Skip to content

Connect Amazon Web Services to ChatGPT: Audit IAM and Security Risks

Uday Gajavalli Uday Gajavalli 9 min read AI & Agents
Elaichi from the team behind Truto

Amazon Web Services in ChatGPT, in about a minute.

The best way to connect Amazon Web Services to ChatGPT is Elaichi: connect Amazon Web Services to Elaichi once, then add Elaichi to ChatGPT as a connector. Two steps, about a minute, with a 14‑day free trial and no credit card required.

  • No credit card required
  • 500+ connectors
  • Credentials vaulted, never read back
  1. Start your free trial

    14 days free, no credit card required.

  2. Connect Amazon Web Services

    Once, in Elaichi. ChatGPT never gets more access than you have.

  3. Add Elaichi to ChatGPT

    In ChatGPT, open Plugins, press +, and paste the URL into Server URL. Sign in and approve.

    https://api.elaichi.ai/mcp
TrutoFor product teams

Building Amazon Web Services into your own product? This guide is for you.

Connect AWS to ChatGPT using Truto's MCP servers to automate IAM audits and triage Security Hub alerts. This guide covers server creation, rate limits, and zero-code security workflows.

The developer guide

Learn how to securely connect Amazon Web Services to ChatGPT using Truto's managed MCP servers to audit IAM, triage security findings, and automate cloud ops.

If you need to connect Amazon Web Services (AWS) to ChatGPT to automate cloud security posture management, audit IAM privileges, or triage Security Hub alerts, you need a Model Context Protocol (MCP) server. This server acts as the translation layer between ChatGPT's JSON-RPC tool calls and the sprawling, multi-dialect reality of the AWS API.

If your team uses Claude, check out our guide on connecting Amazon Web Services to Claude or explore our broader architectural overview on connecting Amazon Web Services to AI Agents.

Giving a Large Language Model (LLM) read and write access to an AWS environment is a massive engineering and security challenge. You have to handle fragmented pagination schemas, XML-to-JSON inconsistencies, region-sharded endpoints, and highly sensitive IAM boundaries. Every time AWS introduces a new security service or changes a payload structure, a custom integration requires manual code updates.

This guide breaks down exactly how to use Truto to generate a secure, managed MCP server for AWS, connect it natively to ChatGPT, and execute complex security and IAM audit workflows using natural language.

The Engineering Reality of the AWS API

Building a custom MCP server for AWS means owning the entire API lifecycle. While the open MCP standard provides a predictable way for LLMs to discover tools, implementing it against AWS is exceptionally painful. AWS is not a single API - it is a collection of hundreds of independent services built over two decades, each with its own quirks and design patterns.

If you build this layer yourself, here are the specific integration challenges you must solve:

Fragmentation of Pagination Dialects

Unlike modern SaaS platforms that standardize on cursor-based pagination, AWS uses multiple pagination dialects. EC2 and Security Hub use NextToken and MaxResults. S3 uses Marker, NextMarker, and MaxKeys. Some legacy XML APIs use PageSize and IsTruncated. Your MCP server must abstract these dialects into a unified pagination model (like standard limit and next_cursor fields) so the LLM does not have to guess which pagination token to pass back on subsequent calls. Truto handles this normalization automatically.

The "404 as Data" Paradigm

In standard REST APIs, a 404 Not Found or a 403 Forbidden usually indicates an integration failure or a bad identifier. In AWS security services, they often represent valid posture data. For example, querying GuardDuty or Inspector in a region where it is not enabled returns an InvalidAccessException (HTTP 401) or a 404. That is not an error - it means "this security control is disabled here." Your MCP tools must catch these specific exceptions and surface them as clean "not configured" states to the LLM, rather than crashing the agent's execution loop.

Region Sharding and Blind Spots

Many AWS APIs are strictly regional. If you query EC2 security groups or Security Hub findings in us-east-1, you learn nothing about eu-west-2. To answer a prompt like "Are there any public S3 buckets in my account?", an LLM cannot just call DescribeBuckets once. The server logic (or the LLM itself) must first sweep DescribeRegions to discover active regions, then fan out calls to every region. Exposing raw AWS endpoints directly to an LLM often results in hallucinations where the agent assumes one region's data represents the entire account.

