Dynamodb

com.pulsemcpv0.2.7更新於 Sep 29, 2026

MCP server for AWS DynamoDB with fine-grained tool control and configurable access levels.

已驗證STDIO僅桌面Cloud & Infrastructure

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Dynamodb,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

DynamoDB MCP Server

An MCP server for AWS DynamoDB with fine-grained tool control. Provides comprehensive DynamoDB operations with configurable access levels.

Features

  • Complete DynamoDB Operations: Tables, items, queries, scans, and batch operations
  • Fine-grained Access Control: Enable/disable tools by group or individually
  • Table-level Access Control: Restrict operations to specific tables
  • AWS Credential Support: Works with explicit credentials or AWS credential chain
  • Custom Endpoints: Support for local DynamoDB or LocalStack

Available Tools

Tool names are kept short since MCP clients typically prefix them with the server name (e.g., dynamodb:list_tables).

Readonly Tools (Group: readonly)

ToolDescription
list_tablesList all DynamoDB tables with pagination
describe_tableGet table metadata, schema, and indexes
get_itemRetrieve single item by primary key
query_itemsQuery items using key conditions
scan_tableScan table with optional filters
batch_get_itemsGet multiple items across tables

ReadWrite Tools (Group: readwrite)

ToolDescription
put_itemCreate or replace an item
update_itemUpdate specific attributes
delete_itemDelete item by primary key
batch_write_itemsBatch put/delete operations

Admin Tools (Group: admin)

ToolDescription
create_tableCreate a new table
delete_tableDelete a table and all data
update_tableUpdate table settings

Configuration

Environment Variables

VariableRequiredDescription
AWS_REGIONYesAWS region (or AWS_DEFAULT_REGION)
AWS_ACCESS_KEY_IDNoAWS access key (uses credential chain if not set)
AWS_SECRET_ACCESS_KEYNoAWS secret key (uses credential chain if not set)
DYNAMODB_ENDPOINTNoCustom endpoint (for local DynamoDB)
DYNAMODB_ENABLED_TOOL_GROUPSNoComma-separated groups: readonly, readwrite, admin
DYNAMODB_ENABLED_TOOLSNoWhitelist specific tools
DYNAMODB_DISABLED_TOOLSNoBlacklist specific tools
DYNAMODB_ALLOWED_TABLESNoRestrict operations to specific tables (comma-separated)

Tool Access Control

Control which tools are available using three methods:

1. Tool Groups (recommended for most cases):

bash
# Read-only accessDYNAMODB_ENABLED_TOOL_GROUPS="readonly"
# Read and write, no table managementDYNAMODB_ENABLED_TOOL_GROUPS="readonly,readwrite"
# All operations (default)DYNAMODB_ENABLED_TOOL_GROUPS="readonly,readwrite,admin"

2. Whitelist Specific Tools:

bash
# Only allow specific operationsDYNAMODB_ENABLED_TOOLS="get_item,query_items,scan_table"

3. Blacklist Specific Tools:

bash
# Enable all except dangerous operationsDYNAMODB_DISABLED_TOOLS="delete_table,create_table"

Priority: DYNAMODB_ENABLED_TOOLS > DYNAMODB_DISABLED_TOOLS > DYNAMODB_ENABLED_TOOL_GROUPS

Table-level Access Control

Restrict all operations to specific tables only:

bash
# Only allow access to Users and Orders tablesDYNAMODB_ALLOWED_TABLES="Users,Orders"

When DYNAMODB_ALLOWED_TABLES is set:

  • list_tables only returns tables in the allowed list
  • Operations on non-allowed tables return an "Access denied" error
  • Batch operations fail if any table in the request is not allowed
  • Table names are matched case-sensitively (DynamoDB table names are case-sensitive)
  • When using pagination with list_tables, the limit applies before filtering

Note: If not set or set to an empty string, all tables are accessible (no filtering).

This is useful for:

  • Multi-tenant environments where each client should only access their tables
  • Development environments where you want to protect production tables
  • Limiting the blast radius of AI agents to specific tables

Claude Desktop Configuration

Add to your claude_desktop_config.json:

macOS: ~/Library/Application Support/Claude/claude_desktop_config.json Windows: %APPDATA%\Claude\claude_desktop_config.json

json
{  "mcpServers": {    "dynamodb": {      "command": "npx",      "args": ["-y", "aws-dynamodb-mcp-server"],      "env": {        "AWS_REGION": "us-east-1",        "AWS_ACCESS_KEY_ID": "your-access-key",        "AWS_SECRET_ACCESS_KEY": "your-secret-key",        "DYNAMODB_ENABLED_TOOL_GROUPS": "readonly,readwrite"      }    }  }}

Using Local DynamoDB

For development with local DynamoDB or LocalStack:

json
{  "mcpServers": {    "dynamodb-local": {      "command": "npx",      "args": ["-y", "aws-dynamodb-mcp-server"],      "env": {        "AWS_REGION": "us-east-1",        "AWS_ACCESS_KEY_ID": "local",        "AWS_SECRET_ACCESS_KEY": "local",        "DYNAMODB_ENDPOINT": "http://localhost:8000"      }    }  }}

Examples

Query Items

Query all orders for customer "C123" from the last 30 days:- Table: Orders- Key condition: customerId = :cid AND orderDate > :date- Values: {":cid": "C123", ":date": "2025-01-01"}

Create Table

Create a Users table with:- Partition key: userId (String)- Billing: Pay per request

Batch Operations

Get user profiles for IDs: user1, user2, user3 from the Users table

Development

Setup

bash
cd experimental/dynamodbnpm run install-allnpm run build

Testing

bash
# Unit testsnpm run test:run
# Integration testsnpm run test:integration
# Manual tests (requires AWS credentials)npm run test:manual

Resources

ResourceDescription
dynamodb://configServer configuration and tool group mappings

License

MIT

來源:experimental/dynamodb/README.md,提交 0ed34de

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.2.7最新Sep 16, 2026