Skip to content

S3 Provider — Reference

Reference · Advanced · Server Connect

Configure the endpoint, signing region and credentials used by object-storage actions.

Configure the endpoint, signing region and credentials used by object-storage actions.

  • An object-storage account with a test bucket and credentials limited to the intended operations.

The provider definition creates a storage client for later actions. Selecting it in an action does not provision a bucket or make stored objects public. Definition fields appear when creating/editing the module; an ordinary action selects the existing provider.

Control Meaning
NameThe reusable provider definition name used by storage actions.
ServiceSelects the editor’s AWS, Digital Ocean, Vultr, Linode, Wasabi or Custom endpoint controls. A preset does not guarantee support for every API operation or current region.
Region / EndpointPreset services offer endpoint choices. Custom accepts an endpoint hostname and signing region. The installed wrappers prepend https://, so enter the host rather than a full URL with that scheme already included. Verify current service endpoints with the provider.
Access Key IdThe server-side credential identifier authorized for the intended bucket/key operations.
Secret Access KeyThe corresponding secret. Do not expose it in page code, output or client upload configuration.
Force path styleNode.js passes this to the SDK to request path-style addressing. The installed PHP provider does not pass an equivalent flag, so do not assume identical behavior for a custom endpoint.

Save a test provider and start with the permitted read/list operation for an existing test bucket. Then test a new scoped object key and the required upload/download flow. A successful list call does not prove that writes, deletes, signed requests or cross-bucket copies are allowed.

AWS disables ACLs by default for new buckets using Bucket owner enforced ownership. Such buckets accept uploads without an ACL or with bucket-owner-full-control; other ACLs can be rejected. Wappler’s Access control is therefore not a complete bucket-access policy. See AWS Object Ownership. Check the saved ACL option and your provider’s policy before changing access settings.

A presigned URL grants the specified operation using the signer’s permissions until its effective expiry. It can be reused while valid, and uploading to an existing key can replace that object. Keep the URL private and choose an authorized destination before signing. See AWS presigned URLs. Signing is separate from transferring and validating bytes.

Connect the storage operation to explicit server authorization, file validation and metadata persistence. Do not treat a generated Location string as proof that an object is public.

You can select an endpoint/region and credential scope appropriate to the storage operations your application needs.