Reqsign vs vendor SDKs
If you are building your own HTTP client, SDK, proxy, or storage engine, the real decision is between two ways of getting requests signed: pull in each cloud's full SDK, or use a dedicated signing layer.
| Reqsign | Vendor SDKs | |
|---|---|---|
| Scope | Signing, credential loading, scoped granting — nothing else | The cloud's full API surface: clients, request/response models, transports |
| HTTP client | Yours — Reqsign mutates a plain http::request::Parts and hands it back | Bundled; requests flow through the SDK's own stack |
| Retries, pooling, middleware | Yours | The SDK's |
| Dependency footprint | One signing crate per provider, plus the runtime pieces you opt into | Per-cloud SDK trees, each with its own HTTP and TLS choices |
| Multi-cloud | One composition pattern (Context + ProvideCredential + SignRequest) across nine providers, protocols kept explicit | One SDK per cloud, each with its own idioms |
| Custom runtimes / WASM | Pluggable I/O via Context, wasm32-unknown-unknown for a verified subset | Generally assumes the SDK's supported runtimes |
| Beyond signing | Out of scope by design | Pagination, waiters, service helpers, management APIs |
When Reqsign fits
You own the HTTP layer and want to keep it: a database's storage backend, a CLI, a gateway, an SDK of your own. You need wire-correct signatures, production-grade credential chains, and perhaps presigning or downscoped grants — without inheriting a vendor SDK's HTTP stack, retry policy, and dependency tree per cloud.
When a vendor SDK fits
You need broad coverage of one cloud's API surface — management operations, typed request/response models, service-specific helpers — and the SDK's bundled stack fits your application. Signing is a fraction of what those SDKs do; Reqsign replaces only that fraction.
Relationship to Apache OpenDAL
Reqsign started inside Apache OpenDAL™ and graduated to a standalone Apache top-level project in 2026. The two remain close, and the dependency points one way: OpenDAL's cloud storage services sign their requests with Reqsign; Reqsign does not depend on OpenDAL.
The two serve different builders. Reqsign gives you signing primitives for a client you are writing yourself. OpenDAL is a ready-made data access layer — if what you actually want is to read and write storage behind one API rather than construct requests, use OpenDAL and you get Reqsign's signing underneath for free.