Skip to content
CommunicationQuality Score: 46/99 (Fair)No Auth RequiredSpec v2014-03-28auto GenerationTransport: stdio

Amazon CloudWatch LogsMCP Configuration & Schema Registry

The Amazon CloudWatch Logs Model Context Protocol (MCP) configuration provides a validated, machine-readable JSON schema and executable bridge that connects state-of-the-art AI coding assistants — including Claude Desktop, Cursor IDE, Windsurf, Cline, and VS Code Copilot — directly to the Amazon CloudWatch Logs REST API. By leveraging the standardized open Model Context Protocol, AI agents can dynamically discover capabilities, validate input parameters against strict JSON Schemas, and execute live API operations without context switching or manual copy-pasting.

Quick Specs & Integration Summary

1. Functionality:Exposes 10 API endpoints as callable AI tools for Amazon CloudWatch Logs.
2. Authentication:Zero authentication required — ready for immediate execution.
3. Protocol Layer:Standard Model Context Protocol JSON-RPC 2.0 via stdio transport.
4. Quick Launch:npx -y @modelcontextprotocol/server-openapi https://api.apis.guru/v2/specs/amazonaws.com/logs/2014-03-28/openapi.json

Technical Architecture & Protocol Semantics

Under the Model Context Protocol specification, the Amazon CloudWatch Logs configuration functions as an isolated protocol adapter. When an AI agent initializes a session, the client establishes a bidirectional JSON-RPC 2.0 communication channel over standard input/output (stdio) or Server-Sent Events (SSE). During the initial handshake, the server publishes its tool manifest extracted from the Amazon CloudWatch Logs OpenAPI specification (version 2014-03-28).

Amazon CloudWatch Logs is a fully managed service provided by Amazon Web Services (AWS) designed for centralizing, monitoring, and analyzing log data at any scale. Its core capabilities enable developers and DevOps teams to ingest log files from a multitude of sources, including Amazon EC2 instances, AWS CloudTrail for API activity auditing, Lambda functions, and various on-premises servers. The service acts as a durable, scalable repository that allows for real-time monitoring of logs and the setting of metric filters to trigger alarms or operational actions based on specific log patterns. Typical enterprise use cases include security and compliance monitoring through centralized audit trails, application performance analysis by correlating logs with metrics, and operational troubleshooting by creating a single pane of glass for all application and infrastructure logs across complex, distributed microservices architectures. When exposed as tools via the Model Context Protocol (MCP) to an AI coding assistant, the CloudWatch Logs API unlocks powerful, context-aware automation for developers. Instead of manually navigating the AWS Console or crafting CLI commands, the developer can instruct the AI agent to perform complex log management tasks conversationally. The AI can directly invoke API actions to create and organize log groups and streams, making it an invaluable partner for setting up new application environments or services. Furthermore, it can programmatically manage log lifecycle and security, such as associating encryption keys (KMS) with sensitive log groups or deleting obsolete log data. This transforms the AI from a code generator into an active operational teammate capable of interacting with and modifying the cloud environment to support the development workflow. Practical workflow examples demonstrate significant efficiency gains. A developer can instruct the AI agent: "Analyze the recent error patterns in the 'production-api' log group by querying the last 500 error log events." The agent would use the API to filter and retrieve the relevant logs, then summarize the findings. For infrastructure automation, a command like "Set up a new log group and stream for my 'auth-service' debug logs, and apply the standard KMS encryption key" would trigger the agent to sequentially call `CreateLogGroup`, `CreateLogStream`, and `AssociateKmsKey` with the correct parameters. Another dynamic task would be: "Create a metric filter that tracks 'TimeoutException' errors in the 'payment-service' log group and output the metric to CloudWatch under the 'ServiceHealth' namespace," which automates the creation of operational monitoring with a single instruction. Critical configuration and security practices are paramount when deploying this API via an MCP server. Although the authentication method for the underlying AWS calls is handled by AWS IAM (not "None" at the service level), the MCP server itself acts as a conduit and must be secured. Developers must configure the MCP server with IAM credentials that adhere strictly to the principle of least privilege. The associated IAM role or user should be granted only the specific CloudWatch Logs permissions necessary for its intended tasks, such as `logs:CreateLogGroup`, `logs:FilterLogEvents`, and `logs:PutMetricFilter`, while explicitly denying more dangerous actions like broad deletion unless absolutely required. Furthermore, network access to the MCP server should be restricted, and all log data, especially if it contains sensitive information, must be encrypted in transit and at rest using customer-managed KMS keys as referenced in the API. Regular auditing of the permissions and activity logs of the IAM principal is essential to maintain a secure posture. This architecture guarantees strict process boundary isolation: all sensitive authorization headers and secret tokens remain sandboxed inside the client runtime, never leaking into language model context windows or external logging endpoints.

