Skip to main content
AWS cloud operations, regional availability, documentation, skills, file transfer, and sandboxed multi-step API execution through the official AWS MCP Server. Requests are authenticated with encrypted AWS IAM credentials and SigV4. Tilde exposes 9 AWS tools for AI agents through MCP. Connect with AWS IAM credentials.
  • call aws — DEPRECATED: This tool is being deprecated in favor of run_script. Use run_script instead. Execute AWS CLI commands. PRIMARY tool when you know the exact command needed. - Command MUST start with “aws” and follow AWS CLI syntax - For cross-region operations, include —region; for alternate profiles, include —profile - max_results defaults to 100 for paginated operations. Larger values consume more tokens. OMIT for non-paginated ops (get, create, delete). PAGINATION: If response has non-null “pagination_token”, results are INCOMPLETE. Call again with “—starting-token <value>”. ALWAYS paginate through ALL pages before reporting counts or conclusions. MULTI-STEP PATTERNS: Most tasks require list→describe workflows. List operations return only identifiers—always follow with describe/get calls for full details. Never infer from names alone; retrieve and inspect actual data. MULTI-REGION/PROFILE: When a task involves “all regions” or multiple profiles, query EVERY relevant region/profile separately. LOCAL FILE SYSTEM: No filesystem access. Use ’-’ for output file args. No ‘file://’/‘fileb://‘—provide values inline. S3-to-S3 operations (both source and destination are S3 URIs) ARE supported. Command restrictions: NO pipes, shell operators, grep/awk/sed, redirection, command substitution, shell variables, or local file paths. BACKGROUND TASKS: Long-running operations return {task_id, status:“working”}. Poll via get_tasks tool with task_ids=[…]—NOT an aws subcommand. Each task runs once. FILE UPLOAD: Ask user for a staging bucket. Get pre-signed URL via get_presigned_url, upload file, then call call_aws with staging_sources (bucket, key, cli_argument, optional extract). Do NOT include cli_argument flags in cli_command. For directories: zip first (zip-only, max 4GB), use extract:true. For commands with native S3 args (—code S3Bucket=X,S3Key=Y), use those directly—no staging needed. Examples: - aws s3api put-object —bucket my-bucket —key data.bin with staging_sources=[{“bucket”:“staging”,“key”:“data.bin”,“cli_argument”:“—body”}] - aws lambda create-function —function-name F —runtime python3.12 —handler index.handler —role <arn> with staging_sources=[{“bucket”:“staging”,“key”:“func.zip”,“cli_argument”:“—zip-file”}]
  • get presigned url — Generate pre-signed S3 URLs for uploading or downloading files. Use BEFORE call_aws when a command requires a local file path. Use for direct S3 uploads/downloads instead of call_aws. Max upload 5 GB; larger files use multipart via call_aws. For uploads: generates PUT URL. For downloads: generates GET URL. No special headers needed unless s3_params provided—then corresponding HTTP headers MUST be included or request fails with SignatureDoesNotMatch.
  • get tasks — Poll status of long-running tasks. Use after a tool call returns task_id with status “working”. Up to 3 IDs per call. Tasks expire after 5 min. Pass poll_iteration (start at 1, increment each call) and follow the recommended_wait_seconds in the response before polling again.
