Encrypt Online
Theme

S3 Presigned URL Debugger

Check the expiry and signing details of an S3 presigned URL

The link is checked in your browser without opening it. Treat it like a temporary password.

Check a presigned linkNo AWS credentials needed

GET downloads; PUT uploads. Choose the method your client sends; it isn't included in the URL.

Request headers, time, and signing key

Enter one name: value per line, using the values your client sends.

Leave empty for the current time, or enter the time of a failed request.

Add the key to compare signatures. Use test credentials when debugging your signing code.

Expiry and signed headers

Paste the complete URL to see its expiry, region, and required headers. Add a signing key only if you need to compare signatures.

SignatureDoesNotMatch

Compare the request your client sends with the one used to sign the URL. The method, host, path, query parameters, and signed headers must match. For uploads, check Content-Type first.

Use the original URL, including every X-Amz- parameter. Changing a parameter or decoding the URL before sending it can change the signature.

Fix S3 presigned URL SignatureDoesNotMatch errors

Temporary credentials and expiry

A link stops working when its signing credentials expire, even if X-Amz-Expires allows more time. Check the expiry returned with the temporary credentials. IAM, bucket policies, and KMS permissions can also deny access; browser CORS errors need a separate CORS check.

To build an Authorization header, use the AWS SigV4 calculator. The canonical request guide explains the values used to calculate a signature.

This page supports S3 URLs signed with AWS4-HMAC-SHA256. Use an AWS SDK for SigV4a, streaming signatures, or presigned POST forms.

Inputs are not saved. The site may load analytics and advertising. Privacy details.