How do I set up an Amazon S3 bucket?
- Create an S3 bucket in your chosen AWS Region. Keep Block Public Access enabled and use Bucket owner enforced Object Ownership for a private bucket. Record the bucket name and region.
- Configure a dedicated AWS identity for Transloadit, restricted to the destination bucket and prefix. Follow the /s3/store permission policy, including its additional permissions for tags, region discovery and encryption. Do not use root access keys.
- Save an Amazon S3 Template Credential with the access key ID (
key), secret access key (secret),bucketandbucket_region. Keep AWS secrets on trusted backends. For short-lived AWS credentials, follow the Robot’s temporary-credential guidance. - Reference the credential’s name in your Template and explicitly set
acl: "bucket-default". Omittingacluses the Robot’spublic-readdefault;privatealso sends an ACL. The following example omits the ACL header and writes under the policy’suploads/prefix:
{
"steps": {
":original": {
"robot": "/upload/handle"
},
"exported": {
"robot": "/s3/store",
"use": ":original",
"credentials": "YOUR_S3_CREDENTIALS",
"acl": "bucket-default",
"path": "uploads/${unique_prefix}/${file.url_name}"
}
}
}
- Replace
YOUR_S3_CREDENTIALSwith the saved credential name. Saving credentials does not authorize uploads: authenticate users and authorize uploads on your backend, and make Signature Authentication mandatory for signed browser flows. Follow the credential and instruction protection guidance before exposing an upload flow. - Test the Template with a non-sensitive file, check the completed Assembly Status, and verify the object in your bucket. A returned result URL does not grant public read access. Write permission can overwrite existing keys; choose unique paths and consider S3 versioning for recovery.
More
- For more details about Templates and security, see our Template documentation.
- For more information on saving to S3, such as how to customize file names, see the 🤖/s3/store documentation.
- To upload files from your own Node.js application, follow the Amazon S3 upload tutorial. The file storage tutorials also cover curl and rclone workflows.