Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

An Amazon S3 403 AccessDenied means the request was not authorized—but the missing permission may not be in the IAM policy you first check. S3 can reject a request because of an explicit deny, a missing allow, a bucket or endpoint policy, AWS Organizations controls, encryption permissions, ownership settings, or the path through CloudFront or a VPC endpoint.

Start by identifying the exact caller, API action, bucket and object key, Region, and request path. Then check for explicit denies before adding the narrowest permission that fits. Do not make the bucket public or grant s3:* as a diagnostic shortcut.

Capture the request before changing permissions

Save the complete CLI, SDK, browser, or CloudFront error. Record the time, caller ARN, AWS account, bucket, exact key, Region, operation, and whether the request was signed, presigned, anonymous, routed through a VPC endpoint, or served through CloudFront. Preserve the S3 request ID and extended request ID if present. Redact credentials and presigned URLs before sharing logs: a presigned URL acts as a bearer credential until it expires.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use the same credentials and runtime context as the failed request. For a CLI profile, for example:

#1 Best Overall
Sale
Amazon Fire HD 10 tablet, built for relaxation, 10.1" vibrant Full HD screen, octa-core processor, 4 GB RAM, 32 GB, Black
  • Do what you love, uninterrupted — 25% faster performance than the previous generation and is ideal for seamless streaming, reading, and gaming.
  • High-def entertainment — A 10.1" 1080p Full HD display brings brilliant color to all your shows and games. Binge watch longer with 13-hour battery, 3 or 4 GB RAM, 32 or 64 GB of storage, and up to 1 TB expandable storage with micro-SD card (sold separately).
  • Thin, light, durable — Tap into entertainment from anywhere with a lightweight, durable design and strengthened glass made from aluminosilicate glass. As measured in a tumble test, Fire HD 10 is 2.7 times as durable as the Samsung Galaxy Tab A8 (2022).
  • Stay up to speed — Use the 5 MP front-facing camera to Zoom with family and friends, or create content for social apps like Instagram and TikTok.
  • Ready when inspiration strikes — With 4,096 levels of pressure sensitivity, the Made for Amazon Stylus Pen (sold separately) offers a natural writing experience that responds to your handwriting. Use it to write, sketch in apps like OneNote, and more.
AWS_PROFILE=production aws sts get-caller-identity

The response identifies the effective account and principal, often an assumed role rather than the developer or IAM user expected. For an application, inspect the credentials available to the running workload—such as its container role or instance profile—not just your local shell. See the AWS CLI command reference.

Run controlled tests with the same identity

Make the profile, Region, and endpoint explicit where relevant. Substitute your bucket and exact key:

aws s3api get-bucket-location --bucket example-bucket

aws s3api head-object 
  --profile production 
  --region us-east-1 
  --bucket example-bucket 
  --key 'path/to/object.txt'

aws s3api get-object 
  --profile production 
  --region us-east-1 
  --bucket example-bucket 
  --key 'path/to/object.txt' 
  ./object.txt

aws s3api list-objects-v2 
  --profile production 
  --region us-east-1 
  --bucket example-bucket 
  --prefix 'path/to/'

These calls test different permissions: a successful object read does not prove that listing is allowed, and a listing failure does not by itself prove that a known-key read must fail. If the bucket uses Requester Pays, add --request-payer requester to the relevant request. Consult the current HeadObject, GetObject, and ListObjectsV2 command references for options.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A 403 from HeadObject is not proof that the object exists or is absent. S3 may return a forbidden response for a nonexistent key when the caller lacks permission to list the bucket. Keys are case-sensitive; check the exact spelling, prefix, trailing slash, and URL encoding. See the HeadObject API and GetObject API documentation.

Read the error, but do not overinterpret it

When available, S3’s enhanced denial message can name a policy type or explain that a request was denied or lacked an allow. AWS provides this extra context for many requests within the same account or AWS Organization. Cross-account requests outside the same organization may receive only a generic denial, and some VPC endpoint policy denials do not include enhanced context. A generic message does not identify which policy layer failed.

  • AccessDenied or Forbidden usually signals an authorization issue, but not necessarily an IAM-user policy problem.
  • SignatureDoesNotMatch points toward signing details such as the Region, request method, signed headers, or a modified URL—not simply a missing allow.
  • InvalidAccessKeyId indicates that the access key was not recognized; verify which credentials are in use.
  • AllAccessDisabled is distinct from an ordinary missing action permission; retain the full response and investigate the account or resource status.
  • KMS.AccessDeniedException means the KMS authorization path also needs investigation.
  • If the error appears only through a website or CDN, it may be CloudFront’s response to an origin failure rather than a direct S3 response.

