Skip to main content

AWS SigV4a

AWS services that accept Signature Version 4A for multi-region requests, addressed by service name and a region set (for example s3 with us-east-1,us-west-2).

AWS Signature Version 4A✓ header signing✓ query / presign✓ WASMdocs.rs/reqsign-aws-v4a ↗

Query authentication mirrors SigV4 presigning with the ECDSA-based SigV4a signature.

Get started​

cargo add reqsign --features aws-v4a
use reqsign::aws::v4a::{default_signer, SigningRegionSet};

// Same credential chain as SigV4; the signature covers a region set —
// built for multi-region endpoints like S3 Multi-Region Access Points.
let region_set = SigningRegionSet::new("us-east-1,us-west-2")?;
let signer = default_signer("s3", region_set);

let mut req = http::Request::builder()
.method(http::Method::GET)
.uri("https://m1abcdefgh.mrap.accesspoint.s3-global.amazonaws.com/my-object")
.body(())?
.into_parts()
.0;

// Sign in place, then send with the HTTP client you already use.
signer.sign(&mut req, None).await?;

Credentials

Default credential chain

The default signer tries these sources in order and uses the first one that yields a credential — no configuration needed when any of them is present:

  1. Environment variables
  2. Shared config and credentials files
  3. IAM Identity Center (SSO)
  4. STS AssumeRoleWithWebIdentity (OIDC)
  5. External credential process
  6. ECS container credentials
  7. EC2 instance metadata (IMDSv2)

Credential providers

Available ProvideCredential implementations. Construct any of them directly, reorder them, or compose them into your own chain — see Loading credentials: