Floci emulates the AWS services listed below on a single port (4566). All services use the real AWS wire protocol, your existing AWS CLI commands and SDK clients work without modification.
This page is the canonical reference for supported service and operation counts. Some services expose separate control-plane and data-plane rows below. Other docs (and the README) should link here rather than duplicating the table.
Operation counts are exact. For dispatch-table services (Query and JSON 1.1) each count reflects one case per AWS action in the handler. For REST-based services (S3, Lambda, API Gateway v1) the count reflects distinct AWS SDK operations, collapsing routes where one JAX-RS handler fans out via query-string or header markers (e.g. PUT /{bucket}/{key} → PutObject, PutObjectTagging, PutObjectAcl, etc.).
| Service | Endpoint | Protocol | Supported operations |
|---|---|---|---|
| SSM | POST / + X-Amz-Target: AmazonSSM.* / AmazonSSMMessageDeliveryService.* |
JSON 1.1 | 22 |
| SQS | POST / with Action= param |
Query / JSON | 20 |
| SNS | POST / with Action= param |
Query / JSON | 17 |
| S3 | /{bucket}/{key} |
REST XML | 58 |
| S3 Vectors | POST /{OperationName} |
REST JSON | 12 |
| S3 Tables | /buckets, /namespaces/*, /tables/* |
REST JSON | 25 |
| DynamoDB | POST / + X-Amz-Target: DynamoDB_20120810.* |
JSON 1.1 | 28 |
| DynamoDB Streams | POST / + X-Amz-Target: DynamoDBStreams_20120810.* |
JSON 1.1 | 4 |
| Lambda | /2015-03-31/functions/... |
REST JSON | 46 |
| Lambda MicroVMs | /2025-09-09/... + /2026-04-04/... |
REST JSON | 22 |
| API Gateway v1 | /restapis/... |
REST JSON | 79 |
| API Gateway v2 | /v2/apis/... |
REST JSON | 53 + data-plane |
| IAM | POST / with Action= param |
Query | 76 |
| STS | POST / with Action= param |
Query | 7 |
| AWS Sign-In | /v1/authorize, /v1/token |
REST JSON | 2 |
| Organizations | POST / + X-Amz-Target: AWSOrganizationsV20161128.* |
JSON 1.1 | 55 |
| Cognito | POST / + X-Amz-Target: AWSCognitoIdentityProviderService.* |
JSON 1.1 | 43 |
| Cognito Identity | POST / + X-Amz-Target: AWSCognitoIdentityService.* |
JSON 1.1 | 13 |
| Global Accelerator | POST / + X-Amz-Target: GlobalAccelerator_V20180706.* |
JSON 1.1 | 22 |
| KMS | POST / + X-Amz-Target: TrentService.* |
JSON 1.1 | 34 |
| CloudHSM v2 | POST / + X-Amz-Target: BaldrApiService.* |
JSON 1.1 | 18 |
| Kinesis | POST / + X-Amz-Target: Kinesis_20131202.* |
JSON 1.1 | 24 |
| Managed Service for Apache Flink | POST / + X-Amz-Target: KinesisAnalytics_20180523.* |
JSON 1.1 | 7 |
| Secrets Manager | POST / + X-Amz-Target: secretsmanager.* |
JSON 1.1 | 16 |
| Step Functions | POST / + X-Amz-Target: AmazonStatesService.* |
JSON 1.1 | 19 |
| SWF | POST / + X-Amz-Target: SimpleWorkflowService.* |
JSON 1.0 | 39 |
| CloudFormation | POST / with Action= param |
Query | 19 |
| Cloud Control API | POST / + X-Amz-Target: CloudApiService.* |
JSON 1.1 | 5 |
| EventBridge | POST / + X-Amz-Target: AmazonEventBridge.* |
JSON 1.1 | 16 |
| EventBridge Scheduler | /schedules/*, /schedule-groups/*, /tags/* |
REST JSON | 12 |
| EventBridge Pipes | /v1/pipes/* |
REST JSON | 7 |
| CloudWatch OAM | REST paths such as POST /CreateSink and POST /CreateLink |
REST JSON | 15 |
| CloudWatch Logs | POST / + X-Amz-Target: Logs.* |
JSON 1.1 | 17 |
| CloudWatch Metrics | POST / with Action= or JSON 1.1 |
Query / JSON | 11 |
