
Infrawise
Your AI coding assistant finally knows your infra
4 followers
Your AI coding assistant finally knows your infra
4 followers
Open-source MCP server that gives Claude Code, Cursor, and Copilot a live, read-only map of your AWS services, database schemas, and IaC. Exact partition keys, Lambda event shapes, and misconfig warnings at coding time. One command, zero config, 100% local.



Free
Launch Team / Built With

Dropbox SignSimple, secure eSignatures for the way your team works.
Promoted



How does it handle permissions when scanning my AWS account, does it need broad read access or can I scope it down with something like a session policy for just the services I care about?
@lknur289838 Great question. It doesn't need blanket read access unless you actually want it to.
There are two ways to scope it down:
1. Service-level config (the main one)
In infrawise.yaml you explicitly enable the AWS services you want (DynamoDB, Lambda, SQS, SNS, S3, RDS, etc.). If a service is disabled, Infrawise won't even make API calls to it. So in practice, you only need IAM permissions for the services you've enabled.
2. IAM / Session Policies
Infrawise just uses the standard AWS SDK credential chain (AWS profile, SSO, environment variables, IAM role, etc.). If you assume a role with a restrictive session policy, that's completely fine. It'll simply operate within whatever permissions AWS gives it.
So if you're only using DynamoDB and Lambda, you can enable just those two in the config and grant read-only access for just those services. No need to hand over broad account-wide permissions.