Inconsistent Data Encodings

AWS payloads often require undocumented decoding steps. For example, IAM policy documents returned by GetAccountAuthorizationDetails are URL-encoded (RFC 3986) and must be decoded before parsing. However, Organizations Service Control Policies (SCPs) returned by DescribePolicy are plain JSON and must never be URL-decoded. If your MCP server applies the IAM decoding logic to an SCP, it mangles the payload.

AWS to ChatGPT Quickstart Guide

If you want the fastest path to connecting ChatGPT to your AWS account without building custom infrastructure, follow these steps.

What you need:

  • A Truto account with API access.
  • AWS IAM credentials (Access Key ID and Secret Access Key) for an IAM user or role with the appropriate ReadOnlyAccess or SecurityAudit permissions.
  • A ChatGPT Pro, Plus, Business, Enterprise, or Education seat with Developer mode enabled.

Step 1: Connect AWS as an Integrated Account

First, connect AWS to your Truto environment. Navigate to Integrated Accounts -> New Integrated Account in the Truto dashboard, select Amazon Web Services, and provide the IAM credentials. Truto securely vaults these credentials and handles the request signing (SigV4) for all subsequent API calls.

Grab your integrated_account_id. You can copy it from the Truto UI or list it via the API:

curl https://api.truto.one/integrated-account \
  -H "Authorization: Bearer $TRUTO_API_TOKEN"

Step 2: Generate an AWS MCP Server

Next, generate an MCP server scoped specifically to that AWS account. You can do this via the UI or the API.

Method A: Via the Truto UI

  1. Navigate to the Integrated Account page for your AWS connection.
  2. Click the MCP Servers tab.
  3. Click Create MCP Server.
  4. Configure the server (e.g., set Methods to read to ensure read-only access).
  5. Copy the generated MCP Server URL.

Method B: Via the API Make a POST request to generate the server dynamically. We will filter the methods to read to ensure ChatGPT cannot accidentally delete AWS resources:

curl -X POST https://api.truto.one/integrated-account/$INTEGRATED_ACCOUNT_ID/mcp \
  -H "Authorization: Bearer $TRUTO_API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "AWS Security Audit",
    "config": {
      "methods": ["read"],
      "tags": ["iam", "securityhub", "config"]
    }
  }'

The response includes a url (e.g., https://api.truto.one/mcp/a1b2c3d4e5f6...). This URL contains a hashed cryptographic token that handles routing and authentication. Keep it secret.

Step 3: Connect the MCP Server to ChatGPT

Now, tell ChatGPT to use this server.

Method A: Via the ChatGPT UI

  1. In ChatGPT, go to Settings -> Apps -> Advanced settings.
  2. Enable Developer mode.
  3. Under MCP servers, click Add new server.
  4. Name it "AWS Security".
  5. Paste the Truto MCP URL into the Server URL field and click Save.

Method B: Via Manual Config File (for local/CLI agents) If you are running a local MCP client or an agent framework that uses the standard config file approach, add the Truto endpoint using the SSE transport:

{
  "mcpServers": {
    "aws-security": {
      "command": "npx",
      "args": [
        "-y",
        "@modelcontextprotocol/server-sse",
        "--url",
        "https://api.truto.one/mcp/a1b2c3d4e5f6..."
      ]
    }
  }
}

ChatGPT will immediately handshake with the server, negotiate capabilities, and ingest the AWS tool schemas.

Hero Tools for Cloud Security Audits

Truto exposes the AWS API surface as highly optimized, LLM-ready tools. We inject automatic context into descriptions (e.g., "Always send back exactly the cursor value you received") to prevent agent hallucinations.

Here are five high-leverage hero tools for auditing IAM and security risks.

1. Account Authorization Details (list_all_amazon_web_services_iam_account_authorization_details)

This is the master IAM collector. Instead of making separate calls to list users, groups, roles, and inline policies, this single tool performs a sweeping collection of the entire IAM posture. It returns full policy documents (automatically URL-decoded by Truto), attached managed policies, and permission boundaries.

"Fetch the complete IAM authorization details for this account and list any user that has an inline policy granting full administrative access (*:*)."

