Crate s3v4

source ·
Expand description

This crate provides a signature function that can be used to sign an S3 request and a pre_signed_url function for generating a presigned URL using AWS’ S3 version 4 signing algorithm.

Both functions return an Error generated by the ::error_chain crate which can be converted to a String or accessed through the description method or the display_chain and backtrace methods in case a full backtrace is needed.

Examples are provided in the ./examples directory showing how to upload and download files to/from objects and how to retrieve information through HEAD requests.



Signing a request

   let signature: s3v4::Signature = s3v4::signature(
       "UNSIGNED-PAYLOAD", //payload hash, or "UNSIGNED-PAYLOAD"
   ).map_err(|err| format!("Signature error: {}", err.display_chain()))?;

Using the signature data to make a request

   let req = Request::builder()
       .header("x-amz-content-sha256", "UNSIGNED-PAYLOAD")
       .header("x-amz-date", &signature.date_time)
       .header("authorization", &signature.auth_header)
   let agent = AgentBuilder::new().build();
   let response = agent
       .set("x-amz-content-sha256", "UNSIGNED-PAYLOAD")
       .set("x-amz-date", &signature.date_time)
       .set("authorization", &signature.auth_header)

Generating a pre-signed URL

    let pre_signed_url = s3v4::pre_signed_url(
    .map_err(|err| format!("{:?}", err))?;

The following code can be used as is to generate a presigned URL from command line arguments.

use url;
fn main() -> Result<(), String> {
    let url =
        url::Url::parse(&std::env::args().nth(1).expect("missing url")).expect("malformed URL");
    let access = std::env::args().nth(2).expect("missing access");
    let secret = std::env::args().nth(3).expect("missing secret");
    let method = std::env::args().nth(4).expect("missing method");
    let expiration = std::env::args()
        .expect("missing expiration (seconds)")
        .expect("wrong expiration format");
    let region = std::env::args().nth(6).expect("missing region");
    let service = std::env::args().nth(7).expect("missing service");
    let date_time: chrono::DateTime<chrono::Utc> = match std::env::args().nth(8) {
        Some(d) => chrono::DateTime::parse_from_rfc3339(&d)
            .expect("Invalid date format (should be \"YYYY-MM-DDTHH:MM:SSZ)\"")
        None => chrono::Utc::now(),
    let payload_hash = "UNSIGNED-PAYLOAD";
    let pre_signed_url = s3v4::pre_signed_url(
    .map_err(|err| format!("{:?}", err))?;
    println!("{}", pre_signed_url);

Run with e.g

cargo run --example presign -- <endpoint URL> <access> <secret> <method> \
   <expiration in seconds> <region> ["YYYY-MM-DDTHH:MM:SSZ" (timestamp)]

To send the request just use curl with

  • -I for HEAD requests
  • –file-upload for PUT requests
  • nothing for GET requests


  • The Error type.
  • Struct containing authorisation header and timestamp. Returned by sign_request.



  • Additional methods for Result, for easy interaction with this crate.


Type Definitions

  • Convenient wrapper around std::Result.