Authentication TypePublic (No Auth)Injected via local client environment
Tools & Routes Mapped10 OperationsConforms to JSON-RPC 2.0 specs
Specification OriginOpenAPI v2014-03-28auto schema validation
Documentation & Schema Quality Index
46
★ Grade C - Baseline Coverage
Automated Audit Checklist
Automated schema extraction & validation (+12 pts)
Extensive tool mapping (10 endpoints defined) (+20 pts)
Zero-configuration public API instant execution (+20 pts)
Full JSON-RPC 2.0 Model Context Protocol specification conformity (+15 pts)
Upstream technical documentation verification (+12 pts)

Hosted Remote Configuration URL

MCP Configuration File

Provide this hosted URL in any client that supports remote MCP schema auto-loading.

https://mcpbridge.org/config/amazonaws-com-logs.json

2. AI Assistant Use Cases & Practical Workflows

Tailored for Communication

Real-world execution scenarios demonstrating how LLM agents (Claude 3.7, GPT-4o, Cursor Agent) invoke Amazon CloudWatch Logs tools to automate developer workflows.

1. Automated Incident Escalation & Notification Routing

Incident Comms

Broadcast priority notifications with rich incident context, system health metrics, and on-call engineer assignment details.

Example Natural Language Prompt:

"Dispatch a high-priority incident notification via Amazon CloudWatch Logs containing the latest stack trace, affected microservice names, and link to the active monitoring dashboard."

Mapped: /#X-Amz-Target=Logs_20140328.AssociateKmsKey

2. Knowledge Base & Workspace Documentation Sync

Knowledge Sync

Synchronize newly merged pull request documentation and architectural decision records into searchable workspace hubs.

Example Natural Language Prompt:

"Fetch updated technical notes from our repository and sync them into Amazon CloudWatch Logs. Ensure headers, code blocks, and parameter tables are correctly formatted in markdown."

Mapped: /#X-Amz-Target=Logs_20140328.CancelExportTask

3. Omnichannel Customer Ticket Triaging & Sentiment Analysis

Support Automation

Classify incoming customer inquiry tickets, detect customer sentiment urgency, and auto-draft contextual solution proposals.

Example Natural Language Prompt:

"Retrieve open customer support tickets from Amazon CloudWatch Logs. Classify urgency based on customer sentiment and generate drafted reply outlines for Tier-2 engineering review."

Autonomous Agent Loop

4. Scheduled Webhook Dispatch & Event Orchestration

Event Orchestration

Automate event notification triggers when deployments complete, staging builds pass, or schema changes are detected.

Example Natural Language Prompt:

"Configure an event notification hook in Amazon CloudWatch Logs to trigger Slack updates whenever a high-severity deployment event is logged in staging."

Autonomous Agent Loop

End-to-End Multi-Step Agent Execution Lifecycle

When an engineer submits a task to Claude Desktop or Cursor, the LLM executes an autonomous 4-phase Model Context Protocol loop:

Phase 1

Schema Introspection

Handshake lists all 10 tools and builds argument validators.

Phase 2

Argument Synthesis

Model extracts parameters from prompt and validates types against OpenAPI rules.

Phase 3

Stdio Execution

Bridge invokes live API with injected local credentials and captures raw HTTP response.

Phase 4

Output Remediation

LLM parses JSON results, handles status codes, and presents synthesized answers.

3. Multi-Client Installation Matrix & Setup Guides

Select your AI assistant below to view exact configuration file paths, JSON installation snippets, and launch commands.

