---
title: "AWS CloudTrail MCP Server: review, setup & limitations · Undominated.ai"
canonical: https://undominated.ai/mcp-servers/awslabs-cloudtrail/
description: "Looks up CloudTrail events and runs CloudTrail Lake queries when configured for the selected account."
---

# AWS CloudTrail MCP Server: review, setup & limitations · Undominated.ai

> Looks up CloudTrail events and runs CloudTrail Lake queries when configured for the selected account.

[← Explore all mcp servers](/mcp-servers/)

CLOUD OPERATIONS / Amazon Web Services

# AWS CloudTrail MCP Server

Looks up CloudTrail events and runs CloudTrail Lake queries when configured for the selected account.

 [See setup guidance ↓](#setup)[Original source ↗](https://github.com/awslabs/mcp/tree/49de7cc11ae064b9224f07ae050c612c3f92dd55/src/cloudtrail-mcp-server)

SOURCE REVIEW

 Reviewed 2026-10-07
 Evidence 2 linked sources
 Publisher Amazon Web Services
 Licence [Apache-2.0 ↗](https://github.com/awslabs/mcp/blob/49de7cc11ae064b9224f07ae050c612c3f92dd55/LICENSE)
 Revision 49de7cc11ae0
 [Read what was—and wasn’t—checked ↓](#review)

“The CloudTrail MCP Server provides specialized tools to address common security and operational scenarios including event lookup, user activity analysis, API call tracking, and advanced CloudTrail Lake analytics.”

 [Amazon Web Services · upstream description ↗](https://github.com/awslabs/mcp/blob/49de7cc11ae064b9224f07ae050c612c3f92dd55/src/cloudtrail-mcp-server/README.md) Our analysis follows below.

01 / THE REASONING

## Why this made the selection.

 - Looks up CloudTrail events and runs CloudTrail Lake queries when configured for the selected account.
- Looking up recorded AWS API activity.

### A good fit for

 - Looking up recorded AWS API activity
- Querying an enabled CloudTrail Lake store for an investigation

### Weigh up before choosing

 - Event-history lookup has a bounded management-event window; missing results do not establish that no event occurred.
- Lake queries require a configured store, suitable permissions and potentially billable query execution.
- The recorded source revision does not pin an unversioned or @latest registry package. No end-to-end MCP setup or authenticated service operation was tested.

02 / THE REVIEW RECORD

## What we actually inspected.

Source review has boundaries. A clear record is more useful than a “safe” badge.

### Material inspected

 - src/cloudtrail-mcp-server/README.md
- LICENSE

### Our findings

 - Event lookup and CloudTrail Lake are distinct capabilities; the README scopes event-history lookup to the recent management-event window.
- CloudTrail Lake needs separate enabled data-store/query prerequisites; an absent result is not evidence no event occurred.
- No event queries, audit records or account permissions were tested.

### Not established by this review

 - The pinned documentation and selected source files were reviewed; the external server was not executed by this review.
- No authenticated service requests, account mutations, tenant access controls, or end-to-end MCP client setup were tested.
- A repository revision does not pin an unversioned or @latest registry package; resolved package provenance and runtime permission enforcement remain unverified.

The review applies to the material and revision named here. A newer upstream release can change its behavior.

03 / PUT IT TO WORK

## Connect a server deliberately.

[Upstream setup instructions ↗](https://github.com/awslabs/mcp/blob/49de7cc11ae064b9224f07ae050c612c3f92dd55/src/cloudtrail-mcp-server/README.md)

DOCUMENTED COMMAND

 uvx awslabs.cloudtrail-mcp-server@latest Copy command ↗

Copying does not execute this command. It may retrieve a newer version than the reviewed source.

 - Register the uvx command.
- Use credentials for the account you mean.

### Before you start

 - uv
- AWS credentials for the service

### Compatibility

Local stdio MCP clients

### Implementation

Python

### Transports

stdio

### Local process, AWS credentials

 - Read permitted CloudTrail event history.
- Start and read CloudTrail Lake queries when an event data store and the necessary permissions are available.

### Cost model

Apache-2.0 server. CloudTrail Lake ingestion/storage/query charges and other AWS usage are separate.

04 / FOLLOW THE EVIDENCE

## The source trail.

Our notes are separate from the original resource. Check upstream before adopting a new version.

 - [Server documentation ↗](https://github.com/awslabs/mcp/blob/49de7cc11ae064b9224f07ae050c612c3f92dd55/src/cloudtrail-mcp-server/README.md) Checked 2026-10-07 https://github.com/awslabs/mcp/blob/49de7cc11ae064b9224f07ae050c612c3f92dd55/src/cloudtrail-mcp-server/README.md Supports: Install command and stated scope
- [Repository licence ↗](https://github.com/awslabs/mcp/blob/49de7cc11ae064b9224f07ae050c612c3f92dd55/LICENSE) Checked 2026-10-07 https://github.com/awslabs/mcp/blob/49de7cc11ae064b9224f07ae050c612c3f92dd55/LICENSE Supports: Redistribution terms

KEEP COMPARING

## Other approaches to consider.

Related by category or shared topics. These are alternatives to inspect, not a measured quality order.

 [### AWS Billing and Cost Management MCP Server ↗ Queries account billing and cost data, with optional analysis workflows that use Athena and S3.](/mcp-servers/awslabs-aws-billing-cost-management/)[### AWS CloudWatch MCP Server ↗ Queries CloudWatch metrics, alarms and log data for the configured AWS account.](/mcp-servers/awslabs-cloudwatch/)[### AWS DynamoDB MCP Server ↗ Supports DynamoDB modeling, source-database analysis, local validation and code generation.](/mcp-servers/awslabs-dynamodb/)

 [AI Tools ↗](/tools/)[Skills ↗](/skills/)[Agents ↗](/agents/)[MCP Servers ↗](/mcp-servers/)[Workflows ↗](/workflows/)

## Continue your investigation

 - [Inspect resource evidence](/tools/)
- [Choose a host](/agents/)
- [Inspect reusable workflows](/skills/)
- [Use Undominated data](/api/)
