Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
To upload a website screenshot to Amazon S3, store its image bytes as an S3 object under a unique key and authorize the write. For a browser-based upload, a trusted backend should create a short-lived presigned URL; the browser sends the screenshot directly to S3, and the bucket must allow the website’s origin, method and request headers through CORS. CORS permits cross-origin requests but does not grant permission: IAM and bucket policies still control access.
What an S3 screenshot upload needs
Amazon S3 stores uploaded files as objects. For a screenshot, the essential pieces are a bucket, an object key (the object’s name and optional prefix), the image bytes, and authorization to write that object. The object key might look like screenshots/7b2f...png.
Choose the upload route based on who is sending the image. Use the console or AWS CLI/SDK when a trusted operator or server controls the upload. Use a presigned PUT or POST when a browser or end user must upload without receiving long-lived AWS credentials.
| Method | Best fit | Credential exposure | Automation and user experience | CORS and operational overhead |
|---|---|---|---|---|
| S3 console | One-off manual uploads by an authorized operator | Uses the operator’s AWS sign-in; no browser app credentials are needed | Simple for a person; not suited to an automated application flow | No website CORS setup for a console upload; low setup overhead |
| AWS CLI or SDK | Trusted scripts, services, and operator workflows | Uses the caller’s AWS credentials or supported temporary credentials; keep them out of untrusted clients | Good for repeatable automation; requires code or command-line access | No browser CORS for server-to-S3 requests; manage permissions and runtime credentials |
| Presigned browser upload | A website letting a user’s browser upload an image directly to S3 | The browser receives a time-limited URL for a specific operation, not long-lived AWS keys | Supports a direct browser-to-S3 flow; the application needs a backend signer | Requires a matching S3 CORS rule plus careful signing and policy configuration |
Choose a key and protect the bucket
Plan the object key before writing upload code. Use an application-generated identifier under a prefix, such as screenshots/{generated-id}.png, rather than accepting an arbitrary path from a user. S3 can replace an existing object when a new upload uses the same key; a versioning-enabled bucket retains a new version instead. Unique keys avoid accidental collisions and make it easier to scope write permissions.
#1 Best Overall
- Get NVMe solid state performance with up to 1050MB/s read and 1000MB/s write speeds in a portable, high-capacity drive(1) (Based on internal testing; performance may be lower depending on host device & other factors. 1MB=1,000,000 bytes.)
- Up to 3-meter drop protection and IP65 water and dust resistance mean this tough drive can take a beating(3) (Previously rated for 2-meter drop protection and IP55 rating. Now qualified for the higher, stated specs.)
- Use the handy carabiner loop to secure it to your belt loop or backpack for extra peace of mind.
- Help keep private content private with the included password protection featuring 256‐bit AES hardware encryption.(3)
- Easily manage files and automatically free up space with the SanDisk Memory Zone app.(5). Non-Operating Temperature -20°C to 85°C
- Create or select a bucket in the AWS Region where the application will store screenshots.
- Keep the bucket private unless public delivery is an explicit requirement. For display, use controlled GET access or a CDN rather than making uploads public by default.
- Give the signing service only the object-write permissions it needs, preferably scoped to the screenshot prefix.
- Never put long-lived AWS access keys in website JavaScript. Use a backend signer, a managed identity flow, or another AWS-supported temporary-credential design.
Upload manually with the S3 console
- In the AWS Management Console, open Amazon S3 and select the destination bucket.
- Choose Upload, add the screenshot file, and start the upload.
- Use the resulting object key in your application or workflow. Keep the object private unless your delivery design intentionally allows wider access.
This method is useful for a one-off file or a trusted operator. It is not a substitute for a secure browser upload flow: a website should not ask users to sign in with an AWS account or expose application credentials to perform uploads.
Upload with the AWS CLI
For a trusted operator or automation environment configured with AWS CLI credentials, upload a local screenshot with:
aws s3 cp ./screenshot.png s3://YOUR_BUCKET/screenshots/generated-id.png --content-type image/png
Replace YOUR_BUCKET and the example key with your bucket and a unique application-generated key. The command sends the local file to S3 and sets the object content type to image/png. The caller’s credentials must be authorized for the destination. Do not run a command using privileged credentials on a machine or in a context controlled by untrusted users.
