Transloadit
Pricing
  • File Uploads
  • File Importing
  • Batch Processing
  • Video Encoding
  • Audio Encoding
  • Image Processing
  • Document Processing
  • Artificial Intelligence
  • File Filtering & Security
  • Media Cataloging
  • File Compression
  • Code Evaluation
  • File Exporting
  • Smart CDN
  • View all services
  • Explore integrations
  • Explore live demos
  • Uppy
  • TransloaditKit
  • Android SDK
  • Node.js SDK
  • Python SDK
  • Ruby SDK
  • Go SDK
  • Java SDK
  • PHP SDK
  • Zapier
  • MCP Server
  • Transloadit CLI
  • Terraform
  • Essentials
  • Best Practices
  • FAQ
  • Robots
  • API
  • Formats
  • Build your first app
  • About
  • Comparisons
  • Open Source
  • Testimonials
  • Jobs
  • Security
  • Posts
  • DevTimes
  • DevTips
  • Press
  • Research
  • Case Studies
  • Solutions
  • Guides
  • Glossary
  • Legal
  • Tools
  • Helping Coursera bring education to millions around the world
  • Transloadit Support
  • Open Source Support
  • Service level agreement
EssentialsRobotsFAQAPIFormatsBest Practices

How do I set up an Amazon S3 bucket?

  1. Create an S3 bucket⁠ in your chosen AWS Region. Keep Block Public Access enabled and use Bucket owner enforced Object Ownership for a private bucket. Record the bucket name and region.
  2. Configure a dedicated AWS identity for Transloadit, restricted to the destination bucket and prefix. Follow the /s3/store permission policy, including its additional permissions for tags, region discovery and encryption. Do not use root access keys.
  3. Save an Amazon S3 Template Credential with the access key ID (key), secret access key (secret), bucket and bucket_region. Keep AWS secrets on trusted backends. For short-lived AWS credentials, follow the Robot’s temporary-credential guidance.
  4. Reference the credential’s name in your Template and explicitly set acl: "bucket-default". Omitting acl uses the Robot’s public-read default; private also sends an ACL. The following example omits the ACL header and writes under the policy’s uploads/ prefix:
{
  "steps": {
    ":original": {
      "robot": "/upload/handle"
    },
    "exported": {
      "robot": "/s3/store",
      "use": ":original",
      "credentials": "YOUR_S3_CREDENTIALS",
      "acl": "bucket-default",
      "path": "uploads/${unique_prefix}/${file.url_name}"
    }
  }
}
  1. Replace YOUR_S3_CREDENTIALS with the saved credential name. Saving credentials does not authorize uploads: authenticate users and authorize uploads on your backend, and make Signature Authentication mandatory for signed browser flows. Follow the credential and instruction protection guidance before exposing an upload flow.
  2. Test the Template with a non-sensitive file, check the completed Assembly Status, and verify the object in your bucket. A returned result URL does not grant public read access. Write permission can overwrite existing keys; choose unique paths and consider S3 versioning for recovery.

More

  • For more details about Templates and security, see our Template documentation.
  • For more information on saving to S3, such as how to customize file names, see the 🤖/s3/store documentation.
  • To upload files from your own Node.js application, follow the Amazon S3 upload tutorial. The file storage tutorials also cover curl and rclone workflows.

See also:

What if my imports or exports from Backblaze, S3, GCP, etc. are slow?
How do I limit an sFTP user to one directory?
Why did an Assembly Step produce no results?
Contact support⁠

TransloaditChecking status…

Product

  • Services
  • Pricing
  • Demos
  • Tools
  • Security
  • Support

Company

  • About/Press
  • Blog/Jobs
  • Comparisons/Compliance matrix
  • Research
  • Open source
  • Solutions
  • Pioneers of the web

Docs

  • Getting started
  • Transcoding
  • FAQ
  • API
  • Guides/DevTips
  • Supported formats

More

  • Platform status⁠
  • Community forum⁠
  • Uppy
  • tus⁠

© 2009–2026 Transloadit-II GmbH

PrivacyTermsImprint
EnglishDeutschEspañolPortuguês (Brasil)