Official agent skill

AWS Step Functions

by aws in aws/agent-toolkit-for-aws

Authors and edits AWS Step Functions state machines: writes Amazon States Language (ASL) in JSONata, and chooses and structures state types (Task, Choice, Map, Parallel, Pass, Wait, Succeed, Fail).

OfficialApache-2.0Auto-check passedBackend & APIs

Install AWS Step Functions

skills CLI
$ npx skills add aws/agent-toolkit-for-aws --skill aws-step-functions -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws/agent-toolkit-for-aws aws-step-functions --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/specialized-skills/serverless-skills/aws-step-functions .claude/skills/aws-step-functions && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
aws-step-functions
GitHub stars
2.8k
Token cost
~3.4k tokens
SKILL.md length
1,411 words
Files
16 (incl. references, assets)
Skills in repo
138
Repo updated
First seen
Licence
Apache-2.0

At a glance

Authors and edits AWS Step Functions state machines: writes Amazon States Language (ASL) in JSONata, and chooses and structures state types (Task, Choice, Map, Parallel, Pass, Wait, Succeed, Fail).

  • The user is building
  • SKILL.md covers Overview, When to Load Reference Files, Quick Reference and Best Practices, plus 3 more sections
  • Calls aws
  • Migrating a Step Functions state machine

What it does

AWS Step Functions is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Authors and edits AWS Step Functions state machines: writes Amazon States Language (ASL) in JSONata, and chooses and structures state types (Task, Choice, Map, Parallel, Pass, Wait, Succeed, Fail). Covers ASL syntax, JSONata data transformation and variables, Retry/Catch error handling, service integrations (.sync, waitForTaskToken callbacks), Distributed Map for large-scale S3/CSV processing, saga/compensation patterns, Standard vs Express workflow choice, TestState API unit testing, and migrating state machines…

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 17 other files, including reference files and assets (for example `assets/compensation-saga-pattern.asl.json`, `assets/express-standard-handoff.asl.json` and `assets/human-in-the-loop-with-timeout-escalation.asl.json`).

It sits in Backend & APIs, covering Serverless, Unit testing and Microservices. It works with Amazon Web Services, AWS Lambda and Amazon DynamoDB. The repository describes itself as: Official, AWS-supported MCP servers, skills, and plugins to help AI agents build on AWS. The licence is Apache-2.0.

When your agent uses it

  • The user is building
  • Migrating a Step Functions state machine
  • Orchestrating multi-step workflows with branching
  • Human-approval callbacks

Example prompts

  • “t say”
  • “Use the aws-step-functions skill to author and edits AWS Step Functions state machines: writes Amazon States Language (ASL) in JSONata, and chooses…”
  • “/aws-step-functions”

What it can do on your machine

Read from SKILL.md and the folder at commit 188af2f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.aws.amazon.com
    • states-language.net
    • docs.jsonata.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AWS Step Functions loads about 3.4k tokens when it runs, and up to ~20k if it reads all its reference files. Until then it costs about 231 tokens; SKILL.md has 1,411 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~231
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~20k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws/agent-toolkit-for-aws at commit 188af2f, republished under its Apache-2.0 licence (© aws). 1,411 words, ~3,365 tokens.

Download SKILL.mdSave it as .claude/skills/aws-step-functions/SKILL.md (or your agent's skills folder). This skill also uses 15 other files; get the full folder from GitHub.
name
aws-step-functions
description
Authors and edits AWS Step Functions state machines: writes Amazon States Language (ASL) in JSONata, and chooses and structures state types (Task, Choice, Map, Parallel, Pass, Wait, Succeed, Fail). Covers ASL syntax, JSONata data transformation and variables, Retry/Catch error handling, service integrations (.sync, waitForTaskToken callbacks), Distributed Map for large-scale S3/CSV processing, saga/compensation patterns, Standard vs Express workflow choice, TestState API unit testing, and migrating state machines from JSONPath to JSONata. Use when the user is building, authoring, debugging, or migrating a Step Functions state machine or ASL definition, or orchestrating multi-step workflows with branching, retries, or human-approval callbacks, even if they don't say 'Step Functions.' Do NOT use for general Lambda function code, API Gateway, EventBridge wiring, or SAM/CDK application packaging.
version
1

AWS Step Functions

Overview

AWS Step Functions uses Amazon States Language (ASL) to define state machines as JSON. With AWS Step Functions, you can create workflows, also called state machines, to build distributed applications, automate processes, orchestrate microservices, and create data and machine learning pipelines.