Let a browser upload through a presigned URL
A presigned URL lets a backend authorize an upload to a specific object for a limited time. The browser gets permission through that URL rather than receiving AWS security credentials. The backend should determine the object key, sign the request with the intended method and content constraints, and return only the URL and the headers the browser must send.
Rank #2
- Solid state performance with up to 800MB/s read speeds in a portable drive. (Based on internal testing; performance may be lower depending on host device, interface, usage conditions and other factors. 1MB=1,000,000 bytes.)
- Back up your content and memories on a storage solution that fits seamlessly into your mobile lifestyle.
- Take it with you on your adventures—up to two-meter drop protection means this durable drive can take a beating. (Based on internal testing.)
- Secure it to your belt loop or backpack for extra peace of mind thanks to the tough rubber hook.
- From Sandisk, a brand professional photographers trust to take on assignments.
1. Create the bucket and signer permissions
Create or select the target bucket in the intended Region. Configure the backend’s signing identity with only the object permissions required for the upload, scoped to the screenshot prefix where practical. Keep the bucket private; a successful upload does not require making the object publicly readable.
2. Generate the URL on a trusted backend
After authenticating and authorizing the user, generate a short-lived presigned PUT or POST for one unique key, such as screenshots/{generated-id}.png. Apply content constraints that match your application’s needs. If the URL signs a content-type or other header, return that exact header requirement to the client. Do not let a user choose an unrestricted key or issue a URL with broader scope or longer validity than necessary.
3. Send the image bytes from the browser
For a presigned PUT, a browser can send the selected file directly. This example assumes the backend returns JSON with url and contentType, and that its endpoint and response format are implemented by your application:
async function uploadScreenshot(file) {
const signResponse = await fetch('/api/screenshot-upload-url', { method: 'POST' });
if (!signResponse.ok) throw new Error(`Could not get upload URL: ${signResponse.status}`);
const { url, contentType } = await signResponse.json();
const uploadResponse = await fetch(url, {
method: 'PUT',
headers: { 'Content-Type': contentType },
body: file
});
if (!uploadResponse.ok) throw new Error(`S3 upload failed: ${uploadResponse.status}`);
return { uploaded: true, etag: uploadResponse.headers.get('ETag') };
}
The endpoint path and JSON shape above are example application code, not an AWS endpoint. The backend must provide the matching presigned URL, key and content type. If the signed request expects a header, send it exactly as signed; changing a signed header can invalidate the request. Check the response before telling the user the upload succeeded.
Rank #3
- Capacity Display Variance: 500GB external ssd often appears as around 465GB on Windows. MacOS can show full 500 GB capacity. This is binary calculation difference and doesn’t affect SSD hard drive actual physical storage
- 1050 MB/s Speed: Instantly access to your files with blazing-fast 10Gbps external SSD read up to 1050MB/s and write up to 1000MB/s. LED Light indicates USB SSD instant activity
- Data Security: Solid state drives S.M.A.R.T. health diagnostics and adaptive TRIM optimizing data block management ensures consistent write speeds and extends the longevity of the portable SSD
- USB-C & USB-A Cable: Both cables featuring rapid USB 3.2 Gen2, this USB SSD effortlessly bridges devices, enabling seamless cross-platform file transfers and backup between computers, smartphones, tablets and iPhone
- Always Fast: No slowdowns for large file transfers. With SLC caching (25% of current available capacity allocated as high-speed cache), this external SSD delivers steady 10Gbps for transfers within the cache capacity
A presigned POST is another option when an HTML form-style request and policy conditions suit the application. In either case, the browser must send the method, fields, bytes and headers the backend authorized.
Recommended Free Tools
4. Configure S3 CORS for the website
When JavaScript on your site sends a request to an S3 bucket on another origin, the bucket needs a CORS rule matching the site origin, upload method and request headers. For example, a site using PUT with a content-type header needs a rule allowing that origin, PUT, and the header it sends. Do not use a broad origin or header allowance unless the application actually requires it. Expose a response header such as ETag only if client code needs to read it.