2. Access Key Last Used (get_single_amazon_web_services_iam_access_key_last_used_by_id)

AWS access keys never expire structurally. To find stale credentials, an agent must retrieve the key IDs and then call this tool to find out when and where the key was last used. It is the only reliable signal for identifying abandoned long-term credentials.

"Take this list of active access keys and check when each one was last used. Flag any key that hasn't been used in the last 90 days."

3. Security Hub Findings (list_all_amazon_web_services_securityhub_findings)

This tool lists ASFF (AWS Security Finding Format) findings. It supports server-side time filters and handles AWS's strict 100-item maximum result cap. Truto ensures that archived findings (which vanish after 3 days if marked NOT_APPLICABLE) are properly surfaced if requested.

"Query the active Security Hub findings in us-east-1 and summarize all CRITICAL alerts related to unauthorized API calls."

4. S3 Public Access Block (list_all_amazon_web_services_s_3_bucket_public_access_block)

Determining S3 exposure requires checking the bucket-level Block Public Access (BPA) configuration. If this tool returns a 404 (handled cleanly by Truto), it means BPA is not configured. The agent can read the specific flags (IgnorePublicAcls, RestrictPublicBuckets) to determine true exposure.

"Check the public access block configuration for the 'production-assets-2026' bucket. Is IgnorePublicAcls enabled?"

5. Config Rule Compliance (list_all_amazon_web_services_config_rule_compliance)

Retrieves the pass/fail compliance status for AWS Config rules in a specific region. It returns the raw COMPLIANT, NON_COMPLIANT, or INSUFFICIENT_DATA states along with resource counts, allowing the LLM to quickly identify failing infrastructure controls.

"List the compliance status for all AWS Config rules. Identify any rules currently reporting as NON_COMPLIANT and list the affected resource counts."

To view the complete inventory of AWS tools, schemas, and required parameters, visit the Amazon Web Services integration page.

Workflows in Action

When ChatGPT is equipped with Truto's AWS MCP server, you can orchestrate complex security audits just by asking.

Scenario 1: Hunting for Stale IAM Administrators

Security teams frequently need to audit IAM users to find abandoned accounts with high privileges.

"Find all IAM users in the account. For each user, check their attached policies to see if they have AdministratorAccess. If they do, check the last time their access keys were used and list any admin who hasn't used their keys in over 90 days."

How the agent executes this:

  1. Calls list_all_amazon_web_services_iam_users to get the list of active users.
  2. Calls list_all_amazon_web_services_iam_attached_user_policies for each user to identify attachments of AdministratorAccess.
  3. Calls list_all_amazon_web_services_iam_access_keys for the identified admins to get their key IDs.
  4. Calls get_single_amazon_web_services_iam_access_key_last_used_by_id to retrieve the usage timestamps.
  5. Evaluates the dates locally and outputs a formatted markdown table of stale admins.

Scenario 2: Triaging Network Exposure

Auditing EC2 Security Groups manually across regions is tedious. An agent can automate the mapping of stateful network rules.

"Sweep us-east-1 and us-west-2 for all EC2 Security Groups. Identify any groups that allow inbound ingress from 0.0.0.0/0 on port 22 (SSH) or port 3389 (RDP). Format the result as a markdown table with the Group ID, VPC ID, and the offending port."

sequenceDiagram
  participant User as User
  participant ChatGPT as ChatGPT
  participant Truto as Truto MCP
  participant AWS as AWS API

  User->>ChatGPT: "Sweep us-east-1 and us-west-2 for open SSH/RDP ports..."
  ChatGPT->>Truto: Call tool: list_all_amazon_web_services_ec_2_security_groups (region: us-east-1)
  Truto->>AWS: DescribeSecurityGroups (us-east-1)
  AWS-->>Truto: JSON Array (Group Data)
  Truto-->>ChatGPT: Flattened JSON Schema response
  ChatGPT->>Truto: Call tool: list_all_amazon_web_services_ec_2_security_groups (region: us-west-2)
  Truto->>AWS: DescribeSecurityGroups (us-west-2)
  AWS-->>Truto: JSON Array (Group Data)
  Truto-->>ChatGPT: Flattened JSON Schema response
  ChatGPT->>User: Renders markdown table of offending groups

How the agent executes this:

  1. Calls list_all_amazon_web_services_ec_2_security_groups passing region: "us-east-1".
  2. Calls the same tool passing region: "us-west-2".
  3. Parses the ipPermissions arrays in the response payloads to look for -1 protocols or specific fromPort/toPort matches against 0.0.0.0/0.
  4. Renders the final table to the user.

