Guide · AI assistants

Connect AI assistants to local AWS with MCP

Goku includes an MCP server for AWS that runs on your machine. Claude Code, Claude Desktop, Cursor, VS Code, Windsurf and other MCP clients can use it to create resources, call any AWS API, read logs, take snapshots and inject faults in a local sandbox. Nothing reaches your real AWS account.

Updated 28 September 2026 · Goku 4.1.0 · goku CLI 0.5.0 · Free, no AWS account

Goku was formerly called Mimir. Same product, new name: the image is now tanujsoni027/goku (it was tanujsoni027/mimir-aws) and the command is goku. See old and new names.

On this page: What it does · Install · Connect · Ask · Tools · aws_call · Security · FAQ

A sandbox, not your account

What Goku's MCP server does

The Model Context Protocol (MCP) is how AI assistants call tools. Goku serves it at http://localhost:8080/mcp, on the console's port, over Streamable HTTP, with 25 tools: Goku's own, and aws_call, which calls any operation of the emulated AWS services.

An assistant holding your AWS credentials can run up costs or delete something real. With Goku it works on a sandbox instead:

Step 1

Install Goku and the goku CLI

goku CLI 0.5.0 adds goku mcp, the bridge most clients start. On macOS and Linux:

terminal
$ curl -fsSL https://tanuj24.github.io/goku/install.sh | sh

On Windows, in PowerShell:

PowerShell
PS> irm https://tanuj24.github.io/goku/install.ps1 | iex

Already installed? Run goku update --cli and goku update: the MCP server needs Goku 4.1 or later. More options are on the install page.

Step 2

Connect your assistant

Clients that start a command run goku mcp, which bridges stdio to the endpoint and starts Goku if it isn't running. Clients that take a URL connect to http://localhost:8080/mcp; nothing starts Goku over HTTP, so run goku start first.

Claude Code

terminal
$ claude mcp add goku -- goku mcp

Add --scope user for every project. Or over HTTP:

terminal
$ claude mcp add --transport http goku http://localhost:8080/mcp

To share it with your team, commit a .mcp.json:

.mcp.json
{
  "mcpServers": {
    "goku": { "type": "http", "url": "http://localhost:8080/mcp" }
  }
}

Claude Desktop

Add Goku to claude_desktop_config.json (macOS: ~/Library/Application Support/Claude/, Windows: %APPDATA%\Claude\), then restart Claude Desktop:

claude_desktop_config.json
{
  "mcpServers": {
    "goku": { "command": "goku", "args": ["mcp"] }
  }
}

Desktop apps don't see your shell's PATH: goku mcp config claude-desktop prints this entry with the full path of goku.

Cursor

In ~/.cursor/mcp.json (all projects) or .cursor/mcp.json (one project):

.cursor/mcp.json
{
  "mcpServers": {
    "goku": { "url": "http://localhost:8080/mcp" }
  }
}

With the goku CLI instead: { "command": "goku", "args": ["mcp"] }.

VS Code

In .vscode/mcp.json:

.vscode/mcp.json
{
  "servers": {
    "goku": { "type": "http", "url": "http://localhost:8080/mcp" }
  }
}

With the goku CLI instead: { "type": "stdio", "command": "goku", "args": ["mcp"] }.

Windsurf and every other client

goku mcp config prints each client's setup and the file it goes in:

terminal
$ goku mcp config          # Claude Code, Claude Desktop, Cursor, VS Code and Windsurf
goku mcp config windsurf   # or claude-code, claude-desktop, cursor, vscode

Windsurf's file is ~/.codeium/windsurf/mcp_config.json. Other clients take the URL (Streamable HTTP) or goku mcp (stdio). The console's MCP page, http://localhost:8080/ai-assistants, shows the same setup.

Step 3

Ask for what you need

Ask in plain language. From the console's Things to ask:

Tools

The 25 tools

Goku's tools start with goku_; the AWS tools reach every emulated service.

Goku and servicesgoku_status goku_services_list goku_service_subscribe goku_service_unsubscribe goku_service_delete goku_load_sample_dataVersion and health, services and their subscriptions, and sample data.
Resource Centergoku_resources goku_leftoversEvery container Goku runs, with CPU, memory and idle time, and what older versions left behind.
CloudWatch Logsgoku_logs_groups goku_logs_eventsLog groups and their newest events, with a filter pattern and a start time such as 15m.
Environment snapshotsgoku_snapshot_list goku_snapshot_save goku_snapshot_restore goku_snapshot_resetList, save and restore the whole environment, or reset services to empty.
Fault injectiongoku_chaos_list goku_chaos_add goku_chaos_remove goku_chaos_clearErrors, latency, timeouts, dropped or duplicated messages and Lambda cold starts.
IAMgoku_iam_simulate goku_iam_effective_accessWhether a role or user may act on a resource and why, and all it can do.
Journeys and linksgoku_journeys_recent goku_console_urlRequests followed across services with the hop that failed, and console links.
AWSaws_list_services aws_list_operations aws_callThe emulated services, their operations and whether Goku implements them, and any call.

Tool hints such as readOnlyHint and destructiveHint let clients that confirm destructive actions ask before aws_call, goku_service_delete, goku_snapshot_restore, goku_snapshot_reset, goku_chaos_remove and goku_chaos_clear.

Any AWS API

How aws_call works

aws_call sends any operation of an emulated service with the AWS SDK for JavaScript v3. The assistant passes the service, operation and input as JSON:

aws_call input
{
  "service": "dynamodb",
  "operation": "PutItem",
  "input": {
    "TableName": "orders",
    "Item": { "id": { "S": "o-1" }, "total": { "N": "42" } }
  }
}
Security

Security, and turning it off

The endpoint gives full access to your local Goku without a confirmation step, so it only answers requests from your machine:

Settings, on the Goku container:

For example, docker run -e GOKU_MCP=off … starts Goku without it. goku doctor says whether the endpoint answers.

FAQ

Frequently asked questions

Which AI assistants can connect to Goku?

Claude Code, Claude Desktop, Cursor, VS Code, Windsurf and any other MCP client: over Streamable HTTP at http://localhost:8080/mcp, or through the goku mcp command.

Does the assistant touch my real AWS account?

No. Every tool, aws_call included, acts on the Goku on your machine. The assistant needs no AWS account or credentials.

Is it safe to give an assistant full access?

The access is to your local sandbox only, and the endpoint refuses other websites. Save a snapshot first for an easy way back.

What can the assistant do in Goku?

It gets 25 tools, from logs, snapshots, fault injection and IAM to aws_call for any operation of the emulated AWS services.

Can I turn the MCP server off?

Yes. Run the Goku container with GOKU_MCP=off and /mcp answers 404.