S3 evaluates the first CORS rule that matches the request. Check that the rule covers the exact production origin, method and requested headers; a rule for a different hostname or method will not match. CORS does not override IAM or bucket policies and cannot make a denied upload authorized.
5. Record the result and deliver the object safely
After S3 returns a successful response, have the application record or return the object key. Do not assume a browser response alone makes the object safe to publish. Keep delivery access separate from upload access: use controlled reads or a CDN if users need to view screenshots.
Or skip the browser setup
If your goal is to obtain a website screenshot rather than upload an existing file, ScreenshotNeo can return a screenshot through one API request; you can then store the returned bytes in S3 from your trusted application. Cookie banners, popups and chat widgets are removed before the shot. Bot checks, blank pages and failed loads are never billed. Its MCP server lets AI agents take screenshots, and 1,000 screenshots a month are free with no card; paid plans start at $5 for 3,000.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →For example, fetch a screenshot and write it locally, then upload that file using the CLI command above. See the ScreenshotNeo documentation for API details.
Rank #4
- NEARLY 2X FASTER THAN OUR PREVIOUS GENERATION(8) – move 1,000 high-res photos in under 60 seconds(6) with up to 2000MB/s transfer speeds(2).
- IP65 RATING AND UP TO 3M DROP PROTECTION(3) – protects against spills and drops.
- POCKET-SIZED – fits easily in pockets and small bags.
- SPACE TO OWN YOUR AI CONTENT – speed and capacity to download your high-res clips and photo edits.
- 256-BIT AES ENCRYPTION(4) – helps keep private files secure with password protection.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Sign up for 1,000 free screenshots a month with no card.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Troubleshoot failed uploads
S3 returns 403 Forbidden
A 403 can indicate missing or mismatched IAM permissions, a bucket-policy denial, the wrong object key or Region, a bad signature, or an expired URL or credentials. First check the signing principal’s permission for the exact key and verify the URL has not expired. Then confirm that the method, signed headers and content type match the request and that the bucket and signer agree on the Region.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →The browser reports a CORS error
Check the browser’s network request and match its origin, method and requested headers against the bucket CORS rule. Confirm that the rule applies to the production hostname and that no earlier matching rule has different allowances. A CORS change only affects cross-origin browser access; if S3 denies the write, fix IAM, the bucket policy, signature or URL rather than loosening CORS.
The signature is invalid
Send the exact HTTP method and any signed headers the backend used when creating the URL. A changed content type or omitted signed header can invalidate the request. Also check that the URL has not expired and that the signer’s credentials were valid when it was created.
Best Value
- Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
The upload succeeds but the object is missing or overwritten
Verify the exact bucket and key returned by the signer. Reusing a key replaces the existing object unless bucket versioning is enabled, in which case S3 retains a new version. Generate unique keys and store the resulting key with the application record.
Performance, reliability and cost considerations
For browser uploads, sending bytes directly to S3 avoids routing the image payload through your application server, while still requiring that server to authorize each upload. Keep the presigned URL short-lived and issue it only after your application checks the user and intended upload. If the application needs to confirm a file’s properties or apply additional checks, plan that validation separately; a successful S3 response only confirms the storage request was accepted.
Free tools Windows power users keep installed
One-click scans. No signup required.
Screenshot upload costs depend on the AWS resources and delivery pattern used; the cited S3 documentation does not establish a universal screenshot-upload price or performance benchmark. Avoid treating the console’s documented maximum file size as a performance target: AWS states that the S3 console upload maximum is 160 GB for a file, far above ordinary screenshot sizes. See AWS: Uploading objects for that console limit and the upload workflow.
Frequently asked questions
Does a presigned URL make an S3 object public?
No. It authorizes the specified request for a limited time; it does not by itself make the object publicly readable. Keep upload and read access as separate decisions.
Should I use PUT or POST?
Use the method your backend signs. PUT sends the file as the request body; POST uses a form-style request with policy fields. The bucket CORS rule and browser request must match the chosen method.
Can I upload a screenshot from a browser without CORS?
A cross-origin browser request to S3 needs a matching CORS rule to be available to the web application. CORS is separate from authorization, so the request also needs valid signing and AWS permissions.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

