Overview
CyberArk MCP Server for Secure Cloud Access enables secure, dynamic access control for cloud resources in developer and AI-driven workflows. Built for use with AI assistants such as Amazon Q Developer or Claude for Desktop, this solution helps to avoid standing access and enforces least privilege natively. The CyberArk MCP Server allows developers and AI agents to elevate access directly from their CLI, IDE, or AI assistant while enforcing Zero Standing Privileges (ZSP) across multi-cloud environments. Designed to meet the needs of both platform and security teams, the CyberArk MCP Server helps to ensure that identities have only the access they need, and only when they need it. This potentially lowers the risk of credential misuse, privilege creep, and attack surface sprawl, especially in environments that leverage Infrastructure as Code (IaC), CI/CD pipelines, or agentic AI.
Usage instructions:
Key capabilities:
- Native CLI and AI assistant integration (Amazon Q Developer, Claude for Desktop, etc.)
- Dynamic, policy-based ZSP enforcement across human and machine access
- Real-time revocation and role-based access control
- Detailed logging and audit trails for every access event
- Built-in support for secure AI workflows and automated operations
AWS integration highlights:
- Natively works with AWS IAM roles and cloud infrastructure
- Optimized for the Amazon Q Developer CLI experience
- Designed to scale across hybrid and multi-cloud AWS environments With CyberArk MCP Server, organizations can accelerate AI and cloud innovation without compromising control, visibility, or security.
Please note: this feature is offered free-of-charge for download by SCA customers and is, therefore, subject to section 1.4 of CyberArk SaaS Terms of Use. By downloading this feature, you confirm that you agree.
Highlights
- Elevate access through natural language, the CLI, developer IDE, or AI assistant such as Amazon Q Developer.
- Zero Standing Privileges dynamically enforced across human and machine identities - no embedded secrets or static credentials.
- Improve audit readiness with visibility and logs of access events, tied to identity and action.
Details
Unlock automation with AI agent solutions

Features and programs
Financing for AWS Marketplace purchases
Pricing
Vendor refund policy
Free offering
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
CyberArk MCP Server for Secure Cloud Access v1.0.7
- Amazon Bedrock AgentCore - Preview
Container image
Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.
Version release notes
Secure, just-in-time cloud access for developers and AI agents using Zero Standing Privileges right from the CLI, IDE, or AI assistant such as Amazon Q Developer.
Additional details
Support
Vendor support
Contact CyberArk for support-related questions: www.cyberark.com/customer-support/Â
Please note: this feature is offered free-of-charge for download by SCA customers and is, therefore, subject to section 1.4 of CyberArk SaaS Terms of Use. By downloading this feature, you confirm that you agree.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.