Free tools Windows power users keep installed
One-click scans. No signup required.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
An Amazon S3 403 AccessDenied means the request was not authorized—but the missing permission may not be in the IAM policy you first check. S3 can reject a request because of an explicit deny, a missing allow, a bucket or endpoint policy, AWS Organizations controls, encryption permissions, ownership settings, or the path through CloudFront or a VPC endpoint.
Start by identifying the exact caller, API action, bucket and object key, Region, and request path. Then check for explicit denies before adding the narrowest permission that fits. Do not make the bucket public or grant s3:* as a diagnostic shortcut.
Capture the request before changing permissions
Save the complete CLI, SDK, browser, or CloudFront error. Record the time, caller ARN, AWS account, bucket, exact key, Region, operation, and whether the request was signed, presigned, anonymous, routed through a VPC endpoint, or served through CloudFront. Preserve the S3 request ID and extended request ID if present. Redact credentials and presigned URLs before sharing logs: a presigned URL acts as a bearer credential until it expires.
Use the same credentials and runtime context as the failed request. For a CLI profile, for example:
#1 Best Overall
- Do what you love, uninterrupted — 25% faster performance than the previous generation and is ideal for seamless streaming, reading, and gaming.
- High-def entertainment — A 10.1" 1080p Full HD display brings brilliant color to all your shows and games. Binge watch longer with 13-hour battery, 3 or 4 GB RAM, 32 or 64 GB of storage, and up to 1 TB expandable storage with micro-SD card (sold separately).
- Thin, light, durable — Tap into entertainment from anywhere with a lightweight, durable design and strengthened glass made from aluminosilicate glass. As measured in a tumble test, Fire HD 10 is 2.7 times as durable as the Samsung Galaxy Tab A8 (2022).
- Stay up to speed — Use the 5 MP front-facing camera to Zoom with family and friends, or create content for social apps like Instagram and TikTok.
- Ready when inspiration strikes — With 4,096 levels of pressure sensitivity, the Made for Amazon Stylus Pen (sold separately) offers a natural writing experience that responds to your handwriting. Use it to write, sketch in apps like OneNote, and more.
AWS_PROFILE=production aws sts get-caller-identity
The response identifies the effective account and principal, often an assumed role rather than the developer or IAM user expected. For an application, inspect the credentials available to the running workload—such as its container role or instance profile—not just your local shell. See the AWS CLI command reference.
Run controlled tests with the same identity
Make the profile, Region, and endpoint explicit where relevant. Substitute your bucket and exact key:
aws s3api get-bucket-location --bucket example-bucket
aws s3api head-object
--profile production
--region us-east-1
--bucket example-bucket
--key 'path/to/object.txt'
aws s3api get-object
--profile production
--region us-east-1
--bucket example-bucket
--key 'path/to/object.txt'
./object.txt
aws s3api list-objects-v2
--profile production
--region us-east-1
--bucket example-bucket
--prefix 'path/to/'
These calls test different permissions: a successful object read does not prove that listing is allowed, and a listing failure does not by itself prove that a known-key read must fail. If the bucket uses Requester Pays, add --request-payer requester to the relevant request. Consult the current HeadObject, GetObject, and ListObjectsV2 command references for options.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →A 403 from HeadObject is not proof that the object exists or is absent. S3 may return a forbidden response for a nonexistent key when the caller lacks permission to list the bucket. Keys are case-sensitive; check the exact spelling, prefix, trailing slash, and URL encoding. See the HeadObject API and GetObject API documentation.
Read the error, but do not overinterpret it
When available, S3’s enhanced denial message can name a policy type or explain that a request was denied or lacked an allow. AWS provides this extra context for many requests within the same account or AWS Organization. Cross-account requests outside the same organization may receive only a generic denial, and some VPC endpoint policy denials do not include enhanced context. A generic message does not identify which policy layer failed.
AccessDeniedorForbiddenusually signals an authorization issue, but not necessarily an IAM-user policy problem.SignatureDoesNotMatchpoints toward signing details such as the Region, request method, signed headers, or a modified URL—not simply a missing allow.InvalidAccessKeyIdindicates that the access key was not recognized; verify which credentials are in use.AllAccessDisabledis distinct from an ordinary missing action permission; retain the full response and investigate the account or resource status.KMS.AccessDeniedExceptionmeans the KMS authorization path also needs investigation.- If the error appears only through a website or CDN, it may be CloudFront’s response to an origin failure rather than a direct S3 response.
