PluginBench
Skill
Official
Pass
Audit score 90

aws-blocks

aws/agent-toolkit-for-aws

Infrastructure-from-Code framework for building full-stack AWS applications with pre-built Building Blocks.

What is aws-blocks?

AWS Blocks is an Infrastructure-from-Code framework that bundles CDK, SDK, and local mocks into 18+ reusable Building Blocks (KVStore, Database, Auth, Realtime, AsyncJob, FileBucket, etc.). Use it when building APIs, selecting infrastructure components, developing locally, or deploying to AWS—all Building Blocks work without AWS credentials during development.

  • Scaffold new full-stack projects or add AWS Blocks to existing apps with one command
  • Define entire backend in a single aws-blocks/ directory with fully typed frontend imports
  • Run all Building Blocks locally with persistent mocks (.bb-data/) without AWS credentials
  • Deploy ephemeral testing environments (npm run sandbox) or long-lived production environments (npm run deploy)
  • Access 18+ Building Blocks: KVStore, DistributedTable, Database, AuthBasic, AuthCognito, Realtime, AsyncJob, FileBucket, AI/search, email, and observability
  • Use least-privilege IAM credentials and built-in security patterns for authentication and secrets management

How to install aws-blocks

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill aws-blocks
Prerequisites
  • Node.js and npm installed
  • Existing project (Vite, React, Next.js, or Amplify Gen 2) or willingness to scaffold a new one
  • AWS account and credentials for deployment (not required for local development)
Claude Code
Cursor
Windsurf
Cline

How to use aws-blocks

  1. 1.Run npx @aws-blocks/create-blocks-app my-app to scaffold a new project, or npx @aws-blocks/create-blocks-app . to add to an existing project
  2. 2.Choose a template (default, bare, react, backend, demo, auth-cognito, or nextjs) based on your stack
  3. 3.Review node_modules/@aws-blocks/blocks/README.md for core concepts, project structure, and development workflow
  4. 4.Select and configure Building Blocks in aws-blocks/ (e.g., KVStore, AuthBasic, Database)
  5. 5.Run npm run dev to start local development with mocks persisting to .bb-data/
  6. 6.Use npm run sandbox to deploy ephemeral testing environments or npm run deploy for production
  7. 7.Read individual Building Block package READMEs (e.g., @aws-blocks/bb-kv-store) for detailed API reference

Use cases

Good for
  • Building a new full-stack web application with authentication and real-time features
  • Adding serverless backend infrastructure to an existing Vite, React, or Next.js frontend
  • Creating a todo or data-driven app with KVStore, DistributedTable, and AuthBasic in minutes
  • Integrating AWS Blocks into an existing Amplify Gen 2 project
  • Developing and testing locally without AWS account setup, then deploying to production with sandbox environments
Who it's for
  • Full-stack developers building web applications on AWS
  • Teams wanting Infrastructure-as-Code without manual CDK boilerplate
  • Developers preferring local-first development with cloud deployment
  • Projects using Vite, React, Next.js, or backend-only architectures

aws-blocks FAQ

Do I need AWS credentials to develop locally?

No. All Building Blocks work locally with mocks that persist to .bb-data/ without AWS credentials. Credentials are only needed when deploying with npm run sandbox or npm run deploy.

Can I add AWS Blocks to an existing project?

Yes. Run npx @aws-blocks/create-blocks-app . in your project root. It detects your framework (Vite, React, Next.js, Amplify Gen 2) and adds an aws-blocks/ workspace alongside your code.

What Building Blocks are available?

AWS Blocks includes 18+ Building Blocks: KVStore, DistributedTable, Database, AuthBasic, AuthCognito, Realtime, AsyncJob, FileBucket, AI/search, email, and observability tools. Each has its own package under @aws-blocks scope.

How do I protect API methods from unauthorized access?

Call await auth.requireAuth(context) in every method that shouldn't be public. ApiNamespace methods are unauthenticated by default, so explicit auth checks are required.

What templates are available for scaffolding?

Seven templates: default (Vite + lit-html with auth and realtime), bare (minimal Vite), react (React + Vite), backend (backend-only), demo (todo app with CRUD), auth-cognito (passwordless email-OTP), and nextjs (Next.js + SSR).

