mcpSecurity.cloud
Independent AWS MCP security intelligence

AWS MCP servers: official, open source, and community

Our catalog surfaces 199 AWS-related matches. This guide separates product association from publisher identity, then connects each implementation to distribution and current security evidence.

199AWS catalog search matches
6Amazon and AWS product families mapped
4representative evidence records
Executive finding

“AWS-related” is not the same as “published by AWS.”

The catalog’s 199 AWS matches include implementations that connect to AWS products, AWS-associated packages, and community projects. Brand association alone does not establish publisher identity, security review, or endorsement.

Official vs community

Three different AWS MCP populations

Search results frequently collapse these populations together. They have different ownership, hosting, update, authentication, and evidence models.

PopulationWho operates itTypical deliveryWhat to verify
AWS-managed MCP ServerAWS-managed serviceRemote regional endpointIAM and SCP scope, proxy configuration, mutating access, CloudTrail coverage
AWS Labs open-source serversAWS Labs repositories and contributorsPrimarily locally run packages; varies by serverExact repository and package, credentials used, tool authority, maintenance state
Community AWS serversIndependent publishersnpm, PyPI, source, or remote endpointPublisher provenance, package integrity, remote operator, permissions, verification evidence
Independent conclusion: an implementation can accurately describe itself as an “AWS MCP server” while having no first-party publishing relationship with AWS.
Security decision

What to establish before adoption

The decisive variable is not the AWS label. It is the combination of operator identity, execution boundary, and effective authority.

01 · IDENTITY

Who controls it?

Verify the repository owner, package publisher, remote domain, and whether first-party status is supported by retained evidence.

02 · AUTHORITY

What can it change?

Map every exposed tool to the IAM principal, resources, regions, and mutating operations available in the deployment.

03 · ASSURANCE

What was tested?

Use exact-version verification as bounded evidence. Missing evidence means unknown; a clean retained run is not certification.

AWS MCP server inventory

Amazon and AWS product coverage

Counts below are catalog search appearances and can overlap. Open a result set to evaluate individual implementations rather than treating the total as a list of official servers.

Product familyCatalog matchesIntegration surfaceComplete result set
AWS199Cloud infrastructure, deployment, operations, data, and AI servicesView all AWS results →
Amazon81Cross-product records explicitly referencing AmazonView all Amazon results →
Amazon Bedrock4Foundation models, agents, knowledge bases, and generative AIView all Amazon Bedrock results →
Amazon Redshift12Cloud data warehouse querying, analytics, and administrationView all Amazon Redshift results →
Amazon CloudWatch8Metrics, logs, alarms, and operational observabilityView all Amazon CloudWatch results →
Amazon DynamoDB6NoSQL tables, records, queries, and cloud data operationsView all Amazon DynamoDB results →
Catalog evidence

Representative AWS-related records

These records demonstrate why attribution and verification must remain separate. They are examples, not a complete or ranked recommendation list.

ImplementationDistributionCurrent security evidenceEvidence record
Amazon All-in-One Scrape MCPAmazonDistribution unresolvedVerification pendingNo completed public current-version result is available.Open evidence →
Amazon DataZone MCP ServerAmazon DataZonePyPI · amazon-datazone-mcp-server · 0.1.1Verification pendingNo completed public current-version result is available.Open evidence →
AWS Nova CanvasAWS Nova CanvasPyPI · 1.1.0Verification completedNo proven finding in the retained current-version test scope.Open evidence →
Yawlabs AWS MCPAWS; Yawlabs named publishernpm · @yawlabs/aws-mcp · 1.8.2Verification completedNo proven finding in the retained current-version test scope.Open evidence →
Primary sources

Validate implementation claims at the source

AWS MCP questions

Direct answers for security teams

What is the official AWS MCP Server?

AWS describes its managed MCP Server as a remote service that gives compatible agents authenticated AWS access through a small tool set. It is distinct from the collection of open-source AWS Labs servers and from third-party servers that mention AWS.

Are all AWS MCP servers published by Amazon?

No. An AWS product name can describe the service an MCP connects to without proving that AWS published, reviewed, or endorsed the implementation. Publisher identity must be verified separately.

Is an AWS MCP server safe?

No server is safe by name alone. Review publisher evidence, authentication, effective IAM permissions, mutating tools, remote endpoints, auditability, package provenance, and version-specific verification before adoption.

How many AWS MCP servers are there?

AWS Labs lists dozens of specialized AWS servers, while this catalog currently surfaces 199 AWS search matches. The catalog count is a discovery measure, not a deduplicated count of official AWS servers.

Method. Catalog counts were captured on 31 August 2026. The 310 appearances across all product rows overlap and are not a deduplicated implementation count; “199 AWS matches” is the direct AWS query count. Association is based on product terms in catalog identity and description fields and does not imply first-party publication, endorsement, or certification. Verification applies only to the selected exact version and retained test scope. Search every Amazon and AWS catalog match →

Let’s talk about MCP security.

Share your details and our security team will contact you.