For S3-specific denial guidance, see AWS’s 403 troubleshooting guide.
Use a request authorization worksheet
Write down these fields before editing policies. They keep the investigation focused on the specific request rather than broad permissions:
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchRank #2
- Fire HD 8 offers an 8" HD display for seamless streaming and gaming, coupled with a 5MP rear facing camera for photos—with a thin, light, durable design.
- Fast and responsive with long battery life - With up to 4 GB RAM (2X more than 2022 release), 64GB of storage, and up to 1 TB of expandable storage (sold separately). Hexa-core processor for fast, responsive performance. Up to 13 hours of reading, browsing the web, watching videos, gaming, and listening to music at home and on-the-go.
- Save time, get creative - Enjoy three smart tools to help you send polished emails, quickly summarize webpages, and create unique wallpapers.
- Stream or download your favorite shows, movies, and games (like Minecraft, Roblox, and more). Enjoy your favorite content from Facebook, Hulu, Instagram, TikTok, and more through Amazon’s Appstore (Google Play not supported. Subscription for some apps required).
- Stay connected with family and friends - ask Alexa to make video calls to friends and family or download apps like Zoom.
| Field | What to capture |
|---|---|
| Caller | ARN from sts get-caller-identity |
| Accounts | Caller account and bucket-owner account |
| Action | Exact API operation and corresponding permission |
| Resource | Bucket ARN and exact object ARN, as applicable |
| Region | Bucket, CLI or SDK, signing, and endpoint Regions |
| Path | Direct S3, access point, CloudFront, or VPC endpoint |
| Encryption | SSE-S3, SSE-KMS, or SSE-C, if applicable |
| Ownership | Bucket and object owner; Object Ownership mode |
| Request type | Signed, anonymous, presigned, or Requester Pays |
| Evidence | Full error, request IDs, timestamp, and relevant CloudTrail event |
Match the operation to the permission and ARN
Choose permission by the API being called, not by a vague label such as “S3 read.” Typical mappings include:
| Operation | Typical permission | Resource type |
|---|---|---|
| Download a known object | s3:GetObject |
Object ARN |
| List a bucket or prefix | s3:ListBucket |
Bucket ARN |
| Upload an object | s3:PutObject |
Object ARN |
| Delete an object | s3:DeleteObject |
Object ARN |
| Read bucket location | s3:GetBucketLocation |
Bucket ARN |
| Read or change an object ACL | s3:GetObjectAcl or s3:PutObjectAcl |
Object ARN |
| Read a bucket policy | s3:GetBucketPolicy |
Bucket ARN |
| Download using a customer-managed KMS key | Typically kms:Decrypt as well as S3 permission |
KMS key ARN |
| Upload using a customer-managed KMS key | Typically kms:GenerateDataKey as well as S3 permission |
KMS key ARN |
Bucket-level permissions apply to a bucket ARN such as arn:aws:s3:::example-bucket. Object-level permissions apply to an object ARN such as arn:aws:s3:::example-bucket/path/to/object.txt; a policy covering all objects commonly uses arn:aws:s3:::example-bucket/*. Granting s3:GetObject on the bucket ARN alone does not grant reads of objects. Conversely, s3:ListBucket applies to the bucket ARN, not the object ARN.
s3:ListBucket is unnecessary for a direct read when the exact key is already known, but a tool that enumerates a prefix before downloading may need it. Check the S3 action-to-permission reference for the specific API and any related permissions.
Check explicit denies before adding allows
An explicit Deny overrides an applicable Allow. Inspect the identity policy, bucket and access-point policies, AWS Organizations SCPs, VPC endpoint policy, and relevant encryption or ownership controls. Look for denies conditioned on the principal, action, bucket or key, source VPC or endpoint, IP address, Region, organization, TLS, tags, or encryption headers.