Full instructions (SKILL.md)

Source of truth, from aws/agent-toolkit-for-aws.


name: aws-blocks description: Guides building full-stack applications with AWS Blocks — an Infrastructure-from-Code framework. Applies when creating APIs, selecting Building Blocks (KVStore, DistributedTable, Database, AuthBasic, AuthCognito, Realtime, AsyncJob, FileBucket, etc.), running local development, or deploying AWS Blocks applications. Also covers AWS Blocks topics with validated, version-specific patterns that prevent common mistakes. Triggers when user mentions AWS Blocks; project has aws-blocks/ directory; code imports @aws-blocks packages.

AWS Blocks Application Development

Package naming: All packages are published under the @aws-blocks scope (e.g., @aws-blocks/core, @aws-blocks/blocks, @aws-blocks/bb-kv-store).

Overview

AWS Blocks is an Infrastructure-from-Code framework where Building Blocks bundle CDK, SDK, and local mocks into a single API. It provides 18+ Building Blocks covering storage, authentication, real-time communication, background jobs, file management, AI/search, email, and observability — all working locally without AWS credentials.

Key characteristics:

  • One aws-blocks/ directory defines the entire backend
  • Frontend imports are fully typed — no client generation needed
  • All Building Blocks work locally without AWS (mocks persist to .bb-data/)
  • Deploy ephemeral, individual testing environments with npm run sandbox and long-lived environments with npm run deploy using least-privilege credentials

Scaffolding a New Project

npx @aws-blocks/create-blocks-app my-app
cd my-app

To add AWS Blocks to an existing project:

npx @aws-blocks/create-blocks-app .

This detects the existing project and adds an aws-blocks/ workspace alongside your code.

To add AWS Blocks to an Amplify Gen 2 project:

npx @aws-blocks/create-blocks-app .

When the CLI detects amplify/backend.ts, it automatically integrates AWS Blocks with your Amplify backend.

With a specific template:

npx @aws-blocks/create-blocks-app my-app --template demo
cd my-app

Available Templates

TemplateDescription
defaultVite + lit-html starter app with basic authentication, data persistence, and realtime to help demonstrate basic app architecture and patterns (used when --template is omitted)
bareVite + lit-html starter with a single "hello world" API method and a bare frontend
reactReact + Vite starter with a single API endpoint and typed React frontend
backendBackend-only — no frontend, just the AWS Blocks API with a single endpoint
demoTodo app with AuthBasic, KVStore, DistributedTable, Zod schemas, indexes, and auth-protected CRUD
auth-cognitoFull AuthCognito passwordless email-OTP with roles, device management, and Authenticator UI
nextjsNext.js + React starter with AWS Blocks backend integration (SSR + Server Components)

Development Workflow

After scaffolding, refer to node_modules/@aws-blocks/blocks/README.md for the complete development workflow including:

  • Core concepts (Architecture, Building Block selection)
  • Project structure and Scope organization
  • Error handling patterns
  • Schema validation
  • Local development
  • Best practices and common mistakes
  • Deployment IAM role setup and security guidance

When implementing a specific Building Block, read its package README for the detailed API reference (e.g., node_modules/@aws-blocks/bb-kv-store/README.md). These are the authoritative docs for your installed version.

Security Considerations

  • Use await auth.requireAuth(context) in every method that shouldn't be public — ApiNamespace methods are unauthenticated by default
  • Use new AppSetting(scope, id, { secret: true }) for API keys and credentials — never hardcode or use .env files
  • Always attach a schema to KVStore/AppSetting that accepts user data — the RPC layer validates structure but not business logic
  • Do not add broad * IAM policies — each Building Block already grants least-privilege scoped to its own resources
  • Never change blockPublicAccess on FileBucket — serve public files through CloudFront instead
  • Configure CORS_ALLOWED_ORIGINS explicitly for production — avoid wildcards
  • For cross-domain deployments, pass crossDomain: true to auth constructors (enables SameSite=None; Secure; Partitioned)
  • Enable monitoring: { enabled: true, snsTopicArn: '...' } on Hosting for production alerts
  • Add WAF and API Gateway throttling via CDK for public-facing apps — not included by default
  • Logger provides serialization safety (circular refs, type coercion) but does NOT redact sensitive content — never pass raw credentials, tokens, or secrets to Logger methods; sanitize context objects before logging