Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

AWS Signature Version 4 Signer and Debugger

Every SigV4 step, presigned URLs and a line-by-line check against AWS’s error.

Developer No upload Works offline Free preview, no sign-upIncluded in your pass Pro tool Pro pass: ₹179 for 30 days

Free preview.

  • Free preview: the first lines of every signing step (up to 20) with the signature hidden, and how many lines differ from AWS’s error.
  • Locked until you unlock it: copy.
  • Unlock: Pro pass, ₹179 for 30 days, a one-time payment that never renews.

Ways to unlock shows how to get the full result.

See passes (opens in a new tab)

Printing this result is locked in the free preview.

Your keys stay in this page. Signing runs in your browser with Web Crypto; nothing is sent anywhere or saved. Prefer short-lived keys from AWS STS, or a test user with narrow permissions.

Request

The path and query are signed exactly as typed: write them the way your client sends them.

One per line, Name: value. Host, X-Amz-Date and the signature headers are added for you.

Its SHA-256 is part of the signature: every byte counts, including line endings and a final newline.

Paste a raw HTTP request

Credentials and scope

To reproduce a failing request, use its X-Amz-Date. ISO times such as 2015-08-30T12:36:00Z are converted.

Signing

Advanced options

Next steps

About the AWS Signature Version 4 Signer and Debugger

Sign a request for any AWS API with Signature Version 4 and see each step the way AWS computes it: the canonical request, the string to sign, the signing key derived from your secret key, the signature, and then the Authorization header — or a presigned URL that works until it expires. A ready-made curl command sends the signed request.

When a call fails with SignatureDoesNotMatch, paste the error AWS returned: the page reads the canonical request and string to sign that AWS printed (Amazon S3’s XML error or the message other services send) and compares them line by line with yours, with a hint for every line that differs.

Your keys are used only inside this page with your browser’s Web Crypto HMAC-SHA256: nothing is sent anywhere or saved. For testing, prefer short-lived credentials from AWS STS over long-term access keys.

Without a pass the result is a free preview: the first lines of every step (up to 20) with the signature hidden, and how many lines differ from AWS’s error, with the first rows of that comparison. The whole result and every copy unlock with a Pro pass.

How to use it

  1. Choose the method and enter the URL exactly as your client sends it: an S3 object URL, an API Gateway or Lambda function URL, or a query API such as https://sts.amazonaws.com/. The Region and service are filled in from AWS host names; check them against the service’s documentation.
  2. Add any headers (one per line, Name: value) and the body. Host, X-Amz-Date and the signature headers are added for you. You can also paste a raw HTTP request under Paste a raw HTTP request.
  3. Enter the access key ID, secret access key and, for temporary credentials (keys starting with ASIA), the session token. Set the request time: Now for a new request, or the X-Amz-Date of a failing request to reproduce it.
  4. Pick Authorization header or Presigned URL (with its lifetime). The canonical request, string to sign, signing key and signature update as you type; copying the header, the URL or the curl command unlocks with a Pro pass.
  5. To debug an error, paste AWS’s whole error response into Compare with AWS’s error. Every line that differs is shown with what to change.

Examples

The “get-vanilla” case of AWS’s signing test suite
Input
GET https://example.amazonaws.com/
Region: us-east-1 · Service: service · Time: 20150830T123600Z
Access key ID: AKIDEXAMPLE
Secret key: wJalrXUtnFEMI/K7MDENG+bPxRfiCYEXAMPLEKEY
Result
Canonical request:
GET
/

host:example.amazonaws.com
x-amz-date:20150830T123600Z

host;x-amz-date
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855

Signature: 5fa00fa31553b73ebf1942676e86291e8372ff2a2260956d9b8aae1d763fbf31

The example keys are AWS’s published test keys, not real credentials. e3b0c442…b855 is the SHA-256 of an empty body.

An Amazon S3 presigned URL valid for one day
Input
GET https://examplebucket.s3.amazonaws.com/test.txt
Region: us-east-1 · Service: s3 · Time: 20130524T000000Z · Expires: 86400
Access key ID: AKIAIOSFODNN7EXAMPLE
Result
https://examplebucket.s3.amazonaws.com/test.txt?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAIOSFODNN7EXAMPLE%2F20130524%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20130524T000000Z&X-Amz-Expires=86400&X-Amz-SignedHeaders=host&X-Amz-Signature=aeeed9bbccd4d02ee5c0109b86d86835f995330da4c265957d157751f604d404

S3 presigned URLs sign UNSIGNED-PAYLOAD instead of a body hash, because the body is not known when the URL is made.

Common uses

  • Finding out why a hand-written client, a Lambda function or an IoT device gets SignatureDoesNotMatch or IncompleteSignature.
  • Calling an IAM-protected API Gateway or Lambda function URL from curl or Postman without an SDK.
  • Making a presigned S3 download or upload link for a test.
  • Learning how SigV4 works, step by step, before implementing it in another language.

