Docs / Strand / connectors/aws-s3

AWS S3

Direction: Read / Write | Type: aws.s3

Amazon Simple Storage Service connector for reading and writing objects to S3 buckets.

Required Permissions#

The IAM user or role must have the following permissions:

Operation Required IAM Permissions
put_object s3:PutObject
get_object s3:GetObject
list_objects s3:ListBucket
Tip: Scope permissions to specific bucket ARNs (e.g., arn:aws:s3:::my-bucket for bucket-level and arn:aws:s3:::my-bucket/* for object-level actions) to follow the principle of least privilege.

Operations#

Operation Direction Description
put_object Write Upload data to an S3 bucket
get_object Read Read an object's contents into the workflow as JSON
list_objects Read List objects in a bucket
Info

The get_object operation reads the object content into the node's output payload as JSON. It does not download or save files to disk.

Connector Configuration#

Field Required Default Description
Authentication Type No api_key Uses explicit credentials (the fields below).
Region Yes - AWS region code (e.g., us-east-1, eu-west-1)
Endpoint URL No - Custom endpoint for an S3-compatible store — MinIO, Cloudflare R2, Backblaze B2, Wasabi — or an AWS VPC endpoint. Leave empty for AWS. Path-style addressing is used automatically when set.
Access Key ID Conditional - AWS access key (encrypted). Required when Authentication Type is api_key
Secret Access Key Conditional - AWS secret key (encrypted). Required when Authentication Type is api_key
Bucket No - Default S3 bucket name (can be overridden at node level)

S3-compatible storage#

The connector speaks the S3 API, so it works against anything that does. Set Endpoint URL to your provider's endpoint and leave the rest of the fields as they are — the access key, secret and bucket all mean the same thing.

Provider Endpoint URL
MinIO https://minio.example.com (your own host)
Cloudflare R2 https://<account-id>.r2.cloudflarestorage.com
Backblaze B2 https://s3.<region>.backblazeb2.com
Wasabi https://s3.<region>.wasabisys.com

Region still has to be set — most S3-compatible providers accept us-east-1 as a placeholder — and path-style addressing is applied automatically, which is what these providers expect.

Note

Test Connection reports that it reached the endpoint but does not verify your credentials against it. S3-compatible providers do not implement AWS STS, which is what the credential check uses. Run the connector once to confirm the keys work.

Node Configuration#

Field Required Description
Operation Yes put_object, get_object, or list_objects
Bucket No S3 bucket name (overrides connector default)
Key Depends Object key/path. Required for put_object and get_object. Supports Jinja2.

Output#

put_object#

json

{
  "success": true,
  "status": "uploaded",
  "data": {
    "bucket": "my-bucket",
    "key": "path/to/file.json",
    "etag": "abc123"
  },
  "service": "aws.s3",
  "operation": "put_object"
}

get_object#

json

{
  "success": true,
  "status": "downloaded",
  "data": {
    "bucket": "my-bucket",
    "key": "path/to/file.json",
    "content": {"your": "data"}
  },
  "service": "aws.s3",
  "operation": "get_object"
}

Access the content in subsequent nodes:

jinja2

{{ payload.data.content }}
{{ payload.data.content.your }}

Example#

Connector Setup:

json

{
  "region": "us-east-1",
  "access_key_id": "AKIAIOSFODNN7EXAMPLE",
  "secret_access_key": "wJalrXUtnFEMI/K7MDENG...",
  "bucket": "my-data-bucket"
}

Node Configuration (upload):

Node Configuration (read):