This skill provides comprehensive guidance for writing state machines in ASL, covering:

  • ASL structure and JSONata expression syntax
  • Details on the eight available workflow states
  • The $states reserved variable
  • Workflow variables with Assign
  • Error handling
  • AWS Service integration patterns
  • Example code for data transformation and architecture
  • Validation and testing of state machines
  • How to migrate from JSONPath to JSONata

The AWS MCP server is recommended for sandboxed execution and audit logging when following this skill, but all steps use AWS CLI syntax and work without it.

When to Load Reference Files

Load the appropriate reference file based on what the user is working on:

  • ASL structure, state types, Task, Pass, Choice, Wait, Succeed, Fail, Parallel, Map → see references/asl-state-types.md
  • Error handling, troubleshooting, Retry, Catch, fallback, error codes, States.Timeout, States.ALL → see references/error-handling.md
  • Service integrations, Lambda invoke, DynamoDB, SNS, SQS, SDK integrations, Resource ARN, sync, async → see references/service-integrations.md
  • Migrating from JSONPath to JSONata, migration, JSONPath to JSONata, InputPath, Parameters, ResultSelector, ResultPath, OutputPath, intrinsic functions, Iterator, payload template → see references/migrating-from-jsonpath-to-jsonata.md
  • Validation, linting, testing, TestState, test state, mock, mocking, unit test, inspection level, DEBUG, TRACE, validate state, test in isolation → see references/validation-and-testing.md
  • Architecture patterns, examples, polling, saga, compensation, scatter-gather, semaphore, lock, human-in-the-loop, escalation, Express to Standard → see references/architecture-patterns.md
  • Data transformation, JSONata expressions, filtering, aggregation, string operations, $reduce, $lookup, $toMillis, $partition, $parse, $hash, $uuid → see references/transforming-data.md
  • State input/output, $states, Assign, Output, Arguments, variable scope, variable limits, evaluation order, passing data between states → see references/processing-state-inputs-and-outputs.md

Quick Reference

Standard vs Express Workflows
StandardExpress
Max duration1 year5 minutes
Execution semanticsExactly-onceAt-least-once (async) / At-most-once (sync)
Execution historyRetained 90 days, queryable via APICloudWatch Logs only
Max throughput2,000 exec/sec100,000 exec/sec
Pricing modelPer state transitionPer execution count + duration
.sync / .waitForTaskTokenSupportedNot supported
Best forAuditable, non-idempotent operationsHigh-volume, idempotent event processing

Choose Standard for: payment processing, order fulfillment, compliance workflows, anything that must never execute twice.

Choose Express for: IoT data ingestion, streaming transformations, mobile backends, high-throughput short-lived processing.

When recommending Express, the single limitation you must always state — even for fire-and-forget / high-throughput pipelines — is that Express does NOT support .sync or .waitForTaskToken (no callbacks, no nested .sync waits, no human-approval or job-completion waits). Also note: 5-minute max duration, no queryable execution history (CloudWatch Logs only), and at-least-once (async) / at-most-once (sync) execution — so non-idempotent work can run twice. If any of these matter, choose Standard (exactly-once, up to 1 year, full history).

Setting the State Machine Query Language

JSONata is the preferred way to reference and transform data in ASL. It replaces the five JSONPath I/O fields (InputPath, Parameters, ResultSelector, ResultPath, OutputPath) with just two: Arguments (inputs) and Output.

Enable at the top level to apply to all states:

json
{ "QueryLanguage": "JSONata", "StartAt": "...", "States": {...} }

Or per-state to migrate from JSONPath incrementally:

json
{ "Type": "Task", "QueryLanguage": "JSONata", ... }

JSONPath is supported and is the default if QueryLanguage is omitted — existing state machines do not need to be migrated.