Claude Desktop

claude_desktop_config.json
macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
Windows: %APPDATA%\Claude\claude_desktop_config.json
Linux: ~/.config/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "amazonaws-com-logs": {
      "command": "npx",
      "args": [
        "-y",
        "@modelcontextprotocol/server-openapi",
        "https://api.apis.guru/v2/specs/amazonaws.com/logs/2014-03-28/openapi.json"
      ],
      "env": {
        "AMAZON_CLOUDWATCH_LOGS_API_KEY": "your_amazon_cloudwatch_logs_api_key"
      }
    }
  }
}
Deep link

Cursor IDE

.cursor/mcp.json

Open Cursor Settings → Features → MCP Servers, or create .cursor/mcp.json in your project root.

{
  "mcpServers": {
    "amazonaws-com-logs": {
      "command": "npx",
      "args": [
        "-y",
        "@modelcontextprotocol/server-openapi",
        "https://api.apis.guru/v2/specs/amazonaws.com/logs/2014-03-28/openapi.json"
      ],
      "env": {
        "AMAZON_CLOUDWATCH_LOGS_API_KEY": "your_amazon_cloudwatch_logs_api_key"
      }
    }
  }
}

Saves as .cursor/mcp.json in the download. Move it to your project root.

Deep link install →

VS Code / Cline Extension

cline_mcp_settings.json

Paste into your Cline extension MCP configuration or Roo Code host settings.

{
  "mcpServers": {
    "amazonaws-com-logs": {
      "command": "npx",
      "args": [
        "-y",
        "@modelcontextprotocol/server-openapi",
        "https://api.apis.guru/v2/specs/amazonaws.com/logs/2014-03-28/openapi.json"
      ],
      "env": {
        "AMAZON_CLOUDWATCH_LOGS_API_KEY": "your_amazon_cloudwatch_logs_api_key"
      }
    }
  }
}

Zed Editor & Docker CLI

Zed / Docker

Docker container execution command:

docker run -i --rm -e AMAZON_CLOUDWATCH_LOGS_API_KEY="YOUR_SECRET_VALUE" node:20-alpine npx -y @modelcontextprotocol/server-openapi https://api.apis.guru/v2/specs/amazonaws.com/logs/2014-03-28/openapi.json

Zed settings context servers JSON:

{
  "context_servers": {
    "amazonaws-com-logs": {
      "command": {
        "path": "npx",
        "args": [
          "-y",
          "@modelcontextprotocol/server-openapi",
          "https://api.apis.guru/v2/specs/amazonaws.com/logs/2014-03-28/openapi.json"
        ],
        "env": {
          "AMAZON_CLOUDWATCH_LOGS_API_KEY": "your_amazon_cloudwatch_logs_api_key"
        }
      }
    }
  }
}

Programmatic SDK Integration (TypeScript / Python)

Initialize the Amazon CloudWatch Logs MCP client directly in your backend codebase.

import { Client } from "@modelcontextprotocol/sdk/client/index.js";
import { StdioClientTransport } from "@modelcontextprotocol/sdk/client/stdio.js";

// Initialize Amazon CloudWatch Logs MCP client transport over stdio
const transport = new StdioClientTransport({
  command: "npx",
  args: ["-y","@modelcontextprotocol/server-openapi","https://api.apis.guru/v2/specs/amazonaws.com/logs/2014-03-28/openapi.json"],
  env: { AMAZON_CLOUDWATCH_LOGS_API_KEY: process.env.AMAZON_CLOUDWATCH_LOGS_API_KEY || "YOUR_SECRET_KEY" }
});

const client = new Client(
  { name: "amazonaws-com-logs-client", version: "1.0.0" },
  { capabilities: { tools: {}, resources: {}, prompts: {} } }
);

async function connectAndRun() {
  await client.connect(transport);
  const tools = await client.listTools();
  console.log("Connected to Amazon CloudWatch Logs MCP Server.");
  console.log("Discovered 10 mapped tools:", tools);
}

connectAndRun().catch(console.error);

Raw Stdio Schema Definition

schema.json

For standalone CLI wrappers, background daemon daemons, or custom script integrations:

{
  "mcpServers": {
    "amazonaws-com-logs": {
      "command": "npx",
      "args": [
        "-y",
        "@modelcontextprotocol/server-openapi",
        "https://api.apis.guru/v2/specs/amazonaws.com/logs/2014-03-28/openapi.json"
      ],
      "env": {
        "AMAZON_CLOUDWATCH_LOGS_API_KEY": "your_amazon_cloudwatch_logs_api_key"
      }
    }
  }
}

4. Security, Authentication & Credential Management

Safely configure authentication tokens, isolate execution environments, and implement enterprise security best practices.