For S3-specific denial guidance, see AWS’s 403 troubleshooting guide.

Use a request authorization worksheet

Write down these fields before editing policies. They keep the investigation focused on the specific request rather than broad permissions:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Sale
Amazon Fire HD 8 tablet (newest model), 8” HD Display, 4GB memory, 64GB, responsive and vibrant, designed for portable entertainment, Black
  • Fire HD 8 offers an 8" HD display for seamless streaming and gaming, coupled with a 5MP rear facing camera for photos—with a thin, light, durable design.
  • Fast and responsive with long battery life - With up to 4 GB RAM (2X more than 2022 release), 64GB of storage, and up to 1 TB of expandable storage (sold separately). Hexa-core processor for fast, responsive performance. Up to 13 hours of reading, browsing the web, watching videos, gaming, and listening to music at home and on-the-go.
  • Save time, get creative - Enjoy three smart tools to help you send polished emails, quickly summarize webpages, and create unique wallpapers.
  • Stream or download your favorite shows, movies, and games (like Minecraft, Roblox, and more). Enjoy your favorite content from Facebook, Hulu, Instagram, TikTok, and more through Amazon’s Appstore (Google Play not supported. Subscription for some apps required).
  • Stay connected with family and friends - ask Alexa to make video calls to friends and family or download apps like Zoom.
Field What to capture
Caller ARN from sts get-caller-identity
Accounts Caller account and bucket-owner account
Action Exact API operation and corresponding permission
Resource Bucket ARN and exact object ARN, as applicable
Region Bucket, CLI or SDK, signing, and endpoint Regions
Path Direct S3, access point, CloudFront, or VPC endpoint
Encryption SSE-S3, SSE-KMS, or SSE-C, if applicable
Ownership Bucket and object owner; Object Ownership mode
Request type Signed, anonymous, presigned, or Requester Pays
Evidence Full error, request IDs, timestamp, and relevant CloudTrail event

Match the operation to the permission and ARN

Choose permission by the API being called, not by a vague label such as “S3 read.” Typical mappings include:

Operation Typical permission Resource type
Download a known object s3:GetObject Object ARN
List a bucket or prefix s3:ListBucket Bucket ARN
Upload an object s3:PutObject Object ARN
Delete an object s3:DeleteObject Object ARN
Read bucket location s3:GetBucketLocation Bucket ARN
Read or change an object ACL s3:GetObjectAcl or s3:PutObjectAcl Object ARN
Read a bucket policy s3:GetBucketPolicy Bucket ARN
Download using a customer-managed KMS key Typically kms:Decrypt as well as S3 permission KMS key ARN
Upload using a customer-managed KMS key Typically kms:GenerateDataKey as well as S3 permission KMS key ARN

Bucket-level permissions apply to a bucket ARN such as arn:aws:s3:::example-bucket. Object-level permissions apply to an object ARN such as arn:aws:s3:::example-bucket/path/to/object.txt; a policy covering all objects commonly uses arn:aws:s3:::example-bucket/*. Granting s3:GetObject on the bucket ARN alone does not grant reads of objects. Conversely, s3:ListBucket applies to the bucket ARN, not the object ARN.

s3:ListBucket is unnecessary for a direct read when the exact key is already known, but a tool that enumerates a prefix before downloading may need it. Check the S3 action-to-permission reference for the specific API and any related permissions.

Check explicit denies before adding allows

An explicit Deny overrides an applicable Allow. Inspect the identity policy, bucket and access-point policies, AWS Organizations SCPs, VPC endpoint policy, and relevant encryption or ownership controls. Look for denies conditioned on the principal, action, bucket or key, source VPC or endpoint, IP address, Region, organization, TLS, tags, or encryption headers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For example, this bucket-policy statement denies requests that are not sent over HTTPS:

{
  "Effect": "Deny",
  "Principal": "*",
  "Action": "s3:*",
  "Resource": [
    "arn:aws:s3:::example-bucket",
    "arn:aws:s3:::example-bucket/*"
  ],
  "Condition": {
    "Bool": { "aws:SecureTransport": "false" }
  }
}

Other common conditions constrain access to a specific aws:SourceVpce, aws:SourceVpc, aws:PrincipalOrgID, aws:RequestedRegion, or principal ARN. A new allow does not fix a request that still matches an explicit deny. Find and narrow the deny only if the request is legitimately meant to be permitted. For general evaluation principles, see IAM policy evaluation logic.

