Providers
Reqsign keeps each provider's signing protocol and credential semantics
explicit instead of hiding them behind one abstraction. This matrix and every
detail page are rendered from the
provider catalog.
CI checks crate, feature, page, and source-path consistency. Maintainers review
signing capabilities and credential-chain semantics against the referenced source;
those behavioral claims are not inferred by the validator.
| Provider | Signing schemes | Header | Query / presign | Granting | WASM |
|---|---|---|---|---|---|
| AWS SigV4 | AWS Signature Version 4 | ✓ | ✓ | ✓ 2 | ✓ |
| AWS SigV4a | AWS Signature Version 4A | ✓ | ✓ | — | ✓ |
| Azure Storage | Shared Key, SAS token, Entra ID bearer token | ✓ | ✓ | ✓ 1 | ✓ |
| Google Cloud | OAuth 2.0 bearer token, V4 signed URLs | ✓ | ✓ | ✓ 2 | — |
| Aliyun OSS | OSS signature V1, OSS signature V2, OSS signature V4 | ✓ | ✓ | — | ✓ |
| Huawei Cloud OBS | OBS signature | ✓ | ✓ | — | — |
| Oracle Cloud | OCI request signature | ✓ | — | — | — |
| Tencent COS | COS signature | ✓ | ✓ | — | ✓ |
| Volcengine TOS | TOS signature | ✓ | ✓ | — | — |
CI checks crate, feature, page, and source-path consistency; capability semantics are reviewed by maintainers. Found a mismatch? Open an issue.
Open a provider for its full capability sheet: credential sources, facade features, granting operations, and test coverage.
What "supported" means
For each provider, the detail page states precisely:
- Service scope — which APIs the signer produces valid signatures for.
- Signing schemes — the exact protocols implemented (e.g. SigV4, Shared Key, OSS V4).
- Credential sources — which loading mechanisms the default chain composes.
- Request authentication — whether header signing, query authentication, or both are available.
- Credential granting — explicit downscoping operations, if any.
- WASM status — whether CI verifies the provider for
wasm32-unknown-unknown. - Test coverage — how the claims are exercised (mock servers, fixtures, gated live tests).
Reqsign does not claim to support "every cloud" or every service of any cloud — only what this catalog declares and traces to source.
Out of scope
- Sending requests: Reqsign signs; your HTTP client sends.
- Response modeling, pagination, or service-specific request builders.
- Providers or schemes not listed here. If you need one, open an issue — the architecture is built for adding providers.