Required Environment Keys Reference

Variable NameRequiredTypeDefaultPurpose & Guidance
AMAZON_CLOUDWATCH_LOGS_API_KEYREQUIREDSecret Key / TokenNone (Set in env)your_amazon_cloudwatch_logs_api_key

Zero-Downtime Token Rotation Protocol

  1. Generate Secondary Key: Create a new secret API token with identical scopes in your Amazon CloudWatch Logs developer portal.
  2. Update Client Configuration: Insert the new token inside the env block of your MCP client JSON config.
  3. Validate Connection: Issue a test query in Claude or Cursor to ensure handshake and tool calls succeed.
  4. Revoke Stale Token: Decommission the legacy key on the vendor portal to prevent unauthorized access.

Least-Privilege & Sandboxing Rules

  • Read-Only Token Scoping: Whenever your workflow only requires querying data, provision read-only credentials to prevent accidental mutations.
  • Local Process Isolation: Stdio transports run in isolated local subprocesses; secret credentials are never sent across the internet to MCP Bridge servers.
  • Prompt Injection Defense: AI model responses are sandboxed; verify generated destructive arguments before confirming execution in agent mode.

Enterprise Security Checklist (Mandatory Practices)

  • Never commit claude_desktop_config.json or .cursor/mcp.json containing raw secrets into public GitHub repositories.
  • Add .cursor/mcp.json and .env.local to your project's .gitignore file.
  • Always enforce TLS/HTTPS encryption on outbound network requests initiated by the server process.

5. Tool Parameter Schemas & Natural Language Execution

Mapped OpenAPI operations converted into discrete Model Context Protocol tools with strict JSON-RPC payload validators.

10 Total Tools Mapped
POST/#X-Amz-Target=Logs_20140328.AssociateKmsKey
tools/call: amazonaws-com-logs_post_X_Amz_Target_Logs_20140328_AssociateKmsKey

AssociateKmsKey

Zero required query/path parameters for this endpoint.
JSON-RPC 2.0 Request Payload
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "amazonaws-com-logs_post_X_Amz_Target_Logs_20140328_AssociateKmsKey",
    "arguments": {}
  }
}
Natural Language Prompt

"Use Amazon CloudWatch Logs to execute AssociateKmsKey and output the formatted result."

POST/#X-Amz-Target=Logs_20140328.CancelExportTask
tools/call: amazonaws-com-logs_post_X_Amz_Target_Logs_20140328_CancelExportTask

CancelExportTask

Zero required query/path parameters for this endpoint.
JSON-RPC 2.0 Request Payload
{
  "jsonrpc": "2.0",
  "id": 2,
  "method": "tools/call",
  "params": {
    "name": "amazonaws-com-logs_post_X_Amz_Target_Logs_20140328_CancelExportTask",
    "arguments": {}
  }
}
Natural Language Prompt

"Use Amazon CloudWatch Logs to execute CancelExportTask and output the formatted result."

POST/#X-Amz-Target=Logs_20140328.CreateExportTask
tools/call: amazonaws-com-logs_post_X_Amz_Target_Logs_20140328_CreateExportTask

CreateExportTask

Zero required query/path parameters for this endpoint.
JSON-RPC 2.0 Request Payload
{
  "jsonrpc": "2.0",
  "id": 3,
  "method": "tools/call",
  "params": {
    "name": "amazonaws-com-logs_post_X_Amz_Target_Logs_20140328_CreateExportTask",
    "arguments": {}
  }
}
Natural Language Prompt

"Use Amazon CloudWatch Logs to execute CreateExportTask and output the formatted result."

POST/#X-Amz-Target=Logs_20140328.CreateLogGroup
tools/call: amazonaws-com-logs_post_X_Amz_Target_Logs_20140328_CreateLogGroup

CreateLogGroup

Zero required query/path parameters for this endpoint.
JSON-RPC 2.0 Request Payload
{
  "jsonrpc": "2.0",
  "id": 4,
  "method": "tools/call",
  "params": {
    "name": "amazonaws-com-logs_post_X_Amz_Target_Logs_20140328_CreateLogGroup",
    "arguments": {}
  }
}
Natural Language Prompt

"Use Amazon CloudWatch Logs to execute CreateLogGroup and output the formatted result."

POST/#X-Amz-Target=Logs_20140328.CreateLogStream
tools/call: amazonaws-com-logs_post_X_Amz_Target_Logs_20140328_CreateLogStream

CreateLogStream

Zero required query/path parameters for this endpoint.
JSON-RPC 2.0 Request Payload
{
  "jsonrpc": "2.0",
  "id": 5,
  "method": "tools/call",
  "params": {
    "name": "amazonaws-com-logs_post_X_Amz_Target_Logs_20140328_CreateLogStream",
    "arguments": {}
  }
}
Natural Language Prompt

"Use Amazon CloudWatch Logs to execute CreateLogStream and output the formatted result."

POST/#X-Amz-Target=Logs_20140328.DeleteDataProtectionPolicy
tools/call: amazonaws-com-logs_post_X_Amz_Target_Logs_20140328_DeleteDataProtectionPolicy

DeleteDataProtectionPolicy

Zero required query/path parameters for this endpoint.
JSON-RPC 2.0 Request Payload
{
  "jsonrpc": "2.0",
  "id": 6,
  "method": "tools/call",
  "params": {
    "name": "amazonaws-com-logs_post_X_Amz_Target_Logs_20140328_DeleteDataProtectionPolicy",
    "arguments": {}
  }
}
Natural Language Prompt

"Use Amazon CloudWatch Logs to execute DeleteDataProtectionPolicy and output the formatted result."

POST/#X-Amz-Target=Logs_20140328.DeleteDestination
tools/call: amazonaws-com-logs_post_X_Amz_Target_Logs_20140328_DeleteDestination

DeleteDestination

Zero required query/path parameters for this endpoint.
JSON-RPC 2.0 Request Payload
{
  "jsonrpc": "2.0",
  "id": 7,
  "method": "tools/call",
  "params": {
    "name": "amazonaws-com-logs_post_X_Amz_Target_Logs_20140328_DeleteDestination",
    "arguments": {}
  }
}
Natural Language Prompt

"Use Amazon CloudWatch Logs to execute DeleteDestination and output the formatted result."

POST/#X-Amz-Target=Logs_20140328.DeleteLogGroup
tools/call: amazonaws-com-logs_post_X_Amz_Target_Logs_20140328_DeleteLogGroup

DeleteLogGroup

Zero required query/path parameters for this endpoint.
JSON-RPC 2.0 Request Payload
{
  "jsonrpc": "2.0",
  "id": 8,
  "method": "tools/call",
  "params": {
    "name": "amazonaws-com-logs_post_X_Amz_Target_Logs_20140328_DeleteLogGroup",
    "arguments": {}
  }
}
Natural Language Prompt

"Use Amazon CloudWatch Logs to execute DeleteLogGroup and output the formatted result."

6. Interactive Troubleshooting & FAQ Accordion

Diagnose and resolve common JSON-RPC protocol error codes, connection disconnects, and schema refresh issues.

A 401 Unauthorized response indicates that the upstream Amazon CloudWatch Logs API rejected the authentication credential supplied in your MCP client's environment configuration. To resolve this: (1) Verify that your secret token is defined inside the "env" block of claude_desktop_config.json or .cursor/mcp.json rather than hardcoded in the command string. (2) Check whether Amazon CloudWatch Logs requires a prefix such as "Bearer <token>" in the authorization header. (3) Confirm that your API key has not expired and has been granted sufficient least-privilege scopes on the Amazon CloudWatch Logs developer dashboard.