Field mapping (JSONPath → JSONata):

JSONPath fieldJSONata equivalent
Parameters (keys use key.$)Arguments — drop the .$ suffix and wrap each value in {% %}
ResultSelector and OutputPathOutput (reference the raw result via $states.result)
ResultPathAssign (preferred) or Output
InputPathnot needed — reference $states.input directly

A state uses one query language, not both. Never mix JSONPath fields (InputPath/Parameters/ResultSelector/ResultPath/OutputPath) with JSONata fields (Arguments/Output) in the same state — this is the most common migration error. See references/migrating-from-jsonpath-to-jsonata.md for full details.

How Assign and Output Are Evaluated (Parallel, Not Sequential)

Within a single state, Assign and Output are evaluated at the same time — in parallel — both reading the same data (the state input plus the task result). They are NOT evaluated one after the other. Because they run together, a variable you set in Assign is not visible in that same state's Output: there is no ordering in which Output could observe the just-assigned value. The assigned value becomes available only to subsequent states.

So if you set a variable in Assign and reference it in the same state's Output, you get the old/undefined value — not because Output runs "before" Assign, but because both evaluate concurrently from the same snapshot. To use the value immediately, reference it in the next state (variables persist across states); to shape the current state's output from the task result, use $states.result directly in Output.

Unit Testing a State with TestState

Test a single state without deploying the state machine or calling the real service using the TestState API (aws stepfunctions test-state) with --mock. A complete answer covers all four points:

  • Mock the service response exactly — the --mock result MUST match the target AWS service's API response schema exactly (field names are case-sensitive). For a Lambda invoke Task that is StatusCode and Payload: --mock '{"result":"{\"StatusCode\":200,\"Payload\":{...}}"}'.
  • All three inspection levels (--inspection-level): INFO (default — output, status, nextState), DEBUG (adds data flow: afterArguments, result, variables — use to debug JSONata/data flow), TRACE (adds raw HTTP request/response, for HTTP Task).
  • .sync and .waitForTaskToken integrations still require a mock — for .sync, mock the polling API (e.g. DescribeExecution, not the initial call); for .waitForTaskToken, also pass --context '{"Task":{"Token":"..."}}'.
  • No deployment or real invocation is needed — the state is tested in isolation.

See references/validation-and-testing.md for per-service mock structures and error/retry/Map/Parallel testing.

Show full SKILL.md (520 more words)Show less

Best Practices

  • Set "QueryLanguage": "JSONata" at the top level for new state machines unless the user wants to use JSONPath
  • Keep Output minimal — only include what the state immediately after the current state needs
  • Use Assign to store variables needed in later states instead of threading it through Output
  • Use $states.input to reference original state input
  • Assign and Output are evaluated in parallel from the state's entry data, NOT sequentially — a variable set in Assign is therefore NOT visible in the same state's Output (which still sees the pre-Assign values); the new value takes effect only in the next state.
  • All JSONata expressions must produce a defined value — $data.nonExistentField throws States.QueryEvaluationError
  • Use $states.context.Execution.Input to access the original workflow input from any state
  • Save state machine definitions with .asl.json extension when working outside the console
  • Prefer the optimized Lambda integration (arn:aws:states:::lambda:invoke) over the SDK integration

Troubleshooting

Common Errors
  • States.QueryEvaluationError — JSONata expression failed. Check for type errors, undefined fields, or out-of-range values.
  • Mixing JSONPath fields with JSONata fields in the same state.
  • Using $ or $$ at the top level of a JSONata expression — use $states.input instead.
  • Forgetting {% %} delimiters around JSONata expressions — the string will be treated as a literal.
  • Assigning variables in Assign and expecting them in Output of the same state — new values only take effect in the next state.
  • Reference references/validation-and-testing.md and references/error-handling.md for detailed troubleshooting information.

