AWS SigV4
AWS services that authenticate requests with Signature Version 4, addressed by service name and region (for example s3, sqs, execute-api).
Query authentication produces presigned URLs with X-Amz-Expires derived from expires_in.
Get started
cargo add reqsign --features aws
use reqsign::aws;
// Credentials resolve through the default chain:
// env → profiles → SSO → OIDC → process → ECS → IMDS.
let signer = aws::default_signer("s3", "us-east-1");
let mut req = http::Request::builder()
.method(http::Method::GET)
.uri("https://s3.amazonaws.com/my-bucket/my-object")
.body(())?
.into_parts()
.0;
// Sign in place, then send with the HTTP client you already use.
signer.sign(&mut req, None).await?;
Credentials
Default credential chain
The default signer tries these sources in order and uses the first one that yields a credential — no configuration needed when any of them is present:
- Environment variables
- Shared config and credentials files
- IAM Identity Center (SSO)
- STS AssumeRoleWithWebIdentity (OIDC)
- External credential process
- ECS container credentials
- EC2 instance metadata (IMDSv2)
Credential providers
Available ProvideCredential implementations. Construct any of them directly, reorder them, or compose them into your own chain — see Loading credentials:
EnvCredentialProvider— Environment variablesProfileCredentialProvider— Shared config and credentials filesSSOCredentialProvider— IAM Identity Center (SSO)AssumeRoleWithWebIdentityCredentialProvider— STS AssumeRoleWithWebIdentity (OIDC)ProcessCredentialProvider— External credential processECSCredentialProvider— ECS container credentialsIMDSv2CredentialProvider— EC2 instance metadata (IMDSv2)StaticCredentialProvider— Static access keysAssumeRoleCredentialProvider— STS AssumeRoleCognitoIdentityCredentialProvider— Cognito Identity
Credential granting
This provider can exchange credentials for downscoped ones before any request is signed — see Granting scoped access:
- S3 Access Grants — GetDataAccess exchanges IAM credentials for grant-scoped credentials.
- S3 Express Session — CreateSession issues bucket-scoped session credentials for S3 Express One Zone.