S3 Reader MCP Server
Read-only MCP server for browsing and reading S3 objects, with tools for listing buckets/objects, reading text and binary files, and extracting text from PDFs.
README
S3 Reader MCP Server (Streamable HTTP, Cloud Run)
A Model Context Protocol (MCP) server that exposes read-only tools for browsing and reading Amazon S3 objects, served over the streamable-http transport (MCP spec 2025-03-26), ready to deploy on Google Cloud Run.
Tools exposed
| Tool | Description |
|---|---|
list_buckets |
List all S3 buckets visible to the AWS credentials in use |
list_objects |
List/paginate objects in a bucket, with optional prefix/delimiter |
get_object_metadata |
HEAD an object: size, content-type, last-modified, etag |
read_object_text |
Read an object's body as text (size-capped) |
read_object_base64 |
Read an object's raw bytes as base64 (for binary files) |
read_pdf_text |
Extract readable text from a PDF (page-by-page, with page markers) |
The MCP endpoint is served at: POST /mcp (this is the default
streamable_http_path from the SDK).
All tools are read-only — nothing in this server can create, overwrite, or delete S3 data.
1. Local setup
pip install -r requirements.txt
export AWS_ACCESS_KEY_ID=...
export AWS_SECRET_ACCESS_KEY=...
export AWS_REGION=us-east-1
export PORT=8080
python server.py
You should see a log line like:
Starting S3 MCP server on 0.0.0.0:8080 (region=us-east-1)
You can also put these values in a local .env file instead of exporting
them — server.py loads it automatically via python-dotenv. Never commit
.env to source control (it's already excluded in .dockerignore).
2. Test it with MCP Inspector
Before wiring this server up to any AI client, test it directly with the official MCP Inspector — a small web UI that lets you call MCP tools by hand and see the raw request/response. No install needed beyond Node:
npx @modelcontextprotocol/inspector
This opens a local UI (usually at http://localhost:6274). In the
connection panel:
- Transport type:
Streamable HTTP - URL:
http://localhost:8080/mcp(or your Cloud Run URL +/mcponce deployed) - If your deployment requires auth (see step 6 below), add an
Authorization: Bearer <token>header in the Inspector's headers section. - Click Connect, then open the Tools tab — you should see all six
tools listed (
list_buckets,list_objects,get_object_metadata,read_object_text,read_object_base64,read_pdf_text). - Pick a tool, fill in its arguments (e.g.
list_bucketsneeds none;list_objectsneeds abucket), and click Run Tool to see the live result against your actual AWS account.
This is the fastest way to confirm the server is reachable, credentials are working, and each tool's schema/response shape looks right — before you point a real MCP client (Claude, another agent, etc.) at it.
If you'd rather stay on the command line, curl also works for a basic
smoke test:
curl -X POST http://localhost:8080/mcp \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-03-26","capabilities":{},"clientInfo":{"name":"test","version":"1.0"}}}'
3. AWS credentials & permissions
The server uses boto3's standard credential chain (env vars → shared config → IAM role). Grant the identity used at minimum:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": ["s3:ListAllMyBuckets", "s3:ListBucket", "s3:GetObject"],
"Resource": ["arn:aws:s3:::*"]
}
]
}
Scope Resource down to specific bucket ARNs in production.
Recommended for Cloud Run: store AWS credentials in Secret Manager rather than plain environment variables (see step 5 below). If you're running entirely within AWS-adjacent infra, you could alternatively use workload identity federation between GCP and AWS, but the simplest path is an IAM user with an access key stored as a Cloud Run secret.
4. Build and push the container
export PROJECT_ID=your-gcp-project
export REGION=us-central1
export REPO=s3-mcp-server
gcloud auth login
gcloud config set project "$PROJECT_ID"
# One-time: create an Artifact Registry repo
gcloud artifacts repositories create "$REPO" \
--repository-format=docker \
--location="$REGION"
# Build with Cloud Build (no local Docker needed) and push
gcloud builds submit \
--tag "$REGION-docker.pkg.dev/$PROJECT_ID/$REPO/s3-mcp-server:latest"
(Alternatively, build locally with docker build -t ... . and
docker push ... if you have Docker installed and are authenticated to
Artifact Registry via gcloud auth configure-docker.)
5. Store AWS credentials as secrets
printf '%s' "$AWS_ACCESS_KEY_ID" | gcloud secrets create aws-access-key-id --data-file=-
printf '%s' "$AWS_SECRET_ACCESS_KEY" | gcloud secrets create aws-secret-access-key --data-file=-
6. Deploy to Cloud Run
gcloud run deploy s3-mcp-server \
--image "$REGION-docker.pkg.dev/$PROJECT_ID/$REPO/s3-mcp-server:latest" \
--region "$REGION" \
--platform managed \
--port 8080 \
--set-env-vars AWS_REGION=us-east-1 \
--set-secrets AWS_ACCESS_KEY_ID=aws-access-key-id:latest,AWS_SECRET_ACCESS_KEY=aws-secret-access-key:latest \
--min-instances 0 \
--max-instances 5 \
--no-allow-unauthenticated
Notes:
--no-allow-unauthenticatedrequires callers to send a valid Google identity token (Authorization: Bearer <token>). Use--allow-unauthenticatedonly if you're deploying your own auth in front, since this server exposes read access to your S3 data.- Cloud Run injects
PORTautomatically;server.pyreads it viaos.environ["PORT"], so--port 8080above must matchEXPOSE 8080in the Dockerfile and the container's listening port (already aligned). - Because the server is stateless (
stateless_http=True), it's safe for Cloud Run to route consecutive requests to different container instances — no sticky sessions required.
7. Connect an MCP client
Point any MCP client that supports the streamable-http transport (including MCP Inspector — see step 2) at:
https://<your-cloud-run-url>/mcp
If the service requires authentication, include a Google-signed identity token as a bearer token, e.g. for quick manual testing:
TOKEN=$(gcloud auth print-identity-token)
curl -X POST https://<your-cloud-run-url>/mcp \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}'
Files
server.py— MCP server implementation (FastMCP, streamable-http transport)requirements.txt— Python dependenciesDockerfile— container build for Cloud Run.dockerignore— build context excludes
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。