Security Considerations

  • Least-privilege execution role. Scope the state machine's IAM role to the specific resources and actions it invokes (specific Lambda/DynamoDB/SQS/SNS ARNs). Avoid *FullAccess policies and service:* wildcards.
  • Encryption. Recommend encryption at rest and in transit for every data store a workflow touches: KMS-encrypted DynamoDB tables, server-side encryption (KmsMasterKeyId) on SQS queues and SNS topics, and TLS for HTTP Tasks.
  • Task tokens and message bodies are sensitive. A .waitForTaskToken token is a credential — treat it as a secret. Do not place PII, financial data, or secrets in SQS/SNS message bodies or notifications; pass a reference ID and have recipients look up details through an authorized channel.
  • Validate input and fail fast. Validate required fields at the start of the workflow with a Choice (or Pass) state using $exists() and $type(), and route invalid input to a Fail state so malformed data never reaches downstream states. Protect downstream services from bursts by setting MaxConcurrency on Map states and throttling upstream (StartExecution rate limits or EventBridge).
  • Cross-account access. When using the Credentials field to assume a role in another account, include condition keys such as aws:SourceArn or aws:SourceAccount in the target role's trust policy to prevent unintended assumption.
  • External secrets. For HTTP Tasks calling third-party APIs, store API keys and tokens in AWS Secrets Manager (referenced via an EventBridge connection), never embedded in the state machine definition.
  • Observability. Enable CloudWatch Logs for executions (log level ALL or ERROR; required for Express workflows, which have no queryable execution history), enable CloudTrail to audit Step Functions API calls, and set CloudWatch Alarms on execution failures. Always encrypt the execution log group with a customer-managed KMS key, since state input/output routinely flows through execution logs.

Resources

© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 15 other files (references, assets) in skills/specialized-skills/serverless-skills/aws-step-functions of aws/agent-toolkit-for-aws.

  • SKILL.md
  • assets/compensation-saga-pattern.asl.json
  • assets/express-standard-handoff.asl.json
  • assets/human-in-the-loop-with-timeout-escalation.asl.json
  • assets/nested-map-parallel-structures.asl.json
  • assets/polling-loop-wait-check-choice.asl.json
  • assets/scatter-gather-with-partial-results.asl.json
  • assets/semaphore-concurrency-lock.asl.json
  • references/architecture-patterns.md
  • references/asl-state-types.md
  • references/error-handling.md
  • references/migrating-from-jsonpath-to-jsonata.md
  • references/processing-state-inputs-and-outputs.md
  • references/service-integrations.md
  • references/transforming-data.md
  • references/validation-and-testing.md

Open the folder on GitHubat commit 188af2f

Compare with similar skills

AWS Step Functions next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AWS Step Functions compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AWS Step Functions this skillaws/agent-toolkit-for-aws2.8k—~3.4kAutomated safety check: PassApache-2.0
AWS Advisordiegosouzapw/awesome-omni-skills159—~4.3kAutomated safety check: PassMIT
AWS Serverless Edazxkane/aws-skills3674 repos~3.2kAutomated safety check: PassMIT
AWS Solution Architectalirezarezvani/claude-skills28k1 repos~2.5kAutomated safety check: PassMIT
AWS Serverlessdavila7/claude-code-templates32k8 repos~2kAutomated safety check: PassMIT
AWS Lambda Durable Functionsawslabs/agent-plugins915—~2.3kAutomated safety check: PassApache-2.0

Similar skills

  • AWS Advisor

    diegosouzapw/awesome-omni-skills

    AWS Advisor workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.

    159 GitHub stars~4.3k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • AWS Serverless Eda

    zxkane/aws-skills

    AWS serverless and event-driven architecture expert based on Well-Architected Framework.

    367 GitHub starsUsed in 4 repos~3.2k tokens
    Backend & APIsAuto-check passed
  • AWS Solution Architect

    alirezarezvani/claude-skills

    Design AWS architectures for startups using serverless patterns and IaC templates.

    28k GitHub starsUsed in 1 repo~2.5k tokens
    Backend & APIsAuto-check passed
  • AWS Serverless

    davila7/claude-code-templates

    Specialized skill for building production-ready serverless applications on AWS.

    32k GitHub starsUsed in 8 repos~2k tokens
    Backend & APIsAuto-check passed
  • AWS Lambda Durable Functions

    awslabs/agent-plugins

    Official

    Build resilient, long-running, multi-step applications with AWS Lambda durable functions with automatic state persistence, retry logic, and orchestration for long-running executions.

    915 GitHub stars~2.3k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • AWS Lambda

    awslabs/agent-plugins

    Official

    Design, build, deploy, test, and debug serverless applications with AWS Lambda.

