
cloudtrail-mcp-server
This AWS Labs Model Context Protocol (MCP) server for CloudTrail enables your AI agents to query AWS account activity for security investigations, compliance auditing, and operational troubleshooting.
Discovery Score
53/100
8,799 stars
1,457 forks
The Open Source Drop Lens
Connects your AI assistant to AWS CloudTrail, giving you access to API activity logs across your AWS account. You can search for specific API calls, investigate who changed a resource, and audit access patterns. Essential for security investigations and debugging "who did what."
The MCP server is free and open source. CloudTrail's first management trail is free. Data event logging and CloudTrail Lake queries have per-event costs. Setup is standard AWS credentials with CloudTrail read permissions.
Maintained by AWS Labs. Excellent for incident response and security audits. When something breaks in production and you need to know which API call caused it, asking your AI assistant beats scrolling through the CloudTrail console.
Cost Breakdown
## Free Tier The MCP server itself is completely free and open source.
## Self-Hosted Runs locally or on your own infrastructure.
## Paid No paid tier. The underlying AWS service may have its own pricing.
Free and open source. The underlying AWS service may have its own costs.
Get tools like this every Wednesday
One featured tool, three on the radar. No fluff.