Except if it is awscli creds, then of course there is no MFA.
The work flow we used was AWS Vault -> Okta -> short lived AWS creds.
https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_p...
It briefly pops you out to a browser to authenticate and caches a short lived token locally
There's tools like aws-okta that can advantage of that to supply short lived credentials which require 2FA
You could also write a service that requires whatever authentication you want and returns the results of STS AssumeRole