If your MCP client fails to initialize tools for Amazon CloudWatch Logs: (1) Test the bridge launcher command ("npx -y @modelcontextprotocol/server-openapi https://api.apis.guru/v2/specs/amazonaws.com/logs/2014-03-28/openapi.json") directly inside your terminal or shell to inspect stdout/stderr diagnostic traces. (2) Verify network connectivity to the schema source (https://api.apis.guru/v2/specs/amazonaws.com/logs/2014-03-28/openapi.json). (3) Ensure Node.js (v18+) is installed and accessible in your system PATH. (4) For authenticated APIs, confirm credentials are configured in your client's "env" mapping rather than command arguments.

Similar Communication Configurations

Explore related API bridges with ready-to-use Model Context Protocol schemas.

Slack API

Communication

Send messages, manage channels, and integrate Slack notifications into your AI agent workflows.

https://mcpbridge.org/config/slack.json

Discord API

Communication

Send messages, manage servers, and integrate Discord bots into your AI agent workflows.

https://mcpbridge.org/config/discord.json

Twilio API

Communication

Send SMS, make calls, and manage communication channels through your AI agent.

https://mcpbridge.org/config/twilio.json

Email Activity (beta)

Communication

The Email Activity (beta) API, provided by [Your Email Service Provider], is a specialized suite of endpoints designed to grant programmatic access to granular email event data and system security configurations. Its core capability revolves around detailed filtering and search across two primary domains: user engagement events (like opens, clicks, and bounces) and security/access control settings. While the event data functionality is limited to a recent two-day window by default, it serves as a powerful tool for real-time monitoring and immediate post-campaign analysis. Typical use cases for enterprise teams include building internal dashboards for marketing performance, automating alerts for campaign anomalies (e.g., a sudden spike in bounces), and developing custom reporting pipelines that feed into business intelligence systems. The associated security endpoints—managing an access whitelist and configuring alert notifications—provide critical administrative control, allowing teams to programmatically define which IP addresses or systems can interact with their email infrastructure and to set up proactive monitoring for potential security or deliverability issues. When exposed as tools to an AI coding assistant via the Model Context Protocol (MCP), the value of the Email Activity API shifts from simple data retrieval to enabling intelligent, context-aware automation and synthesis. An AI agent, such as Claude Desktop or an IDE-integrated assistant, can leverage these endpoints not just to fetch data, but to perform complex reasoning on the results. For instance, instead of a developer manually querying for all "bounce" events, they can instruct the AI to "analyze the last 24 hours of bounce data, group them by recipient domain, and draft an alert for the ops team if the failure rate for our primary domain exceeds 1%." The AI can dynamically combine data from the activity endpoint with the current security whitelist via the `/access_settings/whitelist` endpoint to audit configurations, generating suggestions like "I noticed the marketing automation server's IP is not whitelisted, which may be causing the recent campaign sends to fail. Should I add it?" Practical workflow examples showcase the transformative potential of this integration. A developer can instruct the AI agent to perform dynamic tasks such as: "Query the `/alerts` endpoint, review the current conditions for our 'high bounce rate' alert, and suggest a more sensitive threshold based on the bounce data from the last hour, then propose the corresponding API call to update it." Alternatively, an agent could be tasked to "Audit our security posture by fetching the current whitelist, cross-reference it with recent access logs (if available through a separate log endpoint), and flag any IP addresses that have made numerous requests but are not currently whitelisted, recommending whether to create a new whitelist rule." This allows the AI to act as an operational analyst, continuously monitoring system state and suggesting or implementing administrative actions based on real-time data streams. Critical implementation considerations begin with the "None" authentication method indicated for this beta API, which is a significant security red flag. Developers must assume this is a placeholder or error and seek alternative, robust authentication (like OAuth 2.0 or API key via a secure header) as soon as the API matures. Until then, any integration must treat the endpoints as highly sensitive and be restricted to non-production, sandboxed environments only. When setting up the MCP server, adherence to the principle of least privilege is paramount: the API keys or tokens used should be scoped exclusively to the narrow set of email activity and security endpoints required for the specific workflow, with no unnecessary read/write permissions. Configuration should ensure all API calls are made over TLS, and any locally cached email event data must be treated as confidential, encrypted at rest and in transit to prevent exposure of sensitive user engagement information. Developers must also build in robust error handling for rate limits and the inherent instability of beta endpoints, designing their AI-driven workflows to gracefully manage changes in the API schema without failure.

https://mcpbridge.org/config/sendgrid-com.json