# AWS Infrastructure as Code MCP server

> Validate CloudFormation templates, check compliance, debug failed deployments and search CDK and CloudFormation documentation.

- Listing: https://mcp.tc/i/aws-iac
- Connect: this is a local (stdio) server; install it on your machine (see Install). The listing link is a page, not an MCP endpoint.
- Type: local (stdio)
- Auth: no API key needed
- Category: [Cloud & DevOps](https://mcp.tc/c/cloud-devops)
- Vendor: Amazon Web Services
- Verified: yes, mcp.tc checked that this is the official server (https://mcp.tc/verify). It says who runs the server, not that it is safe.
- Homepage: <https://awslabs.github.io/mcp/servers/aws-iac-mcp-server>
- Docs: <https://awslabs.github.io/mcp/servers/aws-iac-mcp-server/>
- Repository: <https://github.com/awslabs/mcp/tree/main/src/aws-iac-mcp-server>
- Package: pypi `awslabs.aws-iac-mcp-server`

## About

Works with AWS CloudFormation and the AWS CDK. It validates templates with cfn-lint, checks them against cfn-guard security rules, and analyzes failed stack deployments with CloudTrail deep links. It also searches CloudFormation and CDK documentation, finds CDK code samples and constructs, and returns CDK best practices.

Runs locally over stdio as a Python package started with uvx. No sign-in or API key is needed for validation, compliance checks and documentation tools. Deployment troubleshooting reads your stacks using your local AWS credentials.

## What it can do

- Validate CloudFormation templates with fix suggestions and line numbers
- Check templates against cfn-guard security and compliance rules
- Troubleshoot failed CloudFormation stack deployments
- Search CloudFormation documentation and read full doc pages
- Search CDK documentation, code samples and constructs
- Get CDK best practices and pre-deploy validation instructions

## Example prompts

- "Validate this CloudFormation template and tell me what to fix."
- "Check my template for security and compliance issues."
- "Why did my CloudFormation stack my-app-stack fail in us-east-1?"
- "Find a TypeScript CDK example for an encrypted S3 bucket."

## Install

### Claude Code

1. Run this in a terminal, in your project folder:

```bash
claude mcp add --transport stdio aws-iac -- uvx awslabs.aws-iac-mcp-server@latest
```

2. Start Claude Code and type `/mcp`. **aws-iac** should show as connected.

Add `--scope user` to make it available in every project.

### Claude Desktop

1. Open **Settings → Developer → Edit Config**. It opens `claude_desktop_config.json`. Add:

`claude_desktop_config.json`:

```json
{
  "mcpServers": {
    "aws-iac": {
      "command": "uvx",
      "args": [
        "awslabs.aws-iac-mcp-server@latest"
      ]
    }
  }
}
```

2. Save the file and restart Claude Desktop.

Needs uv (Python) on your computer. The file lives in `~/Library/Application Support/Claude/` on macOS and `%APPDATA%\Claude\` on Windows.

### Cursor

[Add to Cursor](<https://cursor.com/install-mcp?name=aws-iac&config=eyJjb21tYW5kIjoidXZ4IiwiYXJncyI6WyJhd3NsYWJzLmF3cy1pYWMtbWNwLXNlcnZlckBsYXRlc3QiXX0%3D>) (opens Cursor)

Or add it by hand to `~/.cursor/mcp.json` (all projects) or `.cursor/mcp.json` (this project):

`mcp.json`:

```json
{
  "mcpServers": {
    "aws-iac": {
      "command": "uvx",
      "args": [
        "awslabs.aws-iac-mcp-server@latest"
      ]
    }
  }
}
```

Needs uv (Python) on your computer.

### VS Code

[Install in VS Code](<https://vscode.dev/redirect/mcp/install?name=aws-iac&config=%7B%22type%22%3A%22stdio%22%2C%22command%22%3A%22uvx%22%2C%22args%22%3A%5B%22awslabs.aws-iac-mcp-server%40latest%22%5D%7D>) (opens VS Code)

Or from a terminal:

```bash
code --add-mcp '{"name":"aws-iac","type":"stdio","command":"uvx","args":["awslabs.aws-iac-mcp-server@latest"]}'
```

Or commit it to the repo in `.vscode/mcp.json`:

`.vscode/mcp.json`:

```json
{
  "servers": {
    "aws-iac": {
      "type": "stdio",
      "command": "uvx",
      "args": [
        "awslabs.aws-iac-mcp-server@latest"
      ]
    }
  }
}
```

Needs uv (Python) on your computer.

### Devin Desktop

1. Add it to `~/.config/devin/mcp_config.json` (macOS and Linux) or `%APPDATA%\devin\mcp_config.json` (Windows):

`mcp_config.json`:

```json
{
  "mcpServers": {
    "aws-iac": {
      "command": "uvx",
      "args": [
        "awslabs.aws-iac-mcp-server@latest"
      ]
    }
  }
}
```

2. Refresh the MCP server list in Cascade.

Devin Desktop is the new name for Windsurf.

### Codex

```bash
codex mcp add aws-iac -- uvx awslabs.aws-iac-mcp-server@latest
```

Or edit `~/.codex/config.toml` directly:

`config.toml`:

```toml
[mcp_servers.aws-iac]
command = "uvx"
args = ["awslabs.aws-iac-mcp-server@latest"]
```

Needs uv (Python) on your computer.

### Gemini CLI

```bash
gemini mcp add aws-iac uvx awslabs.aws-iac-mcp-server@latest
```

This adds it to the current project. Add `-s user` to use it everywhere.

### Any client

Most clients that start local servers accept this shape:

```json
{
  "mcpServers": {
    "aws-iac": {
      "command": "uvx",
      "args": [
        "awslabs.aws-iac-mcp-server@latest"
      ]
    }
  }
}
```

Zed puts servers under `context_servers` in its settings, with the same `command`, `args` and `env` fields.

Needs uv (Python) on your computer.

## Details

- Server version: 1.0.26
- Last checked: 2026-10-03
- Listed: 2026-10-03
- Updated: 2026-10-03

---
Source: https://mcp.tc/i/aws-iac (mcp.tc is an independent directory, not affiliated with this server's publisher). Corrections: https://mcp.tc/report
