Agents list resources and their states across services, read-only.
Cloud infrastructure
AWS MCP server
Give AI agents governed access to the AWS MCP server through one audited gateway. Scoped permissions, full observability, and tamper-evident logs on every tool call.
What is the AWS MCP server?
The AWS MCP server is an open Model Context Protocol (MCP) server that connects AI agents to AWS cloud resources across services like EC2, S3, Lambda, and CloudWatch. Through it an agent can list resources, read metrics, and inspect configuration without bespoke integration code, while the Averta MCP Gateway keeps every action scoped and audited.
List EC2 instances and their states.
Read configuration for an instance.
List S3 buckets and their regions.
Read CloudWatch metrics for a resource.
List Lambda functions and runtimes.
Read RDS database configuration.
Read cost and usage with Cost Explorer.
List IAM roles and policies.
Read CloudWatch log streams.
List ECS services and task counts.
Why the Averta MCP Gateway
Centralized governance
Unified authentication, audit logging, and rate control for every AWS MCP connection.
Observability and control
Real-time visibility into usage, anomalies, and SLA compliance across every request.
One-click deployment
Enable the AWS MCP server for your AI teams through one governed gateway, with no manual setup.
Enterprise hardening
High availability, security, and compliance alignment turn MCP from a developer utility into production-grade infrastructure.
OAuth and SSO enforcement
Enterprise authentication and SSO applied automatically to every AWS endpoint.
Shared and per-user auth
Configure service accounts or per-user access, with secrets protected and centralized revocation.
One managed endpoint
Connect agents to AWS through a single governed endpoint instead of locally run servers, improving your security posture.
Granular tool access control
Allow only the tools each role needs. Enable read-only access and block write tools like create and delete.
Works with every major AI platform
CognitionBuilt for enterprise teams.
Cloud, private VPC, embedded SDK, or gateway integration. Run Averta where your data, policies, and auditors need it.
Cloud (SaaS)
Fully managed by Averta. Fastest path to production, no infrastructure to run.
Private / VPC
Deploy in your own environment, so data never leaves your boundary.
Embedded SDK & Proxy
Drop Averta into your stack at the SDK or proxy layer, wherever your agents run.
Gateway Integration
Route agent traffic through the gateway, so policy and audit apply at the edge.
AWS MCP use cases
Where teams put the AWS MCP server to work, governed end to end through the Averta MCP Gateway.
List running EC2 instances in us-east-1.
YouListed running instances in us-east-1.
- Listing EC2 instances
- Filtering by region and state
All actions logged and governed
Powering safe AI execution at leading teams.
Cyfrin secures its production AI agents with Averta.
Book a demo“Averta gave our agents enforceable boundaries for the dev environment, so instructions like ‘don’t read .env files’ became policy instead of polite suggestions.”
Mikhail Karan
Head of Engineering
Explore other MCP servers
Browse allAWS MCP server, answered
Security and setup questions teams ask before connecting the AWS MCP server to AI agents.
Yes. The Averta MCP Gateway sits between your AI agents and any MCP server, giving each agent scoped, per-agent permissions, applying allow, escalate, or block policies on every tool call, and recording a tamper-evident audit of every action. The “Why the Averta MCP Gateway” section on this page covers what it enforces.
It is as safe as the controls around it. The server can reach cloud resources through one set of credentials, so scoping to read-only and specific services is the real risk. The Averta MCP Gateway limits and records every call.
Apply tool-level policy through the Averta MCP Gateway so describe and read operations run automatically while any mutating action escalates for approval. Every call is logged.
Route agents through Averta's MCP Gateway for scoped per-agent permissions, tool-level policy, and tamper-evident audit across every AWS action.
Yes. AWS Labs publishes a suite of official MCP servers, including ones for AWS documentation, knowledge, S3, Lambda, and serverless. Whichever you run, routing it through the Averta MCP Gateway gives each agent scoped, read-first access with a tamper-evident audit trail.
See Averta OS in action
Book a demo and see how Averta OS secures your AI agents from input to execution.
Book a demo