AWS SigV4a
AWS services that accept Signature Version 4A for multi-region requests, addressed by service name and a region set (for example s3 with us-east-1,us-west-2).
Query authentication mirrors SigV4 presigning with the ECDSA-based SigV4a signature.
Get started
cargo add reqsign --features aws-v4a
use reqsign::aws::v4a::{default_signer, SigningRegionSet};
// Same credential chain as SigV4; the signature covers a region set —
// built for multi-region endpoints like S3 Multi-Region Access Points.
let region_set = SigningRegionSet::new("us-east-1,us-west-2")?;
let signer = default_signer("s3", region_set);
let mut req = http::Request::builder()
.method(http::Method::GET)
.uri("https://m1abcdefgh.mrap.accesspoint.s3-global.amazonaws.com/my-object")
.body(())?
.into_parts()
.0;
// Sign in place, then send with the HTTP client you already use.
signer.sign(&mut req, None).await?;
Credentials
Default credential chain
The default signer tries these sources in order and uses the first one that yields a credential — no configuration needed when any of them is present:
- Environment variables
- Shared config and credentials files
- IAM Identity Center (SSO)
- STS AssumeRoleWithWebIdentity (OIDC)
- External credential process
- ECS container credentials
- EC2 instance metadata (IMDSv2)
Credential providers
Available ProvideCredential implementations. Construct any of them directly, reorder them, or compose them into your own chain — see Loading credentials:
EnvCredentialProvider— Environment variablesProfileCredentialProvider— Shared config and credentials filesSSOCredentialProvider— IAM Identity Center (SSO)AssumeRoleWithWebIdentityCredentialProvider— STS AssumeRoleWithWebIdentity (OIDC)ProcessCredentialProvider— External credential processECSCredentialProvider— ECS container credentialsIMDSv2CredentialProvider— EC2 instance metadata (IMDSv2)StaticCredentialProvider— Static access keysAssumeRoleCredentialProvider— STS AssumeRoleCognitoIdentityCredentialProvider— Cognito Identity