  • run script — Execute Python code in a sandboxed environment with AWS API access via call_boto3. Top-level await supported. No network access except call_boto3. The response includes an api_calls list summarizing the AWS API calls the script issued (one entry per call: &#123;service, operation, status, n_items?, error?&#125;). Use it to verify which APIs ran, in what order, and that no expected step was silently skipped or swallowed by return_exceptions=True before trusting return_value. python async def call_boto3( *, # only keyword arguments service_name: str, # aws service name, e.g. s3 operation_name: str, # API operation name, e.g. ListBuckets region_name: str | None = None, # Optional. default to the user configured region params: dict | None = None, # Optional. parameters to call the API, default to empty ) -&gt; dict: # returns json dict, datetimes as ISO strings ... ⚠️ FORBIDDEN: getattr, __class__, __dict__, __subclasses__, import boto3, subprocess, HTTP/socket calls. Use isinstance()/hasattr() instead. ⚠️ USE run_script FOR: - 2+ API calls: listing, filtering, counting, parallel calls, multi-step, multi-region - ANY analysis or comparison: configs, policies, tags, properties across resources - Permission checks: gather identity, resource, and trust policies in one script - Streaming APIs (live-tail, subscribe-to-shard) - results auto-capped; inform user if partial. ⚠️ ONE SCRIPT PER TASK: Do NOT split work across multiple run_script calls. If answering the question requires fetching IDs then describing each - do both in one script. Returning intermediate data to “decide the next step” wastes round-trips and inflates the context. Plan the full logic before writing the script. ⚠️ LIST→DESCRIBE IS MANDATORY: List APIs return ONLY names/ARNs. To check ANY attribute: 1. List* → get ALL names 2. Get*/Describe* PER RESOURCE for the attribute 3. Feature-specific APIs are SEPARATE: streams, encryption, lifecycle, metrics often have dedicated Get* APIs NOT in the main Describe. 4. ResourceNotFoundException = “not configured”-valid data, don’t skip ⚠️ CONTENTS vs CONTAINER: “empty buckets” → list objects IN bucket. “records in table” → scan. “X configured” → GetConfiguration API. ⚠️ NEVER TRUNCATE: Check ALL resources. Never \[:10\] or \[:50\]. Missing resource = wrong answer. ⚠️ DISTRUST EMPTY RESULTS: Before reporting “0 found” verify the response had expected keys and no exceptions occurred. If uncertain → “unable to verify” NOT “0 found”. RULES: 1. SELF-CONTAINED: Never paste resource names/ARNs from prior results into code. Discover everything inside the script. 2. OUTPUT: result = &#123;...&#125; then result alone on the last line. Never use print(). 3. CONCURRENCY: Use asyncio.gather(*\[...\]) for parallel calls. Use return_exceptions=True only for read APIs (Describe, List*, Get*). For mutation APIs (Put*, Create*, Delete*, Update*), let exceptions propagate immediately. 4. REGIONS: The user’s default region is used when region_name is not specified. For all-regions: DescribeRegions, iterate ALL. 5. PAGINATION: List/Describe APIs are auto-paginated - do NOT pass limit parameters or loop over tokens manually. Just call the API and all results are returned. Auto-pagination is bypassed only when you explicitly pass the limit key (e.g. MaxResults, Limit, MaxItems) - avoid doing this unless you intentionally want a page. 6. PERMISSIONS: Gather ALL policies in ONE script (identity, resource, trust). ARN bucket ≠ bucket/*. Report YES, PARTIAL, or NO with reasoning. 7. VERIFY API RESPONSE: Confirm the operation returns the field you need. 8. NO COMMENTS: Do not write any comments in the code. 9. FETCH VS JUDGE: Use the script to fetch and structure data. For mechanical tasks (count, filter by exact value, aggregate) encode the logic in the script. For tasks requiring judgment (“misconfigured”, “issues”, “best practices”, “anomalies”) return the relevant raw fields and let the LLM reason. Do not hardcode evaluation heuristics in Python. IMPORTS: The following modules are pre-imported - do not write any import statements: asyncio, collections, csv, dataclasses, datetime, decimal, enum, fractions, functools, itertools, json, math, re, statistics, string, time, typing, uuid, ClientError from botocore, io (StringIO, BytesIO only). Do not re-import. EXAMPLES: Parallel calls: python buckets, funcs = await asyncio.gather( call_boto3(service_name='s3',operation_name='ListBuckets'), call_boto3(service_name='lambda',operation_name='ListFunctions'), return_exceptions=True, ) result = &#123; 'buckets':len(buckets.get('Buckets',\[\])) if isinstance(buckets,dict) else f'ERR:&#123;buckets&#125;', 'functions':len(funcs.get('Functions',\[\])) if isinstance(funcs,dict) else f'ERR:&#123;funcs&#125;'&#125; result Multi-region: python regions = \[r\['RegionName'\] for r in (await call_boto3(service_name='ec2', operation_name='DescribeRegions'))\['Regions'\]\] responses = await asyncio.gather(*\[call_boto3(service_name='ec2', operation_name='DescribeInstances', region_name=r) for r in regions\], return_exceptions=True) result = &#123;r: len(\[i for rv in res.get('Reservations',\[\]) for i in rv\['Instances'\]\]) for r,res in zip(regions,responses) if isinstance(res,dict)&#125; result List→Describe (auto-paginated - no token loop needed): python r = await call_boto3(service_name='dynamodb', operation_name='ListTables') tables = r\['TableNames'\] result = await asyncio.gather(*\[call_boto3(service_name='dynamodb', operation_name='DescribeKinesisStreamingDestination', params=&#123;'TableName': t&#125;) for t in tables\], return_exceptions=True) result
  • get regional availability — AWS resource availability per region. - Max 10 regions; multi-region needs filters; single-region supports next_token. - Status: isAvailableIn | isNotAvailableIn | isPlannedIn | Not Found. - Response key: products | service_apis | cfn_resources. Not for region counts/docs/vague queries — use search_documentation / list_regions. Filter values must EXACTLY match AWS’s catalog names; guessed, partial, or pluralized names are rejected (“values in filter parameter do not exist”). If unsure of the exact name, first call once for a single region with resource_type set and NO filters to list all valid names, then re-call filtering on the exact match.
