AWS Single Sign-On Claude Desktop Integration
This guide explains how to configure Claude Desktop (Mac and Windows) to use the AWS Single Sign-On API through the Model Context Protocol (MCP). The integration exposes 4 API endpointsas callable tools inside Claude's chat interface, including GetRoleCredentials, ListAccountRoles, ListAccounts, and more. No API keys or credentials are needed — setup takes approximately 30 seconds. The server runs locally via npx and communicates over STDIO transport. Paste the JSON configuration below into your claude_desktop_config.json file to get started.
Integration Specs
Setup Instructions
Open Claude Settings
Launch Claude Desktop, open Settings (click your profile) → Developer → click 'Edit Config'.
Locate configuration file
This opens your local 'claude_desktop_config.json' file in your system editor.
Insert Server Config JSON
Paste the JSON configuration schema block (provided below) into the 'mcpServers' object.
Add authentication credentials
No credentials needed; leave the 'env' mapping empty.
Restart Claude app
Save the config file and restart Claude Desktop to load your new tools.
Configuration JSON
claude_desktop_config.jsonCopy and paste this config snippet inside your local configuration file.
{
"mcpServers": {
"amazonaws-com-sso": {
"command": "npx",
"args": [
"-y",
"@mcp/amazonaws-com-sso"
],
"env": {
"AWS_SINGLE_SIGN_ON_API_KEY": "your_aws_single_sign_on_api_key"
}
}
}
}Required Environment Keys
Provide these variable keys in your local environment section:
AWS_SINGLE_SIGN_ON_API_KEYReplace your_aws_single_sign_on_api_key with your secret key credentials.
Available Tools (4)
These endpoints are parsed from the OpenAPI schema and converted to Claude-compatible tools:
/federation/credentials#role_name&account_id&x-amz-sso_bearer_token/assignment/roles#x-amz-sso_bearer_token&account_id/assignment/accounts#x-amz-sso_bearer_token/logout#x-amz-sso_bearer_token