Skip to main content

Reqsign vs vendor SDKs

If you are building your own HTTP client, SDK, proxy, or storage engine, the real decision is between two ways of getting requests signed: pull in each cloud's full SDK, or use a dedicated signing layer.

ReqsignVendor SDKs
ScopeSigning, credential loading, scoped granting — nothing elseThe cloud's full API surface: clients, request/response models, transports
HTTP clientYours — Reqsign mutates a plain http::request::Parts and hands it backBundled; requests flow through the SDK's own stack
Retries, pooling, middlewareYoursThe SDK's
Dependency footprintOne signing crate per provider, plus the runtime pieces you opt intoPer-cloud SDK trees, each with its own HTTP and TLS choices
Multi-cloudOne composition pattern (Context + ProvideCredential + SignRequest) across nine providers, protocols kept explicitOne SDK per cloud, each with its own idioms
Custom runtimes / WASMPluggable I/O via Context, wasm32-unknown-unknown for a verified subsetGenerally assumes the SDK's supported runtimes
Beyond signingOut of scope by designPagination, waiters, service helpers, management APIs

When Reqsign fits​

You own the HTTP layer and want to keep it: a database's storage backend, a CLI, a gateway, an SDK of your own. You need wire-correct signatures, production-grade credential chains, and perhaps presigning or downscoped grants — without inheriting a vendor SDK's HTTP stack, retry policy, and dependency tree per cloud.

When a vendor SDK fits​

You need broad coverage of one cloud's API surface — management operations, typed request/response models, service-specific helpers — and the SDK's bundled stack fits your application. Signing is a fraction of what those SDKs do; Reqsign replaces only that fraction.

Relationship to Apache OpenDAL​

Reqsign started inside Apache OpenDAL™ and graduated to a standalone Apache top-level project in 2026. The two remain close, and the dependency points one way: OpenDAL's cloud storage services sign their requests with Reqsign; Reqsign does not depend on OpenDAL.

The two serve different builders. Reqsign gives you signing primitives for a client you are writing yourself. OpenDAL is a ready-made data access layer — if what you actually want is to read and write storage behind one API rather than construct requests, use OpenDAL and you get Reqsign's signing underneath for free.