Skip to content
Cloud InfrastructureClaude Desktop Guide

AWS SecurityHub Claude Desktop Integration

This guide explains how to configure Claude Desktop (Mac and Windows) to use the AWS SecurityHub API through the Model Context Protocol (MCP). The integration exposes 10 API endpointsas callable tools inside Claude's chat interface, including GetAdministratorAccount, AcceptAdministratorInvitation, GetMasterAccount, and more. No API keys or credentials are needed — setup takes approximately 30 seconds. The server runs locally via npx and communicates over STDIO transport. Paste the JSON configuration below into your claude_desktop_config.json file to get started.

Integration Specs

ClientClaude Desktop
Runtimenpx
AuthenticationNone
Setup Time~30 sec

Setup Instructions

1

Open Claude Settings

Launch Claude Desktop, open Settings (click your profile) → Developer → click 'Edit Config'.

2

Locate configuration file

This opens your local 'claude_desktop_config.json' file in your system editor.

3

Insert Server Config JSON

Paste the JSON configuration schema block (provided below) into the 'mcpServers' object.

4

Add authentication credentials

No credentials needed; leave the 'env' mapping empty.

5

Restart Claude app

Save the config file and restart Claude Desktop to load your new tools.

Configuration JSON

claude_desktop_config.json

Copy and paste this config snippet inside your local configuration file.

{
  "mcpServers": {
    "amazonaws-com-securityhub": {
      "command": "npx",
      "args": [
        "-y",
        "@mcp/amazonaws-com-securityhub"
      ],
      "env": {
        "AWS_SECURITYHUB_API_KEY": "your_aws_securityhub_api_key"
      }
    }
  }
}

Required Environment Keys

Provide these variable keys in your local environment section:

AWS_SECURITYHUB_API_KEY

Replace your_aws_securityhub_api_key with your secret key credentials.

Available Tools (10)

These endpoints are parsed from the OpenAPI schema and converted to Claude-compatible tools:

GET/administrator
GetAdministratorAccount
POST/administrator
AcceptAdministratorInvitation
GET/master
GetMasterAccount
POST/master
AcceptInvitation
POST/standards/deregister
BatchDisableStandards
POST/standards/register
BatchEnableStandards
POST/securityControls/batchGet
BatchGetSecurityControls
POST/associations/batchGet
BatchGetStandardsControlAssociations
POST/findings/import
BatchImportFindings
PATCH/findings/batchupdate
BatchUpdateFindings