How to connect Claude to Amazon S3 with an MCP server
The three ways to give Claude access to files in Amazon S3 through the Model Context Protocol, what each one can do with your bucket, and how to keep an AI agent from reading or deleting more than it should.
Any of the three will let Claude read files in S3. The managed AWS MCP Server and local servers act with AWS permissions, so fence them with IAM, ideally with the aws:ViaAWSMCPService condition key. A workspace MCP server like BucketDesk's acts with the permissions of a workspace, scoped to the folders you connected and logged like any other user action, which is usually what non-engineers should get.
Searches for Claude and MCP have grown faster than almost anything else in developer tooling this year, and one of the first things people try is connecting Claude to the files their company keeps in Amazon S3. It works. The question worth answering first is not how to connect, but whose permissions the AI uses once it is connected.
The Model Context Protocol (MCP) is an open standard for giving an AI client a set of tools. Claude Code, Claude Desktop, Cursor, Kiro and others can all call an MCP server, and the server decides what those tools can touch. For S3 there are three realistic options, and they differ mostly in that one respect.
Option 1: the managed AWS MCP Server
AWS runs a remote MCP server at regional endpoints such as https://aws-mcp.us-east-1.api.aws/mcp. Its main tool, call_aws, can run AWS API operations on your behalf, which includes listing buckets, reading objects and generating presigned URLs. AWS recommends it over its older open-source AWS API MCP Server and Knowledge MCP Server.
It signs in either with OAuth in the browser or, for terminal agents that need several accounts, with SigV4 through the MCP Proxy for AWS. Either way the calls run as your own IAM identity, and every call is logged in CloudTrail.
claude mcp add aws-mcp https://aws-mcp.us-east-1.api.aws/mcp --transport httpS3 bucket policy examples for team file access
- Good for: engineers and admins who already have IAM access and want Claude to help them operate AWS.
- Watch out for: the agent can do anything your role can, across every service, not just S3.
- Read-only mode, which hides write-capable tools from the agent, is available with the SigV4 setup.
Put a fence around the agent with IAM
Because the AWS MCP Server acts as you, the guardrail belongs in IAM. AWS added two condition keys for this: aws:ViaAWSMCPService is true when a request arrives through an AWS-managed MCP server, and aws:CalledViaAWSMCP names which one.
That lets you keep your normal permissions in the console while denying the risky ones whenever an agent is driving. The statement below, adapted from the AWS Security Blog, still lets Claude read files but stops it deleting objects or buckets.
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "DenyDeleteWhenAccessedViaMCP",
"Effect": "Deny",
"Action": ["s3:DeleteObject", "s3:DeleteBucket"],
"Resource": "*",
"Condition": { "Bool": { "aws:ViaAWSMCPService": "true" } }
}
]
}Amazon S3 encryption at rest: SSE-S3 vs SSE-KMS
- Add s3:PutObject and s3:PutBucketPolicy to the deny list if the agent should never write.
- The deny applies only to the managed AWS servers; a local server using access keys is not covered.
Option 2: a local S3 MCP server
Community S3 MCP servers run on your laptop, usually through Node.js or Python, and expose tools such as list buckets, list objects and read object. AWS's own open-source AWS API MCP Server works the same way and supports a READ_OPERATIONS_ONLY setting.
They are quick to try, but most read AWS credentials from environment variables or a profile on the machine. Whatever those keys can reach, the agent can reach, and the requests look exactly like you in CloudTrail, with no MCP condition key to write a policy against.
- Good for: a personal sandbox bucket or a quick experiment.
- Watch out for: long-lived access keys in a config file, and community code you have not reviewed.
- If you use one, give it a dedicated IAM user or role scoped to a single bucket prefix.
Option 3: an MCP server in front of a file workspace
The first two options give Claude AWS permissions. That suits people who already have them. It is the wrong shape for an operations manager, an accountant or a client-services team, who should see a set of folders, not an AWS account.
BucketDesk's MCP server takes the other approach. It connects at https://app.bucketdesk.com/mcp with a workspace API token, and each tool call goes through the same endpoints, role checks, rate limits and audit events as the BucketDesk app. Claude sees the buckets and folders your workspace has connected, and nothing else in the AWS account.
The tools are list-connections, browse, get-metadata, get-media-metadata, create-share-link, start-archive-job, get-archive-job and ask-document. Tokens are created by a workspace admin, can be read-only or read and write, and expire after 30, 90 or 365 days. There are no delete, upload or restore tools.
claude mcp add --transport http bucketdesk https://app.bucketdesk.com/mcp --header "Authorization: Bearer <token>"Secure AWS access with IAM roles and external IDsAutomation, agents and the approval boundary
- Good for: teams that want Claude to find, summarise and share business files without AWS console access.
- The connection to your bucket is a scoped IAM role you deploy with CloudFormation; no AWS keys are stored.
- The MCP server and API tokens are part of the Business plan.
Asking a document a question instead of downloading it
The difference shows most when Claude needs to read a document. With the AWS MCP Server or a local server, the agent fetches the object and reads the bytes itself, which works for text and small files and gets awkward for a 200-page PDF.
BucketDesk's ask-document tool sends the question to BucketDesk Document AI, which answers from that one file with a page citation, using an approved model on Amazon Bedrock in your own account. Claude gets the answer and the citation, not the whole file, and a follow-up can continue the same chat.
Ask questions about S3 documents with Claude on Amazon BedrockAmazon Bedrock Knowledge Bases on S3 vs asking one document
- Answers stay scoped to the document you name.
- Document AI is off by default in the connection template and uses its own role for Bedrock.
Where Amazon Q and Kiro fit
Amazon Q Developer CLI became Kiro CLI in November 2025, and Kiro is an MCP client just like Claude Code. It can load the AWS MCP Server or BucketDesk's server with the same endpoint. The choice of server, not the choice of assistant, decides what your S3 data is exposed to.
Amazon Q Business took a different route, indexing S3 into its own search index rather than calling tools live, and AWS has closed it to new customers. Amazon Quick, its successor, is itself an MCP client.
Which one to choose
Pick by who will be using Claude, not by which setup is shortest.
- An engineer automating AWS work: the managed AWS MCP Server, with an MCP deny statement on deletes.
- A one-off experiment on your own bucket: a local server with a single-prefix IAM user.
- Business users working with company documents: a workspace MCP server that inherits your app's roles and audit log.
Starter is free. Deploy a scoped role with CloudFormation, sign in, and browse, without handing anyone an access key.
Primary sources
Discussion
0 comments · open to guests · moderatedLiked this? Get the next article by email. No schedule, no filler, one click to leave.