Skip to content

aws configure agent-toolkit fails when a global endpoint_url or AWS_ENDPOINT_URL is set #10698

Description

@HarshCasper

Describe the bug

When a global endpoint is configured, aws configure agent-toolkit sends its Agent Toolkit requests there. The global endpoint can be AWS_ENDPOINT_URL or endpoint_url at profile level. People set one for other services: a local AWS emulator for tests, an S3-compatible object store, or a single-host proxy.

That endpoint cannot serve GET /api/skills. The wizard stops after "Fetching default AWS skills..." and exits before it installs skills or writes any MCP config.

The same failure hits:

  • add-skill, update-skill, check-skill-updates and get-skill-file
  • the wizard launched from the prompt after aws configure, aws configure sso and aws login

The client already avoids settings meant for other services in two places:

  • create_client uses us-east-1 unless --region is passed, because the API is served from one region (utils.py#L68-L78).
  • The prompt clears --endpoint-url because it "is aimed at the calling command" (hint.py#L152-L155).

A configured global endpoint is the case neither one covers.

Expected Behavior

With a global endpoint configured, the wizard and the skill commands still reach https://agent-toolkit.us-east-1.api.aws, as they do without one. Settings aimed at this service still apply: --endpoint-url, AWS_ENDPOINT_URL_AGENTTOOLKIT, and agenttoolkit in a services section.

Current Behavior

$ AWS_ENDPOINT_URL=http://127.0.0.1:9 aws configure agent-toolkit --yes
...
Fetching default AWS skills...

aws: [ERROR]: Could not connect to the endpoint URL: "http://127.0.0.1:9/api/skills?category_filter=aws-core"

It exits with code 255, installs no skills and writes no MCP config.

When a live S3-compatible server sits on the global endpoint, the request is read as a bucket named api, and the exit code is 254:

aws: [ERROR]: An error occurred (404) when calling the ListSkills operation: <?xml version='1.0' encoding='utf-8'?>
<Error><Code>NoSuchBucket</Code><Message>The specified bucket does not exist</Message>...<BucketName>api</BucketName></Error>

aws agent-toolkit add-skill --skill-name aws-iam fails the same way, with <BucketName>skills</BucketName>.

Reproduction Steps

Nothing listens on port 9 inside the container, so no emulator is needed:

mkdir -p /tmp/atk-home/.claude
docker run --rm -v /tmp/atk-home:/root \
  -e AWS_ENDPOINT_URL=http://127.0.0.1:9 \
  amazon/aws-cli:2.37.4 configure agent-toolkit --yes

A profile-level endpoint gives the same error:

[default]
region = us-east-1
endpoint_url = http://127.0.0.1:9

--debug shows Found endpoint for agenttoolkit via: environment_global.

Workarounds that work on 2.37.4:

  • Set AWS_ENDPOINT_URL_AGENTTOOLKIT=https://agent-toolkit.us-east-1.api.aws.
  • Add agenttoolkit to the profile's services section.
  • Set AWS_IGNORE_CONFIGURED_ENDPOINT_URLS=true. This one also turns off the global endpoint for every other command in the same shell.

Possible Solution

Handle the endpoint the way create_client already handles the region:

  • When --endpoint-url is not passed, look up only the service-specific sources: AWS_ENDPOINT_URL_AGENTTOOLKIT, then services.agenttoolkit.
  • If neither is set, create the client with Config(ignore_configured_endpoint_urls=True).
  • Other clients in the same command keep the global endpoint.

That is about 20 lines in utils.py, plus unit tests and a changelog entry. I opened #10699 against v2 with this change.

If you would rather keep global precedence, a smaller option is to catch the ListSkills error in _install_default_skills and print a hint that names AWS_ENDPOINT_URL_AGENTTOOLKIT. I am happy to switch the PR to that.

Out of scope: the modeled commands (search-skills, list-available-skills, get-skill-metadata) do not go through create_client. Today they follow a global endpoint, and a non-us-east-1 region too.

Additional Information/Context

  • Every Agent Toolkit operation is smithy.api#noAuth. A global endpoint that routes requests by SigV4 scope has nothing to route on, so the only server that can answer them is the Agent Toolkit API itself.
  • Testing against a non-production Agent Toolkit endpoint keeps working through AWS_ENDPOINT_URL_AGENTTOOLKIT or --endpoint-url.

Generated with AI tools (Claude Code) and reviewed by @HarshCasper.

CLI version used

aws-cli/2.37.4 Python/3.14.6 Linux/6.9.8 docker/aarch64.amzn.2023. Also reproduced from source at v2 d22f211.

Environment details (OS name and version, etc.)

amazon/aws-cli:2.37.4 container on macOS 14.5 (Darwin 23.5.0). Source runs used python:3.12-slim and Python 3.11 on macOS.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

agent-toolkitbugThis issue is a bug.investigatingThis issue is being investigated and/or work is in progress to resolve the issue.p2This is a standard priority issue

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions