S3 Presigned URL Debugger
Check the expiry and signing details of an S3 presigned URL
The link is checked in your browser without opening it. Treat it like a temporary password.
Expiry and signed headers
Paste the complete URL to see its expiry, region, and required headers. Add a signing key only if you need to compare signatures.
SignatureDoesNotMatch
Compare the request your client sends with the one used to sign the URL. The method, host, path, query parameters, and signed headers must match. For uploads, check Content-Type first.
Use the original URL, including every X-Amz- parameter. Changing a parameter or decoding the URL before sending it can change the signature.
Temporary credentials and expiry
A link stops working when its signing credentials expire, even if X-Amz-Expires allows more time. Check the expiry returned with the temporary credentials. IAM, bucket policies, and KMS permissions can also deny access; browser CORS errors need a separate CORS check.
To build an Authorization header, use the AWS SigV4 calculator. The canonical request guide explains the values used to calculate a signature.
This page supports S3 URLs signed with AWS4-HMAC-SHA256. Use an AWS SDK for SigV4a, streaming signatures, or presigned POST forms.
Inputs are not saved. The site may load analytics and advertising. Privacy details.