| CloudWatch RUM | /appmonitor, /appmonitor/{name}, /appmonitors |
REST JSON | 5 |
| GuardDuty | /detector, /detector/{detectorId}, /detector/{detectorId}/admin, /admin/*, /tags/* |
REST JSON | 13 |
| AWS Account Management | /putAlternateContact, /getAlternateContact |
REST JSON | 2 |
| IAM Access Analyzer | /analyzer, /analyzer/{name} |
REST JSON | 3 |
| IAM Identity Center (SSO Admin) | POST / + X-Amz-Target: SWBExternalService.* |
JSON 1.1 | 79 |
| IAM Identity Center OIDC | /client/register, /device_authorization, /token, /token?aws_iam=t, /authorize, /device |
REST JSON | 4 |
| IAM Identity Center Access Portal | /assignment/accounts, /assignment/roles, /federation/credentials, /logout |
REST JSON | 4 |
| Identity Store | POST / + X-Amz-Target: AWSIdentityStore.* |
JSON 1.1 | 19 |
| Amazon Macie | /admin, /macie, /admin/configuration |
REST JSON | 6 |
| Amazon Inspector | /delegatedadminaccounts/*, /status/batch/get, /enable, /organizationconfiguration/* |
REST JSON | 7 |
| Amazon Verified Permissions | POST / + X-Amz-Target: VerifiedPermissions.* |
JSON 1.0 | 34 |
| Security Hub | /organization/*, /accounts, /findingAggregator/*, /configurationPolicy*, /tags/* |
REST JSON | 22 |
| Amazon Detective | /orgs/*, /graphs/list, /graph/* |
REST JSON | 8 |
| Amazon Connect | /instance, /instance/{instanceId}/*, /tags/* |
REST JSON | 15 |
| Amazon AppIntegrations | /eventIntegrations/*, /dataIntegrations/*, /tags/* |
REST JSON | 14 |
| ElastiCache | POST / with Action= param + TCP proxy |
Query + RESP | 8 |
| MemoryDB | POST / + X-Amz-Target: AmazonMemoryDB.* + TCP proxy |
JSON 1.1 + RESP | 7 |
| RDS | POST / with Action= param + TCP proxy |
Query + wire | 14 |
| RDS Data API | /Execute, /BeginTransaction, /CommitTransaction, /RollbackTransaction |
REST JSON | 4 |
| Timestream for InfluxDB | POST / + X-Amz-Target: AmazonTimestreamInfluxDB.* + InfluxDB container |
JSON 1.0 + InfluxDB HTTP | 24 |
| MSK | /v1/clusters/..., /api/v2/clusters/... + Redpanda broker |
REST JSON + Kafka | 8 |
| Amazon MQ | /v1/brokers/... + RabbitMQ broker |
REST JSON + AMQP | 5 |
| MWAA | / REST paths for environments + CLI/web proxy |
REST JSON | 10 |
| Athena | POST / + X-Amz-Target: AmazonAthena.* |
JSON 1.1 | 4 |
| Glue | POST / + X-Amz-Target: AWSGlue.* |
JSON 1.1 | 38 |
| Lake Formation | POST /<Action> |
REST JSON | 16 |
| Neptune | POST / with Action= param + Gremlin TCP proxy |
Query + WebSocket | 14 |
| DocumentDB | POST / with Action= param + MongoDB container |
Query + MongoDB wire | 8 |
| DMS | POST / + X-Amz-Target: AmazonDMSv20160101.* |
JSON 1.1 | 6 |
| Redshift | POST / with Action= param + PostgreSQL container |
Query + PostgreSQL wire (+ CFN) | 29 |
| Redshift Data API | POST / + X-Amz-Target: RedshiftData.* |
JSON 1.1 | 11 |
| Redshift Serverless | POST / + X-Amz-Target: RedshiftServerless.* |
JSON 1.1 | 8 |
| EMR | POST / + X-Amz-Target: ElasticMapReduce.* |
JSON 1.1 | 24 |
| EMR Serverless | /applications/* |
REST JSON | 7 |
| Data Firehose | POST / + X-Amz-Target: Firehose_20150804.* |
JSON 1.1 | 6 |
| ECS | POST / + X-Amz-Target: AmazonEC2ContainerServiceV20141113.* |
JSON 1.1 | 58 |
| EFS | /2015-02-01/... |
REST JSON | 17 |
| EC2 | POST / with Action= param |
EC2 Query | 78 |
| Lightsail | POST / + X-Amz-Target: Lightsail_20161128.* |
JSON 1.1 | 79 local responses; 161 recognized actions |
