This is a feature that is natively supported by DBeaver.
Have a look at this documentation here for detailed instructions: https://dbeaver.com/docs/dbeaver/AWS-SSM-Configuration/
Ultimately DBeaver can handle the AWS authentication, authorization (if required), tunnel setup, and credential persistence for repeat uses.