How to8 min readOctober 4, 2026

How to connect Claude to Amazon S3 with an MCP server

The three ways to give Claude access to files in Amazon S3 through the Model Context Protocol, what each one can do with your bucket, and how to keep an AI agent from reading or deleting more than it should.

JeVaughn Ferguson
Founder, developer
The short version

Any of the three will let Claude read files in S3. The managed AWS MCP Server and local servers act with AWS permissions, so fence them with IAM, ideally with the aws:ViaAWSMCPService condition key. A workspace MCP server like BucketDesk's acts with the permissions of a workspace, scoped to the folders you connected and logged like any other user action, which is usually what non-engineers should get.

Searches for Claude and MCP have grown faster than almost anything else in developer tooling this year, and one of the first things people try is connecting Claude to the files their company keeps in Amazon S3. It works. The question worth answering first is not how to connect, but whose permissions the AI uses once it is connected.

The Model Context Protocol (MCP) is an open standard for giving an AI client a set of tools. Claude Code, Claude Desktop, Cursor, Kiro and others can all call an MCP server, and the server decides what those tools can touch. For S3 there are three realistic options, and they differ mostly in that one respect.

Option 1: the managed AWS MCP Server

AWS runs a remote MCP server at regional endpoints such as https://aws-mcp.us-east-1.api.aws/mcp. Its main tool, call_aws, can run AWS API operations on your behalf, which includes listing buckets, reading objects and generating presigned URLs. AWS recommends it over its older open-source AWS API MCP Server and Knowledge MCP Server.

It signs in either with OAuth in the browser or, for terminal agents that need several accounts, with SigV4 through the MCP Proxy for AWS. Either way the calls run as your own IAM identity, and every call is logged in CloudTrail.

claude mcp add aws-mcp https://aws-mcp.us-east-1.api.aws/mcp --transport http
  • Good for: engineers and admins who already have IAM access and want Claude to help them operate AWS.
  • Watch out for: the agent can do anything your role can, across every service, not just S3.
  • Read-only mode, which hides write-capable tools from the agent, is available with the SigV4 setup.

Put a fence around the agent with IAM

Because the AWS MCP Server acts as you, the guardrail belongs in IAM. AWS added two condition keys for this: aws:ViaAWSMCPService is true when a request arrives through an AWS-managed MCP server, and aws:CalledViaAWSMCP names which one.

That lets you keep your normal permissions in the console while denying the risky ones whenever an agent is driving. The statement below, adapted from the AWS Security Blog, still lets Claude read files but stops it deleting objects or buckets.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "DenyDeleteWhenAccessedViaMCP",
      "Effect": "Deny",
      "Action": ["s3:DeleteObject", "s3:DeleteBucket"],
      "Resource": "*",
      "Condition": { "Bool": { "aws:ViaAWSMCPService": "true" } }
    }
  ]
}
  • Add s3:PutObject and s3:PutBucketPolicy to the deny list if the agent should never write.
  • The deny applies only to the managed AWS servers; a local server using access keys is not covered.

Option 2: a local S3 MCP server

Community S3 MCP servers run on your laptop, usually through Node.js or Python, and expose tools such as list buckets, list objects and read object. AWS's own open-source AWS API MCP Server works the same way and supports a READ_OPERATIONS_ONLY setting.

They are quick to try, but most read AWS credentials from environment variables or a profile on the machine. Whatever those keys can reach, the agent can reach, and the requests look exactly like you in CloudTrail, with no MCP condition key to write a policy against.

  • Good for: a personal sandbox bucket or a quick experiment.
  • Watch out for: long-lived access keys in a config file, and community code you have not reviewed.
  • If you use one, give it a dedicated IAM user or role scoped to a single bucket prefix.

Option 3: an MCP server in front of a file workspace

The first two options give Claude AWS permissions. That suits people who already have them. It is the wrong shape for an operations manager, an accountant or a client-services team, who should see a set of folders, not an AWS account.

BucketDesk's MCP server takes the other approach. It connects at https://app.bucketdesk.com/mcp with a workspace API token, and each tool call goes through the same endpoints, role checks, rate limits and audit events as the BucketDesk app. Claude sees the buckets and folders your workspace has connected, and nothing else in the AWS account.

The tools are list-connections, browse, get-metadata, get-media-metadata, create-share-link, start-archive-job, get-archive-job and ask-document. Tokens are created by a workspace admin, can be read-only or read and write, and expire after 30, 90 or 365 days. There are no delete, upload or restore tools.

claude mcp add --transport http bucketdesk https://app.bucketdesk.com/mcp --header "Authorization: Bearer <token>"
  • Good for: teams that want Claude to find, summarise and share business files without AWS console access.
  • The connection to your bucket is a scoped IAM role you deploy with CloudFormation; no AWS keys are stored.
  • The MCP server and API tokens are part of the Business plan.

Asking a document a question instead of downloading it

The difference shows most when Claude needs to read a document. With the AWS MCP Server or a local server, the agent fetches the object and reads the bytes itself, which works for text and small files and gets awkward for a 200-page PDF.

BucketDesk's ask-document tool sends the question to BucketDesk Document AI, which answers from that one file with a page citation, using an approved model on Amazon Bedrock in your own account. Claude gets the answer and the citation, not the whole file, and a follow-up can continue the same chat.

  • Answers stay scoped to the document you name.
  • Document AI is off by default in the connection template and uses its own role for Bedrock.

Where Amazon Q and Kiro fit

Amazon Q Developer CLI became Kiro CLI in November 2025, and Kiro is an MCP client just like Claude Code. It can load the AWS MCP Server or BucketDesk's server with the same endpoint. The choice of server, not the choice of assistant, decides what your S3 data is exposed to.

Amazon Q Business took a different route, indexing S3 into its own search index rather than calling tools live, and AWS has closed it to new customers. Amazon Quick, its successor, is itself an MCP client.

Which one to choose

Pick by who will be using Claude, not by which setup is shortest.

  • An engineer automating AWS work: the managed AWS MCP Server, with an MCP deny statement on deletes.
  • A one-off experiment on your own bucket: a local server with a single-prefix IAM user.
  • Business users working with company documents: a workspace MCP server that inherits your app's roles and audit log.
Try it in BucketDesk

Starter is free. Deploy a scoped role with CloudFormation, sign in, and browse, without handing anyone an access key.

Connect a bucket

Primary sources

Discussion

0 comments · open to guests · moderated
Comments appear after a quick review.

Liked this? Get the next article by email. No schedule, no filler, one click to leave.

Keep reading

All writing →