  • list regions — Retrieve a list of all AWS regions.
  • read documentation — Fetch full AWS doc pages as markdown. search_documentation already returns verbatim page chunks, so don’t re-read a URL whose chunk you already have to “confirm” or “round out” an answer — the chunk is the real page text; treat it as authoritative. Reading the full page is justified ONLY when the chunks genuinely lack the content: - an enumeration or aggregation (“list all X”, “how many X”) needs the complete set and the chunks show only part of it; - no search result is on-topic after refining the query, and a known doc URL would have the answer. Otherwise, answer from the chunks. Use exact URLs from search_documentation; don’t guess slugs. Input: requests: \[&#123;url, max_length?, start_index?&#125;\]. Batch 2-5. - max_length default 10000. - start_index default 0; use prior end_index to continue, TOC offset to jump. Allow-listed prefixes: docs.aws.amazon.com; aws.amazon.com (not /marketplace); repost.aws/knowledge-center; docs.amplify.aws; ui.docs.amplify.aws; github.com/{aws-cloudformation/aws-cloudformation-templates, aws-samples/{aws-cdk-examples, generative-ai-cdk-constructs-samples, serverless-patterns}, awsdocs/aws-cdk-guide, awslabs/aws-solutions-constructs, cdklabs/cdk-nag} (README on main); constructs.dev/packages/{@aws-cdk-containers, @aws-cdk, @cdk-cloudformation, aws-analytics-reference-architecture, aws-cdk-lib, cdk-amazon-chime-resources, cdk-aws-lambda-powertools-layer, cdk-ecr-deployment, cdk-lambda-powertools-python-layer, cdk-serverless-clamscan, cdk8s, cdk8s-plus-33}; strandsagents.com/latest/documentation/docs/. Output: SUCCESS — markdown + total_length, start_index, end_index, truncated, redirected_url? (truncated includes TOC with char ranges). ERROR — error_code in {not_found, invalid_url, throttled, downstream_error, validation_error}.
  • retrieve skill — Retrieve an AWS skill (workflows, references). Returns SKILL.md, or file if given. Call search_documentation FIRST and copy skill_name verbatim — it is an opaque registry ID. Never guess or fabricate skill_name or file.
  • search documentation — AWS docs search. Each result’s context is verbatim page text — a real chunk of the actual page, not a short snippet — and usually already contains the answer, so answer directly from it. Use read_documentation only when the chunks genuinely lack the needed detail. Pick ONE topic. Add a 2nd ONLY if query genuinely spans domains. Extra topics dilute ranking. - reference_documentation — API/SDK/CLI specs, config params - current_awareness — new/released/announced - troubleshooting — errors, “how to fix” (NOT for conceptual/feature questions) - amplify_docs — Amplify (+ language) - cdk_docs — CDK concepts/guides - cdk_constructs — CDK code samples, L3 - cloudformation — CFN/SAM templates - strands_docs — Strands Agents SDK (its Skills/agents concepts go here, NOT agent_skills) - agent_skills — this tool’s guided skills (load via retrieve_skill) - general (default) — architecture, best practices, tutorials, feature behavior Results: rank_order (lower=better), url, title, context (verbatim page chunk — answer directly from it).

Connect AWS to an AI agent

Add AWS from the Tilde dashboard, then enable the tools your agent needs on an MCP server. Learn how tools work in Tilde. Browse every Tilde tool provider or compare Tilde-managed and self-managed authentication.