The four steps

  1. Canonical request: method \n canonical URI \n canonical query string \n canonical headers \n signed headers \n payload hash.
  2. String to sign: AWS4-HMAC-SHA256 \n X-Amz-Date \n YYYYMMDD/region/service/aws4_request \n hex(SHA-256(canonical request)).
  3. Signing key: kDate = HMAC("AWS4" + secret, YYYYMMDD), kRegion = HMAC(kDate, region), kService = HMAC(kRegion, service), kSigning = HMAC(kService, "aws4_request").
  4. Signature: hex(HMAC(kSigning, string to sign)), sent as Authorization: AWS4-HMAC-SHA256 Credential=…, SignedHeaders=…, Signature=… or as X-Amz-Signature in a presigned URL.

HMAC is HMAC-SHA256 (RFC 2104). The rules are those of the AWS IAM User Guide, and the signer is tested against every case of AWS’s SigV4 signing test suite and the worked examples of the Amazon S3 API Reference.

Why SignatureDoesNotMatch happens

  • The path is encoded differently. Services other than S3 encode the path a second time: a space sent as %20 is signed as %2520. Amazon S3 encodes the object key once.
  • The query is not sorted or not encoded. Every name and value is URI-encoded (a space is %20, never +) and the pairs are sorted by name.
  • A signed header changed on the way. Proxies, load balancers and HTTP libraries add or rewrite headers; Content-Type often gains ; charset=UTF-8 after signing. Sign only what is sent unchanged.
  • The body differs. The payload hash covers the exact bytes: line endings, a trailing newline or re-serialised JSON change it.
  • Wrong scope. The Region, the service’s signing name (for example execute-api, es, bedrock) or the date in the scope differ from what AWS expects. Global services such as IAM sign with us-east-1.
  • A clock that is off. X-Amz-Date must be close to AWS’s own time, or AWS answers RequestTimeTooSkewed.
  • Temporary credentials without their token. Keys that start with ASIA need X-Amz-Security-Token.

Presigned URLs

A presigned URL carries the signature in its query string (X-Amz-Algorithm, X-Amz-Credential, X-Amz-Date, X-Amz-Expires, X-Amz-SignedHeaders, X-Amz-Signature), so anyone who has the URL can use it until it expires: treat it like a password. With SigV4 it lasts at most 7 days (604,800 seconds), and a URL signed with temporary credentials stops working when those credentials expire, as the Amazon S3 User Guide explains.

Limitations

  • Signature Version 4A (AWS4-ECDSA-P256-SHA256, used by S3 Multi-Region Access Points) is not supported.
  • Chunked S3 uploads (STREAMING-AWS4-HMAC-SHA256-PAYLOAD) and event-stream signing are not covered: the page signs a whole body at once.
  • The page signs requests but does not send them: browsers block most cross-origin calls to AWS endpoints. Use the curl command or your own client.
  • Region and service are guessed only from standard AWS host names; custom domains, VPC endpoints and S3-compatible stores need them typed in.

Privacy

Your keys, request and body stay in this page: signing runs in your browser with Web Crypto, nothing is sent anywhere, and the keys are never saved. Close the tab to forget them.

Frequently asked questions

What do I get without a pass?

Without a pass, AWS Signature Version 4 Signer and Debugger shows the first lines of every signing step (up to 20) with the signature hidden, and how many lines differ from AWS’s error. Until you unlock it, the result can’t be copied. A Pro, Premium or Ultimate pass, a one-time payment that never renews, unlocks the full result. The pricing page lists the passes and their prices.

Is it safe to type my AWS secret access key here?

The key is used only by this page’s own script in your browser, through the Web Crypto API, and is never sent or stored. Still, the safest choice is a short-lived key from AWS STS (for example aws sts get-session-token) or a test user with narrow permissions, never your root account’s keys.

Why does the canonical URI show %2520 instead of %20?

For services other than Amazon S3, AWS URI-encodes the path as it was sent. A space that your client sent as %20 therefore appears as %2520 in the canonical request. Amazon S3 is the exception: it encodes the object key only once. The Path encoding option switches between the two.

Which headers do I have to sign?

host and every x-amz-* header you send must be signed, and AWS asks for Content-Type too whenever the request has one. Other headers are optional; leave out the ones proxies change on the way, such as User-Agent or Connection, which this page leaves unsigned by default.

What is UNSIGNED-PAYLOAD?

An Amazon S3 option that leaves the body out of the signature. Presigned S3 URLs always use it; with header signing S3 also needs the x-amz-content-sha256 header set to the same value (or to the body’s SHA-256).

Where do I find AWS’s canonical request when a call fails?

Amazon S3 returns it in its XML error (<CanonicalRequest> and <StringToSign>). Most other services include it in the error message after “The Canonical String for this request should have been”. Paste the whole response into Compare with AWS’s error.

My canonical request matches AWS’s, but the signature still differs. Why?

Then the difference is in the key: another secret access key, a different date, Region or service in the scope, or code that derives the signing key in the wrong order. Compare the signature this page computes with the one your client sent (S3 shows it as SignatureProvided).

Quick answers and tool search

Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.