Evaluate the identity and bucket policies together

For same-account requests, the caller’s identity policy and applicable resource policies must result in an allowed request without a controlling deny. For cross-account access, the requester generally needs an identity-based allow and the resource owner must allow the external principal through a resource policy. The precise result depends on the full policy context; do not assume one policy document alone determines access.

Rank #3
Sale
Amazon Fire 7 Kids tablet, ages 3-7. Top-selling 7" kids tablet on Amazon. Includes ad-free and exclusive content, easy parental controls, 10-hr battery, 16 GB, Blue
  • SAVE UP TO $70 — Bundle includes a full-featured tablet (not a toy) for kids ages 3-7, a 1-year Amazon Kids+ subscription, and a kid-proof case, versus items purchased separately.
  • 2 YEAR WORRY-FREE GUARANTEE INCLUDED — If it breaks, return it and we’ll replace it for free for 2 years.
  • AMAZON KIDS+ INCLUDED - Includes 1 year of Amazon Kids+, an award-winning digital subscription offering thousands of ad-free books, interactive games, videos, and apps. Kids can explore content from trusted brands like Disney, Nickelodeon, and PBS Kids including educational STEM activities, language learning, and entertainment they love - all in one place. After 1 year, your subscription will automatically renew every month starting at $7.99/month plus applicable tax. You may cancel any time by visiting the Amazon Kids Parent Dashboard or contacting Customer Service.
  • NO-HASSLE PARENT CONTROLS — Easy-to-use Parent Dashboard allows you to filter content based on child's age, set educational goals and time limits, and grant access to additional content like Netflix and Disney+.
  • UP to 10-HOUR BATTERY — Means the tablet is always ready when you need it.

A narrowly scoped identity policy for reading and listing one bucket might be:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "ReadObjects",
      "Effect": "Allow",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::example-bucket/*"
    },
    {
      "Sid": "ListBucket",
      "Effect": "Allow",
      "Action": "s3:ListBucket",
      "Resource": "arn:aws:s3:::example-bucket"
    }
  ]
}

Remove the listing statement if the application only reads known object keys and does not need to enumerate. For a cross-account object read, the bucket owner could grant a specific role, for example:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "AllowExternalRoleRead",
      "Effect": "Allow",
      "Principal": {
        "AWS": "arn:aws:iam::222222222222:role/ReaderRole"
      },
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::example-bucket/*"
    }
  ]
}

This resource-side statement is not a substitute for the requester-side permission in a typical cross-account setup. Do not replace a specific principal with "Principal": "*" as a quick fix. The S3 bucket-policy examples provide additional patterns. The IAM Policy Simulator can help test identity policies, but it does not reproduce every runtime condition, endpoint restriction, KMS key-policy interaction, or service-specific behavior; treat it as one diagnostic input, not final proof. See policy testing guidance.

Check public-access controls only when public access is intended

S3 Block Public Access can be enabled at account, bucket, or access-point level. Its controls—BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, and RestrictPublicBuckets—can prevent or limit access that a public policy or ACL would otherwise grant. New S3 buckets have Block Public Access enabled by default under current S3 behavior.

If an authenticated user is failing, diagnose that principal and its policies first; disabling public-access protections is not the fix. If content truly must be public, verify account- and organization-level requirements and the consequences of exposing it before changing any setting. BlockPublicPolicy can reject a public policy, while RestrictPublicBuckets can constrain access to buckets with public policies, including relevant cross-account access. For public delivery, consider a private S3 origin with CloudFront Origin Access Control rather than opening the bucket. See the Block Public Access documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check Object Ownership and ACLs for older or cross-account objects

With Bucket owner enforced Object Ownership, ACLs are disabled and the bucket owner owns objects. In that mode, an ACL is generally not the missing permission. Older buckets may use Bucket owner preferred or Object writer; if another account owns an object, its ACL can affect access even when a bucket policy appears correct.

