Open source · FSL-1.1-ALv2

Find AWS waste from your terminal or your AI assistant.

cloudcostwise runs CloudWise's open waste checks on your own machine with your own read-only AWS credentials. No signup, no IAM role for a third party, no telemetry. It refuses any AWS call that isn't a read.

$ pipx install cloudcostwise
$ cloudcostwise scan --profile my-profile

Or without installing: uvx cloudcostwise scan. Python 3.11+.

What it checks

20 of CloudWise's 46 service checks: the common, high-hit ones.

EC2LambdaSageMakerWorkSpacesLightsailEBSS3EFSECRRDSDynamoDBElastiCacheElastic IPs, NAT gateways, load balancersVPC endpointsDangling DNS recordsCloudWatch logsCloudWatch dashboardsSecurity postureRI and Savings Plans opportunitiesCompute Optimizer

Every waste type it reports carries its validation level, from unit-tested to fired on a real AWS resource and silent on a healthy twin. See the evidence. Advisory findings are labelled and never added to a total.

What a scan looks like

$ cloudcostwise scan --regions us-east-1
scanning us-east-1 ...
unattached_ebs  x2  $64.00/mo
    us-east-1   vol-0a1b2c3d4e5f60718          $48.00/mo
    us-east-1   vol-0f9e8d7c6b5a40312          $16.00/mo
idle_dynamodb  x1  $5.69/mo
    us-east-1   orders-staging                  $5.69/mo
lambda_old_runtime  x1  $0.01/mo
    us-east-1   legacy-thumbnailer              $0.01/mo

Estimated savings: $69.70/month
20 of 46 service checks run locally. The other 26, history, alerts and safe fixes: cloudcostwise.io

The RI and Savings Plans checks call Cost Explorer, which AWS bills at $0.01 per request (about $0.13 a scan). The CLI says so before it scans; --no-cost-explorer skips them.

Use it from Claude Code or Codex

Then ask: "Where am I wasting money on AWS?"

Claude Code plugin (asks for your AWS profile):
$ /plugin marketplace add cloudwise-app/cloudcostwise
$ /plugin install cloudcostwise@cloudcostwise
Claude Code, plain MCP server:
$ claude mcp add cloudcostwise -s user -e AWS_PROFILE=my-profile -- uvx cloudcostwise mcp
Codex (~/.codex/config.toml):
[mcp_servers.cloudcostwise]
command = "uvx"
args = ["cloudcostwise", "mcp"]
env = { AWS_PROFILE = "my-profile" }

Four read-only tools: scan, list findings, explain a finding, fix guidance. Fixes come back as text for you to review; nothing is ever executed. The plugin and registry entries start it with uvx, so install uv first.

Permissions

ReadOnlyAccess is enough. The minimal policy (69 read actions) is in the repository. A check that lacks a permission reports its findings as missing, never as zero.

What the hosted product adds

The other 26 service checks (Glue, ECS, Step Functions, Backup, CloudFront, commitments and more), savings reconciled against your bill, history and alerts, and safe fixes you approve, with rollback.