Skip to content
cloud infrastructureMCP Integration Directory

AWS CloudTrail MCP Server Integration

AWS CloudTrail is a foundational security, governance, and compliance service provided by Amazon Web Services that enables comprehensive monitoring and auditing of API activity across an AWS account or organization. The CloudTrail API provides programmatic access to create, configure, and manage trails, event data stores, channels, and advanced event selectors that capture detailed logs of AWS Management Console actions, AWS CLI commands, SDK operations, and service-to-service API calls. At its core, the service delivers an immutable, chronological record of every action taken within your cloud environment, including the identity of the caller, the time of the call, the source IP address, the request parameters, and the response elements returned by the AWS service. Enterprise use cases span regulatory compliance (supporting frameworks such as SOC, HIPAA, PCI DSS, and GDPR), forensic investigation and incident response, operational troubleshooting, and governance of multi-account or multi-region AWS Organizations. Organizations rely on CloudTrail to answer critical security questions: Who accessed a sensitive S3 bucket? Was a security group rule modified after hours? Which IAM role was assumed by an external service? The API surface includes operations such as CreateTrail and DeleteTrail for lifecycle management of log destinations, CreateEventDataStore for advanced, long-term event storage powered by Lake Foundation, AddTags and DeleteResourcePolicy for organization and access governance, CreateChannel and DeleteChannel for forwarding events to third-party destinations, and CancelQuery for interrupting running analytical queries against stored events.

Technical Integration & Multi-Client Support

The AWS CloudTrail MCP Integration translates REST paths, operational endpoints, and tool schemas into standardized Model Context Protocol JSON-RPC 2.0 messages. This allows AI assistants like Claude Desktop, Cursor IDE, VS Code (Cline/Roo Code), and Zed Editor to run tool queries and execute functions seamlessly.

Claude Desktop

Add stdio configuration block to claude_desktop_config.json.

Cursor IDE

Configure workspace root at .cursor/mcp.json or Settings -> MCP.

VS Code / Cline

Insert server JSON payload into cline_mcp_settings.json.

Specification & Compatibility Table

PropertySpecification Detail
Target IntegrationAWS CloudTrail (amazonaws-com-cloudtrail)
Directory Categorycloud infrastructure
Protocol SpecJSON-RPC 2.0 (stdio)
Canonical Path/mcp/amazonaws-com-cloudtrail/

Frequently Asked Questions

How do I access the full JSON configuration for AWS CloudTrail?

Click 'Open Full AWS CloudTrail MCP Config' above to view the complete parameter schema, environment variable setup, and copy-pasteable JSON configs for Claude Desktop, Cursor, and VS Code.

Does AWS CloudTrail require authentication secrets?

Authentication depends on upstream API requirements. Check the environment variable table on the detail page to view required API keys and header tokens.

Related Integrations

Browse by Category

Explore MCP server integrations organized by platform and use case.

Developer Tools Integrations (15+)
AI & ML Integrations (15+)
Data & Analytics Integrations (15+)
Cloud Infrastructure Integrations (15+)
Communication Integrations (15+)
Finance & Payments Integrations (15+)
Design & Creative Integrations (15+)
Productivity Integrations (15+)
Databases Integrations (15+)
Security Integrations (15+)
Browser Automation Integrations (6+)
Automation Integrations (6+)