| ACM | POST / + X-Amz-Target: CertificateManager.* |
JSON 1.1 | 12 |
| ECR | POST / + X-Amz-Target: AmazonEC2ContainerRegistry_V20150921.* (control plane) and /v2/... (data plane proxied to registry:2) |
JSON 1.1 + OCI Distribution | 17 |
| Resource Groups Tagging API | POST / + X-Amz-Target: ResourceGroupsTaggingAPI_20170126.* |
JSON 1.1 | 5 |
| Resource Explorer | POST /{OperationName}, rewritten to /re2/* for the four paths S3 Vectors also claims |
REST JSON | 32 |
| SES | POST / with Action= param |
Query | 16 |
| SES v2 | /v2/email/* |
REST JSON | 10 |
| OpenSearch | /2021-01-01/opensearch/... |
REST JSON | 24 |
| AppConfig | /applications/..., /deploymentstrategies/... |
REST JSON | 16 |
| AppConfigData | /configurationsessions, /configuration |
REST JSON | 2 |
| AppSync | /v1/apis/... |
REST JSON | 33 |
| Amazon Bedrock | /guardrails, /guardrails/{guardrailIdentifier}, /tagResource, /untagResource, /listTagsForResource |
REST JSON | 9 |
| Bedrock Runtime | /model/{modelId}/converse, /model/{modelId}/invoke |
REST JSON | 2 (stub; streaming returns 501) |
| Bedrock AgentCore Control | /runtimes/*, /gateways/*, /memories/*, /identities/*, /browsers*, /browser-profiles*, /code-interpreters*, /resourcepolicy/*, /tags/{resourceArn} |
REST JSON | 61 (+ 3 tagging via shared /tags/{arn} route) |
| Bedrock AgentCore | /runtimes/{agentRuntimeArn}/invocations |
REST JSON (binary payload) | 1 (canned-response stub) |
| EKS | /clusters, /clusters/{name}, /tags/{resourceArn} |
REST JSON | 7 |
| ELB v2 | POST / with Action= param |
Query | 34 |
| ELB Classic (v1) | POST / with Action= and Version=2012-06-01 |
Query | 20 |
| WAF v2 | POST / + X-Amz-Target: AWSWAF_20190729.* |
JSON 1.1 | 35 |
| Auto Scaling | POST / with Action= param |
Query | 33 |
| Application Auto Scaling | POST / + X-Amz-Target: AnyScaleFrontendService.* |
JSON 1.1 | 9 |
| Elastic Beanstalk | POST / with Action= or Operation= param |
Query | 14 |
| CodeBuild | POST / + X-Amz-Target: CodeBuild_20161006.* |
JSON 1.1 | 20 |
| AWS Batch | /v1/... |
REST JSON | 10 |
| CodeDeploy | POST / + X-Amz-Target: CodeDeploy_20141006.* |
JSON 1.1 | 30 |
| CodePipeline | POST / + X-Amz-Target: CodePipeline_20150709.* |
JSON 1.1 | 44 |
| AWS Network Firewall | POST / + X-Amz-Target: NetworkFirewall_20201112.* |
JSON 1.0 | 27 |
| AWS Service Catalog | POST / + X-Amz-Target: AWS242ServiceCatalogService.* |
JSON 1.1 | 89 |
| Service Quotas | POST / + X-Amz-Target: ServiceQuotasV20190624.* |
JSON 1.1 | 5 |
| AWS Budgets | POST / + X-Amz-Target: AWSBudgetServiceGateway.* |
JSON 1.1 | 26 |
| AWS RAM | POST /{operationname} (lowercase), DELETE /deleteresourceshare |
REST JSON | 12 |
| Control Catalog | /get-control, /list-controls |
REST JSON | 2 |
| AWS Marketplace | Marketplace Catalog API | REST JSON | 15 |
| Control Tower | /list-landingzones, /get-landingzone, /create-landingzone, /*-baseline* |
REST JSON | 15 |
| Managed Prometheus (AMP) | /workspaces/*, /workspaces/*/rulegroupsnamespaces/*, /tags/* |
REST JSON | 13 |
| AWS Backup | /backup-vaults/*, /backup/plans/*, /backup-jobs/*, /supported-resource-types |
REST JSON | 20 |
| AWS FIS | /experimentTemplates/*, /experiments/*, /actions/*, /targetResourceTypes/*, /safetyLevers/*, /tags/* |
REST JSON | 26 |
| CodeGuru Reviewer | /associations, /associations/{associationArn}, /tags/* |
REST JSON | 7 |
