Introducing OAuth Support for AWS MCP Server
Security Blog
This article introduces OAuth support for the AWS MCP Server, allowing agents to connect using familiar AWS Sign-In credentials and methods through industry-standard OAuth.
- Agents authenticate via browser-based OAuth with IAM federation, Identity Center, and root/IAM user support
- Interactive authorization for developer agents and non-interactive (headless) authorization for applications without browser access
- Dynamic client registration and OAuth metadata discovery enable automatic agent configuration
- New IAM actions (AuthorizeOAuth2Access, CreateOAuth2Token) and OAuth-specific condition keys govern access
- Token introspection and revocation APIs allow administrators to manage and revoke OAuth tokens
- CloudTrail logs OAuth events including authorization requests, token issuance, and associated sign-in sessions
- Supports agents like Claude Code, Kiro, Codex, and Gemini through Model Context Protocol
OAuth support for AWS MCP Server simplifies secure agent integration while maintaining existing IAM policies, roles, and organizational controls.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.