    915 GitHub stars~3.1k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed

More from aws/agent-toolkit-for-aws

All 138 skills in this repo
  • Agent Advisor

    aws/agent-toolkit-for-aws

    Official

    Entry point for AI-agent work on AWS: pick a runtime, plan a migration for existing workloads, and build an executable POC — one phased flow.

    2.8k GitHub stars~4.9k tokensUpdated today
    Auto-check passed
  • Agents Build

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses to extend an existing agent project with memory, app integration, VPC, multi-agent, migration, model, browser, code interpreter, payments, or resource removal.

    2.8k GitHub stars~2.3k tokensUpdated today
    Auto-check: notes
  • Launch With AWS

    aws/agent-toolkit-for-aws

    Official

    Migrates vibe-coded web applications to AWS. An agent skill from aws/agent-toolkit-for-aws.

    2.8k GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Official

    Deploy an event-driven workflow that routes S3 uploads to either Lambda or Fargate via Step Functions based on file size.

    2.8k GitHub stars~4k tokensUpdated today
    Auto-check passed
  • AWS Marketplace Metering

    aws/agent-toolkit-for-aws

    Official

    Deploys, queries, and debugs AWS Marketplace usage-based (PAYG) metering — the pipeline (ResolveCustomer, BatchMeterUsage, EventBridge via SAM) and querying/debugging metering records, statuses…

    2.8k GitHub stars~18k tokensUpdated today
    Auto-check passed
  • Agents Pay

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying operator-defined spend limits.

    2.8k GitHub stars~6.5k tokensUpdated today
    Auto-check: notes

Categories

Questions about AWS Step Functions

What does AWS Step Functions do?

Authors and edits AWS Step Functions state machines: writes Amazon States Language (ASL) in JSONata, and chooses and structures state types (Task, Choice, Map, Parallel, Pass, Wait, Succeed, Fail). AWS Step Functions is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Authors and edits AWS Step Functions state machines: writes Amazon States Language (ASL) in JSONata, and chooses and structures state types (Task, Choice, Map, Parallel, Pass, Wait, Succeed, Fail).

When should I use AWS Step Functions?

AWS Step Functions fits situations like: the user is building; migrating a Step Functions state machine; orchestrating multi-step workflows with branching; human-approval callbacks.

How do I install AWS Step Functions in Claude Code?

Run `npx skills add aws/agent-toolkit-for-aws --skill aws-step-functions -a claude-code`. Or copy the skill folder (skills/specialized-skills/serverless-skills/aws-step-functions in aws/agent-toolkit-for-aws) into .claude/skills/aws-step-functions in your project. Claude Code loads it when a task matches its description.

How do I install AWS Step Functions in Codex?

Run `npx skills add aws/agent-toolkit-for-aws --skill aws-step-functions -a codex`. Or copy the skill folder (skills/specialized-skills/serverless-skills/aws-step-functions in aws/agent-toolkit-for-aws) into .agents/skills/aws-step-functions in your project. Codex loads it when a task matches its description.

Can I use AWS Step Functions in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/agent-toolkit-for-aws --skill aws-step-functions -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aws-step-functions, .gemini/skills/aws-step-functions, .github/skills/aws-step-functions and .opencode/skills/aws-step-functions in your project.

What does AWS Step Functions need to run?

Going by SKILL.md and its folder, AWS Step Functions needs the command-line tools its instructions call (aws).

Does AWS Step Functions access the network?

SKILL.md names 3 domains. As links in the text: docs.aws.amazon.com, states-language.net and docs.jsonata.org. This is read from the text; nothing was executed.

Is AWS Step Functions safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does AWS Step Functions use?

AWS Step Functions is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does AWS Step Functions use?

About 3.4k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 17k tokens, read only when the agent opens those files.

What are the alternatives to AWS Step Functions?

Skills that share tags, products or a category with AWS Step Functions: AWS Advisor (diegosouzapw/awesome-omni-skills, 159 stars), AWS Serverless Eda (zxkane/aws-skills, 367 stars), AWS Solution Architect (alirezarezvani/claude-skills, 28k stars) and AWS Serverless (davila7/claude-code-templates, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AWS Step Functions?

aws (a GitHub organization, an official publisher) maintains it in aws/agent-toolkit-for-aws, which has 2,825 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on October 7, 2026.

Source: aws/agent-toolkit-for-aws on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.