For cross-account uploads, prefer Bucket owner enforced when compatible with the workload. Before changing a production bucket’s Object Ownership mode, migrate any ACL-based permissions because they may stop working. If ACLs must remain, an uploader may need to set the bucket-owner-full-control canned ACL where appropriate:

Rank #4
Sale
Amazon Fire HD 8 Kids Pro tablet (newest model), ages 6-12. Bright 8" HD screen, includes ad-free content, parental controls, 13-hr battery, slim case for older kids, 64GB, Hello Teal
  • SAVE UP TO $100: Get a full-feature tablet (not a toy) made for big kids ages 6–12, 1-year subscription Amazon Kids+ and a slim Kid-Friendly Case, versus items purchased separately.
  • 2 YEAR WORRY-FREE GUARANTEE INCLUDED: If it breaks, return it and we’ll replace it for free for 2 years.
  • AMAZON KIDS+ INCLUDED - Includes 1-year of Amazon Kids+, a digital subscription that provides unlimited access to ad-free, age-appropriate books, videos, apps and games that kids love to play, create and learn. After 1 year, your subscription will automatically renew every month starting at just $7.99/month plus applicable tax. You may cancel any time by visiting the Amazon Kids Parent Dashboard or contacting Customer Service.
  • EASY-TO-USE PARENTAL CONTROLS - Remotely review child activity to learn more about what your child is enjoying, approve (or deny) purchase and download requests, manage content, and more.
  • FAST WITH LONG LASTING BATTERY - Features all-day up to 13-hour battery life, powerful hexa-core processor, with up to 4 GB RAM (2X more than 2022 release), 64 GB of internal storage for content, and up to 1 TB of expandable storage (sold separately) for even more. It’s great for downloading games, videos, books, and music for their on-the-go educational entertainment.
aws s3api put-object 
  --bucket example-bucket 
  --key uploads/file.txt 
  --body ./file.txt 
  --acl bucket-owner-full-control

Check the current Object Ownership documentation and related error responses before modifying ownership settings.

Check SSE-KMS authorization separately

SSE-S3 does not require a separate KMS permission. For SSE-KMS with a customer-managed key, an object download typically needs kms:Decrypt; an upload typically needs kms:GenerateDataKey. The IAM policy and KMS key policy must both permit the relevant use, unless the key policy delegates authorization in a way that allows it. Grants, encryption-context conditions, account boundaries, and organization controls can also affect the result.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Inspect object encryption metadata with:

aws s3api head-object 
  --bucket example-bucket 
  --key 'path/to/object.txt'

Review ServerSideEncryption, SSEKMSKeyId, and version details if relevant. An identity policy might include kms:Decrypt on the particular key ARN, but that alone is not sufficient if the key policy does not authorize the caller. Do not assume the AWS-managed aws/s3 key supports arbitrary cross-account use; check AWS’s documented account restrictions. See the guides for SSE-KMS with S3 and KMS key policies.

Check Requester Pays

On a Requester Pays bucket, a request may be denied if it does not indicate that the requester accepts the charge. For the high-level copy command:

aws s3 cp 
  s3://example-bucket/path/to/object.txt 
  ./object.txt 
  --request-payer requester

For s3api:

aws s3api get-object 
  --bucket example-bucket 
  --key 'path/to/object.txt' 
  ./object.txt 
  --request-payer requester

SDK callers must send the equivalent x-amz-request-payer: requester setting. The flag does not grant S3 permissions; the requester still needs the necessary authorization. See Requester Pays bucket guidance.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Check AWS Organizations and VPC endpoint controls

An AWS Organizations service control policy (SCP) can restrict an account even when its IAM and bucket policies appear to allow the request. Ask an organization administrator to inspect SCPs attached to the account and inherited from its organizational unit or root, especially Region, S3, KMS, principal, resource, network, and encryption restrictions. An enhanced denial message may identify an SCP restriction. See SCP documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If the workload accesses S3 through a gateway or interface VPC endpoint, inspect the endpoint policy, route and DNS path, and any bucket-policy conditions for aws:SourceVpce or aws:SourceVpc. Confirm the workload actually uses the expected endpoint and that it belongs to the expected account. A bucket policy requiring one endpoint ID can deny a request that arrives through another endpoint or the public S3 endpoint. Endpoint-policy denials may not include the enhanced S3 explanation. See the AWS guides for VPC endpoint policies and S3 policies using VPC endpoints.