For example, this bucket-policy statement denies requests that are not sent over HTTPS:
{
"Effect": "Deny",
"Principal": "*",
"Action": "s3:*",
"Resource": [
"arn:aws:s3:::example-bucket",
"arn:aws:s3:::example-bucket/*"
],
"Condition": {
"Bool": { "aws:SecureTransport": "false" }
}
}
Other common conditions constrain access to a specific aws:SourceVpce, aws:SourceVpc, aws:PrincipalOrgID, aws:RequestedRegion, or principal ARN. A new allow does not fix a request that still matches an explicit deny. Find and narrow the deny only if the request is legitimately meant to be permitted. For general evaluation principles, see IAM policy evaluation logic.
Evaluate the identity and bucket policies together
For same-account requests, the caller’s identity policy and applicable resource policies must result in an allowed request without a controlling deny. For cross-account access, the requester generally needs an identity-based allow and the resource owner must allow the external principal through a resource policy. The precise result depends on the full policy context; do not assume one policy document alone determines access.
Rank #3
- SAVE UP TO $70 — Bundle includes a full-featured tablet (not a toy) for kids ages 3-7, a 1-year Amazon Kids+ subscription, and a kid-proof case, versus items purchased separately.
- 2 YEAR WORRY-FREE GUARANTEE INCLUDED — If it breaks, return it and we’ll replace it for free for 2 years.
- AMAZON KIDS+ INCLUDED - Includes 1 year of Amazon Kids+, an award-winning digital subscription offering thousands of ad-free books, interactive games, videos, and apps. Kids can explore content from trusted brands like Disney, Nickelodeon, and PBS Kids including educational STEM activities, language learning, and entertainment they love - all in one place. After 1 year, your subscription will automatically renew every month starting at $7.99/month plus applicable tax. You may cancel any time by visiting the Amazon Kids Parent Dashboard or contacting Customer Service.
- NO-HASSLE PARENT CONTROLS — Easy-to-use Parent Dashboard allows you to filter content based on child's age, set educational goals and time limits, and grant access to additional content like Netflix and Disney+.
- UP to 10-HOUR BATTERY — Means the tablet is always ready when you need it.
A narrowly scoped identity policy for reading and listing one bucket might be:
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errors{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "ReadObjects",
"Effect": "Allow",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::example-bucket/*"
},
{
"Sid": "ListBucket",
"Effect": "Allow",
"Action": "s3:ListBucket",
"Resource": "arn:aws:s3:::example-bucket"
}
]
}
Remove the listing statement if the application only reads known object keys and does not need to enumerate. For a cross-account object read, the bucket owner could grant a specific role, for example:
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "AllowExternalRoleRead",
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::222222222222:role/ReaderRole"
},
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::example-bucket/*"
}
]
}
This resource-side statement is not a substitute for the requester-side permission in a typical cross-account setup. Do not replace a specific principal with "Principal": "*" as a quick fix. The S3 bucket-policy examples provide additional patterns. The IAM Policy Simulator can help test identity policies, but it does not reproduce every runtime condition, endpoint restriction, KMS key-policy interaction, or service-specific behavior; treat it as one diagnostic input, not final proof. See policy testing guidance.
Check public-access controls only when public access is intended
S3 Block Public Access can be enabled at account, bucket, or access-point level. Its controls—BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, and RestrictPublicBuckets—can prevent or limit access that a public policy or ACL would otherwise grant. New S3 buckets have Block Public Access enabled by default under current S3 behavior.
If an authenticated user is failing, diagnose that principal and its policies first; disabling public-access protections is not the fix. If content truly must be public, verify account- and organization-level requirements and the consequences of exposing it before changing any setting. BlockPublicPolicy can reject a public policy, while RestrictPublicBuckets can constrain access to buckets with public policies, including relevant cross-account access. For public delivery, consider a private S3 origin with CloudFront Origin Access Control rather than opening the bucket. See the Block Public Access documentation.
Check Object Ownership and ACLs for older or cross-account objects
With Bucket owner enforced Object Ownership, ACLs are disabled and the bucket owner owns objects. In that mode, an ACL is generally not the missing permission. Older buckets may use Bucket owner preferred or Object writer; if another account owns an object, its ACL can affect access even when a bucket policy appears correct.
