Skip to main content

AWS SigV4

AWS services that authenticate requests with Signature Version 4, addressed by service name and region (for example s3, sqs, execute-api).

AWS Signature Version 4✓ header signing✓ query / presign✓ WASMdocs.rs/reqsign-aws-v4 ↗

Query authentication produces presigned URLs with X-Amz-Expires derived from expires_in.

Get started​

cargo add reqsign --features aws
use reqsign::aws;

// Credentials resolve through the default chain:
// env → profiles → SSO → OIDC → process → ECS → IMDS.
let signer = aws::default_signer("s3", "us-east-1");

let mut req = http::Request::builder()
.method(http::Method::GET)
.uri("https://s3.amazonaws.com/my-bucket/my-object")
.body(())?
.into_parts()
.0;

// Sign in place, then send with the HTTP client you already use.
signer.sign(&mut req, None).await?;

Credentials

Default credential chain

The default signer tries these sources in order and uses the first one that yields a credential — no configuration needed when any of them is present:

  1. Environment variables
  2. Shared config and credentials files
  3. IAM Identity Center (SSO)
  4. STS AssumeRoleWithWebIdentity (OIDC)
  5. External credential process
  6. ECS container credentials
  7. EC2 instance metadata (IMDSv2)

Credential providers

Available ProvideCredential implementations. Construct any of them directly, reorder them, or compose them into your own chain — see Loading credentials:

Credential granting

This provider can exchange credentials for downscoped ones before any request is signed — see Granting scoped access:

  • S3 Access Grants — GetDataAccess exchanges IAM credentials for grant-scoped credentials.
  • S3 Express Session — CreateSession issues bucket-scoped session credentials for S3 Express One Zone.