npx skills add ...
npx skills add aws/agent-toolkit-for-aws --skill aws-blocks
npx skills add aws/agent-toolkit-for-aws --skill aws-blocks
Guides building full-stack applications with AWS Blocks — an Infrastructure-from-Code framework. Applies when creating APIs, selecting Building Blocks (KVStore, DistributedTable, Database, AuthBasic, AuthCognito, Realtime, AsyncJob, FileBucket, etc.), running local development, or deploying AWS Blocks applications. Also covers AWS Blocks topics with validated, version-specific patterns that prevent common mistakes. Triggers when user mentions AWS Blocks; project has aws-blocks/ directory; code imports @aws-blocks packages.
Package naming: All packages are published under the
@aws-blocksscope (e.g.,@aws-blocks/core,@aws-blocks/blocks,@aws-blocks/bb-kv-store).
AWS Blocks is an Infrastructure-from-Code framework where Building Blocks bundle CDK, SDK, and local mocks into a single API. It provides 18+ Building Blocks covering storage, authentication, real-time communication, background jobs, file management, AI/search, email, and observability — all working locally without AWS credentials.
Key characteristics:
aws-blocks/ directory defines the entire backend.bb-data/)npm run sandbox and long-lived environments with npm run deploy using least-privilege credentialsThis detects the existing project and adds an aws-blocks/ workspace alongside your code.
When the CLI detects amplify/backend.ts, it automatically integrates AWS Blocks with your Amplify backend.
| Template | Description |
|---|---|
default | Vite + lit-html starter app with basic authentication, data persistence, and realtime to help demonstrate basic app architecture and patterns (used when --template is omitted) |
bare | Vite + lit-html starter with a single "hello world" API method and a bare frontend |
react | React + Vite starter with a single API endpoint and typed React frontend |
backend | Backend-only — no frontend, just the AWS Blocks API with a single endpoint |
demo | Todo app with AuthBasic, KVStore, DistributedTable, Zod schemas, indexes, and auth-protected CRUD |
auth-cognito | Full AuthCognito passwordless email-OTP with roles, device management, and Authenticator UI |
nextjs | Next.js + React starter with AWS Blocks backend integration (SSR + Server Components) |
After scaffolding, refer to node_modules/@aws-blocks/blocks/README.md for the complete development workflow including:
When implementing a specific Building Block, read its package README for the detailed API reference (e.g., node_modules/@aws-blocks/bb-kv-store/README.md). These are the authoritative docs for your installed version.
await auth.requireAuth(context) in every method that shouldn't be public — ApiNamespace methods are unauthenticated by defaultnew AppSetting(scope, id, { secret: true }) for API keys and credentials — never hardcode or use .env files* IAM policies — each Building Block already grants least-privilege scoped to its own resourcesblockPublicAccess on FileBucket — serve public files through CloudFront insteadCORS_ALLOWED_ORIGINS explicitly for production — avoid wildcardscrossDomain: true to auth constructors (enables SameSite=None; Secure; Partitioned)monitoring: { enabled: true, snsTopicArn: '...' } on Hosting for production alerts