MCP2Lambda

MCP.Pizza Chef: danilop

Useful only if your team already runs code on AWS Lambda. Point it at your account and each matching function shows up in the chat as its own named tool, using the description you wrote on the function to explain what it does and what to pass it. Nothing has to be rewritten on the AWS side. Access is genuinely fenced: it will only call functions whose names start with a prefix you set or that you list by name. It uses the AWS sign-in already on your computer, and the code has not changed since March 2025.

Unmaintained · No commits in 18 months.
Coding
Data

Use This MCP server To

Ask a question only our internal system can answer Look up a customer record without leaving the chat Run one of our existing AWS functions by asking Reach a private company database through a function Let the assistant work something out on AWS instead of my laptop

README

MCP2Lambda

smithery badge

MCP2Lambda MCP server

Run any AWS Lambda function as a Large Language Model (LLM) tool without code changes using Anthropic's Model Context Protocol (MCP).

graph LR
    A[Model] <--> B[MCP Client]
    B <--> C["MCP2Lambda<br>(MCP Server)"]
    C <--> D[Lambda Function]
    D <--> E[Other AWS Services]
    D <--> F[Internet]
    D <--> G[VPC]
    
    style A fill:#f9f,stroke:#333,stroke-width:2px
    style B fill:#bbf,stroke:#333,stroke-width:2px
    style C fill:#bfb,stroke:#333,stroke-width:4px
    style D fill:#fbb,stroke:#333,stroke-width:2px
    style E fill:#fbf,stroke:#333,stroke-width:2px
    style F fill:#dff,stroke:#333,stroke-width:2px
    style G fill:#ffd,stroke:#333,stroke-width:2px
Loading

This MCP server acts as a bridge between MCP clients and AWS Lambda functions, allowing generative AI models to access and run Lambda functions as tools. This is useful, for example, to access private resources such as internal applications and databases without the need to provide public network access. This approach allows the model to use other AWS services, private networks, and the public internet.

From a security perspective, this approach implements segregation of duties by allowing the model to invoke the Lambda functions but not to access the other AWS services directly. The client only needs AWS credentials to invoke the Lambda functions. The Lambda functions can then interact with other AWS services (using the function role) and access public or private networks.

The MCP server gives access to two tools:

  1. The first tool can autodiscover all Lambda functions in your account that match a prefix or an allowed list of names. This tool shares the names of the functions and their descriptions with the model.

  2. The second tool allows to invoke those Lambda functions by name passing the required parameters.

No code changes are required. You should change these configurations to improve results:

Strategy Selection

The gateway supports two different strategies for handling Lambda functions:

  1. Pre-Discovery Mode (default: enabled): Registers each Lambda function as an individual tool at startup. This provides a more intuitive interface where each function appears as its own named tool.

  2. Generic Mode: Uses two generic tools (list_lambda_functions and invoke_lambda_function) to interact with Lambda functions.

You can control this behavior through:

  • Environment variable: PRE_DISCOVERY=true|false
  • CLI flag: --no-pre-discovery (disables pre-discovery mode)

Example:

MCP2Lambda FAQ

Do I need an AWS account?
Yes, and functions already running in it. This is a doorway to code you have deployed on AWS Lambda, so with nothing deployed there is nothing for it to call.
Do I paste a key anywhere?
No key, but it uses the AWS sign-in already configured on your computer and can reach whatever that sign-in is allowed to reach. Set it up with a restricted account rather than an administrator one.
Can it call anything at all in my AWS account?
No, and this is one of its better features. It only calls functions whose names begin with a prefix you choose, or names you list explicitly. Everything else is refused, and the check really is applied.
How does the assistant know what to send a function?
From the description written on the function itself. A function with a vague description, or none, will be used badly or not at all, so it is worth writing those carefully.
Is anything risky here?
One of the three example functions runs whatever code the assistant writes and installs whatever add-on packages it asks for. It runs inside AWS rather than on your laptop, but only deploy that one if you are comfortable with what it allows.
Does it cost money to run?
The add-on is free, but every call runs a function in your AWS account and shows up on your AWS bill. Individual calls cost very little; a runaway loop does not.
Can I use this to reach an internal database?
Yes, and that is the main reason people use it. The function sits inside your network and does the talking, so nothing internal has to be opened to the public internet.
Is the one-command install enough on its own?
No. The automatic installer passes no account details at all, so your AWS sign-in still has to be configured on the same machine first.
Is the download step in the instructions correct?
No. The manual setup still points at a placeholder address containing the word yourusername rather than the real project, so copy the address from the project page instead.
Is it still maintained?
There have been no changes since March 2025. It is small and it still works, but treat it as finished rather than active.