| CodeArtifact | /v1/domain*, /v1/repository*, /v1/package/version*, /v1/tag*, /v1/authorization-token, /codeartifact/maven/* |
REST JSON | 26 |
| CloudFront | /2020-05-31/distribution/*, /2020-05-31/cache-policy/*, /2020-05-31/function/* |
REST XML | 50 |
| Route53 | /2013-04-01/hostedzone/*, /2013-04-01/healthcheck/*, /2013-04-01/change/* |
REST XML | 25 |
| Route 53 Resolver | POST / + X-Amz-Target: Route53Resolver.* |
JSON 1.1 | 18 |
| Amazon SageMaker | POST / + X-Amz-Target: SageMaker.* |
JSON 1.1 | 20 |
| SageMaker Runtime | /endpoints/{EndpointName}/invocations |
REST (binary payload) | 1 |
| Cloud Map | POST / + X-Amz-Target: Route53AutoNaming_v20170314.* |
JSON 1.1 | 22 |
| AWS Config | POST / + X-Amz-Target: StarlingDoveService.* |
JSON 1.1 | 33 |
| CloudTrail | POST / + X-Amz-Target: com.amazonaws.cloudtrail.v20131101.CloudTrail_20131101.* |
JSON 1.1 | 9 |
| Textract | POST / + X-Amz-Target: Textract.* |
JSON 1.1 | 6 |
| Comprehend | POST / + X-Amz-Target: Comprehend_20171127.* |
JSON 1.1 | 5 |
| Rekognition | POST / + X-Amz-Target: RekognitionService.* |
JSON 1.1 | 5 |
| Translate | POST / + X-Amz-Target: AWSShineFrontendService_20170701.* |
JSON 1.1 | 3 |
| Transcribe | POST / + X-Amz-Target: Transcribe.* |
JSON 1.1 | 8 |
| Pricing | POST / + X-Amz-Target: AWSPriceListService.* |
JSON 1.1 | 5 |
| Cost Explorer | POST / + X-Amz-Target: AWSInsightsIndexService.* |
JSON 1.1 | 9 |
| Cost and Usage Reports | POST / + X-Amz-Target: AWSOrigamiServiceGatewayService.* |
JSON 1.1 | 6 |
| BCM Pricing Calculator | POST / + X-Amz-Target: AWSBCMPricingCalculator.* |
JSON 1.0 | 4 |
| BCM Data Exports | POST / + X-Amz-Target: AWSBillingAndCostManagementDataExports.* |
JSON 1.1 | 7 |
| Transfer Family | POST / + X-Amz-Target: TransferService.* |
JSON 1.1 | 17 |
| DataSync | POST / + X-Amz-Target: FmrsService.* |
JSON 1.1 | 48 |
| IoT Core | /things/..., /endpoint, rules/policies REST paths |
REST JSON | 62 |
| IoT Data | /things/{thingName}/shadow, MQTT topics |
REST JSON | 11 |
Lambda, ElastiCache, RDS, MSK, MWAA, ECS, EKS, and OpenSearch spin up real Docker containers and support IAM authentication and SigV4 request signing, the same auth flow as production AWS. RDS Data API executes SQL against the local RDS containers through AWS-compatible REST JSON routes.
ECR proxies Docker Distribution traffic to a shared registry:2 container so the stock docker client can push and pull image bytes against repositories returned by the AWS-shaped control plane. EKS (real mode) starts a k3s container per cluster and exposes the Kubernetes API server on a host port. OpenSearch (real mode) starts an opensearchproject/opensearch container per domain and exposes the data-plane REST API on a host port. DocumentDB starts a real mongo container per cluster and returns its host and port as the cluster endpoint, so any MongoDB driver can connect against the MongoDB-compatible wire protocol.
Before calling any service, configure your AWS client to point to Floci:
export AWS_ENDPOINT_URL=http://localhost:4566
export AWS_DEFAULT_REGION=us-east-1
export AWS_ACCESS_KEY_ID=test
export AWS_SECRET_ACCESS_KEY=testAWS_ENDPOINT_URL is the standard env var recognised by the AWS CLI v2 and AWS SDKs v2+, so no --endpoint-url flag is needed on each command.
- SageMaker - model, endpoint, runtime, and training emulation with Docker execution.