Rate Limits and Retries

When querying AWS heavily (especially via multi-region fanning or recursive IAM lookups), you will eventually hit AWS's throttling limits (e.g., ThrottlingException).

Truto is designed as a transparent integration layer. Truto does not retry, throttle, or apply backoff on rate limit errors. When the upstream AWS API returns an HTTP 429 (Too Many Requests), Truto passes that error directly back to the caller. Truto normalizes the upstream rate limit information into standardized HTTP headers (ratelimit-limit, ratelimit-remaining, ratelimit-reset) per the IETF specification.

Your MCP client, LLM framework, or agent orchestrator is entirely responsible for detecting these 429 errors and implementing exponential backoff and retry logic.

Security and Access Control

Exposing an AWS environment to an LLM requires strict boundary controls. Truto MCP servers provide native, infrastructure-level constraints so you never have to rely solely on LLM prompt instructions for safety.

  • Method Filtering: Constrain servers to read-only access. By setting methods: ["read"] during server creation, Truto physically strips out all create, update, and delete tools. The LLM cannot accidentally terminate an EC2 instance because the tool simply does not exist.
  • Tag Filtering: Scope access by business domain. Setting tags: ["iam"] ensures the server only exposes tools related to identity and access management, completely hiding S3, EC2, or RDS resources.
  • Authentication Gates: By default, the cryptographically secure MCP URL is sufficient for access. If you enable require_api_token_auth: true, the client must also pass a valid Truto API token in the Authorization header, adding a second layer of identity verification.
  • Time-to-Live (TTL): For temporary audits, set an expires_at ISO datetime. Truto will automatically clean up the underlying token and KV entries at that exact moment, instantly severing the LLM's access to AWS.

Automate AWS Audits Today

Connecting ChatGPT to Amazon Web Services using a custom integration requires handling complex XML/JSON mappings, parsing disparate pagination schemas, and manually maintaining hundreds of tool definitions. Truto abstracts this completely, deriving MCP tools dynamically from the API documentation and providing a clean, LLM-ready JSON-RPC interface.

By generating a Truto MCP server, you can give your AI agents secure, scoped, and highly actionable access to your AWS security posture in minutes.

Two ways to put Amazon Web Services to work

Elaichifrom the team behind Truto

For you and your team

Use Amazon Web Services in ChatGPT yourself

Connect Amazon Web Services once, add Elaichi to ChatGPT, and ask. Every call is checked against your own permissions and logged.

Start free, 14 days No credit card required
Truto

For product teams

Ship Amazon Web Services to your customers

Your customers connect their own Amazon Web Services accounts. Your product gets one API and MCP tools for Amazon Web Services, through Truto.

FAQ

What is the easiest way to connect Amazon Web Services to ChatGPT?
The best way to connect Amazon Web Services to ChatGPT is Elaichi: connect Amazon Web Services to Elaichi once, then add Elaichi to ChatGPT as a connector. Two steps, about a minute, with a 14-day free trial and no credit card required.
How does Truto handle AWS API rate limits?
Truto does not retry or absorb rate limits. When AWS returns a 429, Truto passes it directly to the caller while normalizing rate limit headers (ratelimit-limit, ratelimit-remaining, ratelimit-reset). The caller is responsible for retries.
Can I restrict ChatGPT to read-only access in AWS?
Yes. When generating the Truto MCP server, you can configure method filtering by setting `methods: ["read"]`. This ensures the server only exposes tools for GET and LIST operations, preventing any modifications.
Does Truto support multi-region AWS API calls?
Yes. Tools that query regional resources (like EC2 or Security Hub) expose a region parameter in their query schema, allowing the LLM to fan out requests to specific regions as needed.
Amazon Web Services Amazon Web Services in ChatGPT14 days free Start free

More from our Blog