mcp-aws-creds
v1.0.1
Published
CLI to replace AWS credentials in an MCP servers JSON file (env-block and header-block styles)
Downloads
27
Readme
mcp-aws-creds
CLI to replace AWS credentials inside an MCP servers JSON file (e.g. .mcp.json)
and/or a .env file, in one shot, across all shapes seen in this repo:
- env-block servers (stdio, e.g.
trans-db-router) and.envfiles:AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY/AWS_SESSION_TOKEN/AWS_REGION - header-block servers (http, e.g.
syscloud-ce,syscloud-awsrds):headers["x-aws-access-key-id"]/x-aws-secret-access-key/x-aws-session-token/x-aws-region
Only fields that already exist are overwritten — the tool never adds new AWS
fields to a server or .env file that doesn't already have them. For .env
files, only real (non-commented) assignment lines are touched; quoting style
and any export prefix are preserved.
Each <file> argument is auto-detected: a basename matching .env, .env.dev,
.env.example, something.env, etc. is treated as an env file; anything else
is parsed as MCP servers JSON.
Install globally
npm linkThis puts mcp-aws-creds on your PATH. Run npm unlink -g mcp-aws-creds to remove it.
Usage
# See which files/servers/fields would be targeted (no secrets shown)
mcp-aws-creds list .mcp.json .env
# Paste credentials interactively (Ctrl+Z then Enter on Windows to finish)
mcp-aws-creds update .mcp.json .env
# Or pipe/paste from a file (e.g. saved from CloudKeeper's "copy" button)
mcp-aws-creds update .mcp.json .env --file creds.txt
# Preview changes without writing
mcp-aws-creds update .mcp.json .env --file creds.txt --dry-run
# Also set region, and (for the JSON file) restrict to specific servers
mcp-aws-creds update .mcp.json .env --file creds.txt --region us-east-1 --only syscloud-ce,syscloud-awsrds
# Update just the .env file
mcp-aws-creds update .env --file creds.txtCredentials are expected in the standard AWS credentials-file format:
[default]
aws_access_key_id = ...
aws_secret_access_key = ...
aws_session_token = ...Parsing is tolerant of the block's newlines being flattened into one line (observed from some clipboard/paste paths) — each field is matched up to wherever the next known field name begins.
By default, a timestamped backup (<file>.bak.<ISO-timestamp>) is written
before the target file is overwritten. Pass --no-backup to skip it.