For cross-account uploads, prefer Bucket owner enforced when compatible with the workload. Before changing a production bucket’s Object Ownership mode, migrate any ACL-based permissions because they may stop working. If ACLs must remain, an uploader may need to set the bucket-owner-full-control canned ACL where appropriate:
Rank #4
- SAVE UP TO $100: Get a full-feature tablet (not a toy) made for big kids ages 6–12, 1-year subscription Amazon Kids+ and a slim Kid-Friendly Case, versus items purchased separately.
- 2 YEAR WORRY-FREE GUARANTEE INCLUDED: If it breaks, return it and we’ll replace it for free for 2 years.
- AMAZON KIDS+ INCLUDED - Includes 1-year of Amazon Kids+, a digital subscription that provides unlimited access to ad-free, age-appropriate books, videos, apps and games that kids love to play, create and learn. After 1 year, your subscription will automatically renew every month starting at just $7.99/month plus applicable tax. You may cancel any time by visiting the Amazon Kids Parent Dashboard or contacting Customer Service.
- EASY-TO-USE PARENTAL CONTROLS - Remotely review child activity to learn more about what your child is enjoying, approve (or deny) purchase and download requests, manage content, and more.
- FAST WITH LONG LASTING BATTERY - Features all-day up to 13-hour battery life, powerful hexa-core processor, with up to 4 GB RAM (2X more than 2022 release), 64 GB of internal storage for content, and up to 1 TB of expandable storage (sold separately) for even more. It’s great for downloading games, videos, books, and music for their on-the-go educational entertainment.
aws s3api put-object
--bucket example-bucket
--key uploads/file.txt
--body ./file.txt
--acl bucket-owner-full-control
Check the current Object Ownership documentation and related error responses before modifying ownership settings.
Check SSE-KMS authorization separately
SSE-S3 does not require a separate KMS permission. For SSE-KMS with a customer-managed key, an object download typically needs kms:Decrypt; an upload typically needs kms:GenerateDataKey. The IAM policy and KMS key policy must both permit the relevant use, unless the key policy delegates authorization in a way that allows it. Grants, encryption-context conditions, account boundaries, and organization controls can also affect the result.
Inspect object encryption metadata with:
aws s3api head-object
--bucket example-bucket
--key 'path/to/object.txt'
Review ServerSideEncryption, SSEKMSKeyId, and version details if relevant. An identity policy might include kms:Decrypt on the particular key ARN, but that alone is not sufficient if the key policy does not authorize the caller. Do not assume the AWS-managed aws/s3 key supports arbitrary cross-account use; check AWS’s documented account restrictions. See the guides for SSE-KMS with S3 and KMS key policies.
Check Requester Pays
On a Requester Pays bucket, a request may be denied if it does not indicate that the requester accepts the charge. For the high-level copy command:
aws s3 cp
s3://example-bucket/path/to/object.txt
./object.txt
--request-payer requester
For s3api:
aws s3api get-object
--bucket example-bucket
--key 'path/to/object.txt'
./object.txt
--request-payer requester
SDK callers must send the equivalent x-amz-request-payer: requester setting. The flag does not grant S3 permissions; the requester still needs the necessary authorization. See Requester Pays bucket guidance.
Check AWS Organizations and VPC endpoint controls
An AWS Organizations service control policy (SCP) can restrict an account even when its IAM and bucket policies appear to allow the request. Ask an organization administrator to inspect SCPs attached to the account and inherited from its organizational unit or root, especially Region, S3, KMS, principal, resource, network, and encryption restrictions. An enhanced denial message may identify an SCP restriction. See SCP documentation.
Recommended Free Tools
If the workload accesses S3 through a gateway or interface VPC endpoint, inspect the endpoint policy, route and DNS path, and any bucket-policy conditions for aws:SourceVpce or aws:SourceVpc. Confirm the workload actually uses the expected endpoint and that it belongs to the expected account. A bucket policy requiring one endpoint ID can deny a request that arrives through another endpoint or the public S3 endpoint. Endpoint-policy denials may not include the enhanced S3 explanation. See the AWS guides for VPC endpoint policies and S3 policies using VPC endpoints.
Best Value
- Like-New Amazon Fire HD 8 tablet is refurbished, tested, and certified to look and work like new and comes with the same limited warranty as a new device. Like-New Amazon devices may be packaged in generic Amazon-branded boxes.