Best Value
Like-New Amazon Fire HD 8 tablet (newest model), 8” HD Display, 3GB memory, 32GB, designed for portable entertainment, Black
  • Like-New Amazon Fire HD 8 tablet is refurbished, tested, and certified to look and work like new and comes with the same limited warranty as a new device. Like-New Amazon devices may be packaged in generic Amazon-branded boxes.
  • Fire HD 8 offers an 8" HD display for seamless streaming and gaming, coupled with a 5MP rear facing camera for photos—with a thin, light, durable design.
  • Responsive with all day battery life - Includes 3GB RAM (50% more than 2022 release), 32GB of storage, and up to 1 TB of expandable storage (sold separately). Up to 13 hours of reading, browsing the web, watching videos, gaming, and listening to music at home and on-the-go.
  • Save time, get creative - Enjoy three smart tools to help you send polished emails, quickly summarize webpages, and create unique wallpapers.
  • Stream or download your favorite shows, movies, and games (like Minecraft, Roblox, and more). Enjoy your favorite content from Facebook, Hulu, Instagram, TikTok, and more through Amazon’s Appstore (Google Play not supported. Subscription for some apps required).

Separate CloudFront errors from direct S3 errors

If a URL fails through a website or CDN, test the object directly with the intended authenticated identity where possible. Check that the distribution uses the right S3 origin and origin path, is configured for the intended Origin Access Control, and is trusted by the bucket policy. Confirm the URL maps to the right key, including encoding and case. Viewer authorization controls who can reach CloudFront; origin authorization controls whether CloudFront can fetch from S3. Fixing one does not automatically fix the other.

After correcting the origin policy or configuration, a cached error response may remain until the relevant cache entry expires or is invalidated. For private S3 content delivered via CloudFront, AWS generally recommends Origin Access Control rather than making the bucket public. See CloudFront guidance for restricting access to an S3 origin.

For delete or overwrite failures, check Object Lock

S3 Object Lock can prevent deletion or replacement while retention or a legal hold applies. Governance mode may permit a specially authorized bypass; compliance mode cannot be bypassed during the retention period. A legal hold must be removed before permanent deletion, subject to applicable authority and compliance obligations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
aws s3api get-object-retention 
  --bucket example-bucket 
  --key 'path/to/object.txt'

aws s3api get-object-legal-hold 
  --bucket example-bucket 
  --key 'path/to/object.txt'

Do not remove a retention period or legal hold merely to clear an error. Confirm the business and regulatory implications, and review the Object Lock documentation.

For presigned URLs, verify the signer and request details

A presigned URL uses the permissions of the principal that created it; it does not bypass bucket, KMS, network, or organization restrictions. Check its expiration, signing Region, HTTP method, required headers, bucket and key, and whether a browser or proxy changed the query string. The signing principal needs the relevant S3 permission and, for SSE-KMS objects, applicable KMS access. The bucket policy may also reject the request based on protocol or source network.

Generate a test URL for a known object and test it without altering its query string:

aws s3 presign 
  s3://example-bucket/path/to/object.txt 
  --expires-in 900 
  --region us-east-1

curl -i '<PRESIGNED-URL>'

Do not post the URL in public tickets or logs. See AWS’s presigned URL guidance and the CLI presign reference.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use audit tools when the request is still unclear

CloudTrail can help identify the principal, API action, time, and request context. Event history provides recent management-event history; S3 object-level activity is a data event and requires appropriate data-event collection to be configured. Data-event logging can generate substantial volume and downstream storage or query costs, so scope selectors to the buckets or operations needed rather than enabling broad logging without a plan. CloudTrail visibility depends on event type, service path, and configuration; it may not show every denial. Start with the CloudTrail trail documentation.

IAM Access Analyzer can identify unintended public or cross-account access and help validate policies; its S3 findings are useful for reviewing exposure, not a universal explanation for every individual failed request. See IAM Access Analyzer and Access Analyzer for S3. If evidence is insufficient, give AWS Support the full error, request IDs, timestamp, caller ARN, bucket owner, operation, Regions, and request path. AWS specifically recommends retaining S3 request IDs when escalating unresolved issues.

Verify the fix safely

  1. Retest with the same profile, application role, Region, endpoint, and request type that failed.
  2. Test the exact operation and key; separately test listing if the application needs it.
  3. Confirm the result does not rely on broader access than intended, such as public access or s3:*.
  4. For cross-account or encrypted objects, verify the resource-owner and KMS sides as well as the caller’s identity policy.
  5. Check CloudFront through the same distribution after origin access is fixed, and account for cached error responses.
  6. Keep the request IDs and before-and-after policy changes with the incident record, while redacting credentials and presigned URLs.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.