Skip to content
Cloud InfrastructureClaude Desktop Guide

AWS Security Token Service Claude Desktop Integration

This guide explains how to configure Claude Desktop (Mac and Windows) to use the AWS Security Token Service API through the Model Context Protocol (MCP). The integration exposes 10 API endpointsas callable tools inside Claude's chat interface, including GET_AssumeRole, POST_AssumeRole, GET_AssumeRoleWithSAML, and more. No API keys or credentials are needed — setup takes approximately 30 seconds. The server runs locally via npx and communicates over STDIO transport. Paste the JSON configuration below into your claude_desktop_config.json file to get started.

Integration Specs

ClientClaude Desktop
Runtimenpx
AuthenticationNone
Setup Time~30 sec

Setup Instructions

1

Open Claude Settings

Launch Claude Desktop, open Settings (click your profile) → Developer → click 'Edit Config'.

2

Locate configuration file

This opens your local 'claude_desktop_config.json' file in your system editor.

3

Insert Server Config JSON

Paste the JSON configuration schema block (provided below) into the 'mcpServers' object.

4

Add authentication credentials

No credentials needed; leave the 'env' mapping empty.

5

Restart Claude app

Save the config file and restart Claude Desktop to load your new tools.

Configuration JSON

claude_desktop_config.json

Copy and paste this config snippet inside your local configuration file.

{
  "mcpServers": {
    "amazonaws-com-sts": {
      "command": "npx",
      "args": [
        "-y",
        "@mcp/amazonaws-com-sts"
      ],
      "env": {
        "AWS_SECURITY_TOKEN_SERVICE_API_KEY": "your_aws_security_token_service_api_key"
      }
    }
  }
}

Required Environment Keys

Provide these variable keys in your local environment section:

AWS_SECURITY_TOKEN_SERVICE_API_KEY

Replace your_aws_security_token_service_api_key with your secret key credentials.

Available Tools (10)

These endpoints are parsed from the OpenAPI schema and converted to Claude-compatible tools:

GET/#Action=AssumeRole
GET_AssumeRole
POST/#Action=AssumeRole
POST_AssumeRole
GET/#Action=AssumeRoleWithSAML
GET_AssumeRoleWithSAML
POST/#Action=AssumeRoleWithSAML
POST_AssumeRoleWithSAML
GET/#Action=AssumeRoleWithWebIdentity
GET_AssumeRoleWithWebIdentity
POST/#Action=AssumeRoleWithWebIdentity
POST_AssumeRoleWithWebIdentity
GET/#Action=DecodeAuthorizationMessage
GET_DecodeAuthorizationMessage
POST/#Action=DecodeAuthorizationMessage
POST_DecodeAuthorizationMessage
GET/#Action=GetAccessKeyInfo
GET_GetAccessKeyInfo
POST/#Action=GetAccessKeyInfo
POST_GetAccessKeyInfo