region used when a tool call does not specify one, e.g. us-east-1 or ca-central-1. (Required)
    * **Access key ID**: Access key ID of the IAM user. Grant this user read-only permissions unless the write tools will be used. (Required)
    * **Secret access key**: Secret access key matching the access key ID. (Required)
    * **Session token**: Optional. Only needed when the access key pair is a temporary credential.
  </Step>

  <Step title="Select tools">
    **Select tools**. Pick the tools your agents can use. See [Available tools](#available-tools) below.
  </Step>

  <Step title="Save">
    Click **Save**. On Growth and Custom plans, choose who can use it; see [Access levels](/mcps/overview#access-levels).
  </Step>
</Steps>

## Example prompts

* "List the recent executions for our data pipeline state machine."
* "Check the logs for the cache invalidation Lambda function over the last hour."
* "Get the current CPU utilization metrics for the production cluster."
* "Invoke the reporting Lambda function with the daily payload."

## Available tools

Choose which of these tools your agents can use in **Select tools**.

### Read tools

| Tool | Description | Parameters |
| :- | :- | :- |
| `execute_cloudwatch_logs_read_only` | Call a read-only AWS CloudWatch Logs (boto3 `logs`) operation and return its response. For reading logs: `filter_log_events` and `get_log_events` to fetch log lines, `describe_log_groups` / `describe_log_streams` to find them, and `start_query` + `get_query_results` for Logs Ins… | `operation` (string, required), `region` (string), `max_items` (integer), `parameters` (object) |
| `execute_cloudwatch_read_only` | Call a read-only AWS CloudWatch metrics/alarms (boto3 `cloudwatch`) operation. For metrics and alarm state: `get_metric_data` and `get_metric_statistics` to read datapoints, `list_metrics` to discover them, `describe_alarms` / `describe_alarm_history` for alarm state. Pass \`oper… | `operation` (string, required), `region` (string), `max_items` (integer), `parameters` (object) |
| `execute_lambda_read_only` | Call a read-only AWS Lambda (boto3 `lambda`) operation and return its response. For inspecting functions: `get_function` and `get_function_configuration` for a function's settings, `list_functions` to enumerate them, `get_function_concurrency`, `list_event_source_mappings`, \`get… | `operation` (string, required), `region` (string), `max_items` (integer), `parameters` (object) |
| `execute_stepfunctions_read_only` | Call a read-only AWS Step Functions (boto3 `stepfunctions`) operation and return its response. For inspecting state machines and executions: `describe_execution`, `get_execution_history`, `list_executions`, `describe_state_machine`, `list_state_machines`, `describe_map_run`, \`li… | `operation` (string, required), `region` (string), `max_items` (integer), `parameters` (object) |

### Write tools

| Tool | Description | Parameters |
| :- | :- | :- |
| `execute_cloudwatch_logs_write` | Call any AWS CloudWatch Logs (boto3 `logs`) operation, including mutating ones. Covers `create_log_group`, `delete_log_group`, `put_log_events`, `put_retention_policy`, `put_subscription_filter`, `create_export_task` and tagging. `parameters` is the AWS request object. For readi… | `operation` (string, required), `region` (string), `max_items` (integer), `parameters` (object) |
| `execute_cloudwatch_write` | Call any AWS CloudWatch metrics/alarms (boto3 `cloudwatch`) operation, including mutating ones. Covers `put_metric_data`, `put_metric_alarm`, `delete_alarms`, `set_alarm_state`, `put_dashboard` and tagging. `parameters` is the AWS request object. For reading metrics and alarm st… | `operation` (string, required), `region` (string), `max_items` (integer), `parameters` (object) |
| `execute_lambda_write` | Call any AWS Lambda (boto3 `lambda`) operation, including invoking and mutating functions. Covers `invoke` (which runs the function), `create_function`, `update_function_code`, `update_function_configuration`, `delete_function`, `add_permission` and concurrency settings. \`parame… | `operation` (string, required), `region` (string), `max_items` (integer), `parameters` (object) |
| `execute_stepfunctions_write` | Call any AWS Step Functions (boto3 `stepfunctions`) operation, including mutating ones. Covers `start_execution`, `start_sync_execution`, `stop_execution`, `create_state_machine`, `update_state_machine`, `delete_state_machine`, `send_task_success`/`send_task_failure` and tagging… | `operation` (string, required), `region` (string), `max_items` (integer), `parameters` (object) |

## Troubleshooting

* **Access expired or revoked**: If your temporary session token expires or the IAM access key is revoked, the MCP shows that it needs to reconnect. Go to the MCP's page in Nekt and update the credentials to sign in again.
* **Missing permissions**: The agent can only perform operations allowed by the IAM policy attached to your access key. If a tool call fails, verify the IAM identity has the required permissions for that AWS service.

## Need help?

Contact our support team if you have trouble connecting AWS.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.