- Fire HD 8 offers an 8" HD display for seamless streaming and gaming, coupled with a 5MP rear facing camera for photos—with a thin, light, durable design.
- Responsive with all day battery life - Includes 3GB RAM (50% more than 2022 release), 32GB of storage, and up to 1 TB of expandable storage (sold separately). Up to 13 hours of reading, browsing the web, watching videos, gaming, and listening to music at home and on-the-go.
- Save time, get creative - Enjoy three smart tools to help you send polished emails, quickly summarize webpages, and create unique wallpapers.
- Stream or download your favorite shows, movies, and games (like Minecraft, Roblox, and more). Enjoy your favorite content from Facebook, Hulu, Instagram, TikTok, and more through Amazon’s Appstore (Google Play not supported. Subscription for some apps required).
Separate CloudFront errors from direct S3 errors
If a URL fails through a website or CDN, test the object directly with the intended authenticated identity where possible. Check that the distribution uses the right S3 origin and origin path, is configured for the intended Origin Access Control, and is trusted by the bucket policy. Confirm the URL maps to the right key, including encoding and case. Viewer authorization controls who can reach CloudFront; origin authorization controls whether CloudFront can fetch from S3. Fixing one does not automatically fix the other.
After correcting the origin policy or configuration, a cached error response may remain until the relevant cache entry expires or is invalidated. For private S3 content delivered via CloudFront, AWS generally recommends Origin Access Control rather than making the bucket public. See CloudFront guidance for restricting access to an S3 origin.
For delete or overwrite failures, check Object Lock
S3 Object Lock can prevent deletion or replacement while retention or a legal hold applies. Governance mode may permit a specially authorized bypass; compliance mode cannot be bypassed during the retention period. A legal hold must be removed before permanent deletion, subject to applicable authority and compliance obligations.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →aws s3api get-object-retention
--bucket example-bucket
--key 'path/to/object.txt'
aws s3api get-object-legal-hold
--bucket example-bucket
--key 'path/to/object.txt'
Do not remove a retention period or legal hold merely to clear an error. Confirm the business and regulatory implications, and review the Object Lock documentation.
For presigned URLs, verify the signer and request details
A presigned URL uses the permissions of the principal that created it; it does not bypass bucket, KMS, network, or organization restrictions. Check its expiration, signing Region, HTTP method, required headers, bucket and key, and whether a browser or proxy changed the query string. The signing principal needs the relevant S3 permission and, for SSE-KMS objects, applicable KMS access. The bucket policy may also reject the request based on protocol or source network.
Generate a test URL for a known object and test it without altering its query string:
aws s3 presign
s3://example-bucket/path/to/object.txt
--expires-in 900
--region us-east-1
curl -i '<PRESIGNED-URL>'
Do not post the URL in public tickets or logs. See AWS’s presigned URL guidance and the CLI presign reference.
Use audit tools when the request is still unclear
CloudTrail can help identify the principal, API action, time, and request context. Event history provides recent management-event history; S3 object-level activity is a data event and requires appropriate data-event collection to be configured. Data-event logging can generate substantial volume and downstream storage or query costs, so scope selectors to the buckets or operations needed rather than enabling broad logging without a plan. CloudTrail visibility depends on event type, service path, and configuration; it may not show every denial. Start with the CloudTrail trail documentation.
IAM Access Analyzer can identify unintended public or cross-account access and help validate policies; its S3 findings are useful for reviewing exposure, not a universal explanation for every individual failed request. See IAM Access Analyzer and Access Analyzer for S3. If evidence is insufficient, give AWS Support the full error, request IDs, timestamp, caller ARN, bucket owner, operation, Regions, and request path. AWS specifically recommends retaining S3 request IDs when escalating unresolved issues.
Quick Recap
Verify the fix safely
- Retest with the same profile, application role, Region, endpoint, and request type that failed.
- Test the exact operation and key; separately test listing if the application needs it.
- Confirm the result does not rely on broader access than intended, such as public access or
s3:*. - For cross-account or encrypted objects, verify the resource-owner and KMS sides as well as the caller’s identity policy.
- Check CloudFront through the same distribution after origin access is fixed, and account for cached error responses.
- Keep the request IDs and before-and-after policy changes with the incident record, while redacting credentials and presigned URLs.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

