<!DOCTYPE html>
    <html xmlns="http://www.w3.org/1999/xhtml" lang="en-US"><head><meta http-equiv="Content-Type" content="text/html; charset=UTF-8" /><title>AWS Signature Version 4 for API requests - AWS Identity and Access Management</title><meta name="viewport" content="width=device-width,initial-scale=1" /><meta name="assets_root" content="/assets" /><meta name="target_state" content="reference_sigv" /><meta name="default_state" content="reference_sigv" /><link rel="icon" type="image/ico" href="/assets/images/favicon.ico" /><link rel="shortcut icon" type="image/ico" href="/assets/images/favicon.ico" /><link rel="canonical" href="https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_sigv.html" /><meta name="description" content="Learn about the AWS Signature Version 4 signing process for AWS API requests. Learn how AWS SigV4 works, when to sign API requests, and why requests are signed." /><meta name="deployment_region" content="IAD" /><meta name="product" content="AWS Identity and Access Management" /><meta name="guide" content="User Guide" /><meta name="abstract" content="Control access to your AWS resources with user identity (authentication) and with policies that define specific permissions (authorization)." /><meta name="guide-locale" content="en_us" /><meta name="tocs" content="toc-contents.json" /><link rel="canonical" href="https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_sigv.html" /><link rel="alternate" href="https://docs.aws.amazon.com/id_id/IAM/latest/UserGuide/reference_sigv.html" hreflang="id-id" /><link rel="alternate" href="https://docs.aws.amazon.com/id_id/IAM/latest/UserGuide/reference_sigv.html" hreflang="id" /><link rel="alternate" href="https://docs.aws.amazon.com/de_de/IAM/latest/UserGuide/reference_sigv.html" hreflang="de-de" /><link rel="alternate" href="https://docs.aws.amazon.com/de_de/IAM/latest/UserGuide/reference_sigv.html" hreflang="de" /><link rel="alternate" href="https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_sigv.html" hreflang="en-us" /><link rel="alternate" href="https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_sigv.html" hreflang="en" /><link rel="alternate" href="https://docs.aws.amazon.com/es_es/IAM/latest/UserGuide/reference_sigv.html" hreflang="es-es" /><link rel="alternate" href="https://docs.aws.amazon.com/es_es/IAM/latest/UserGuide/reference_sigv.html" hreflang="es" /><link rel="alternate" href="https://docs.aws.amazon.com/fr_fr/IAM/latest/UserGuide/reference_sigv.html" hreflang="fr-fr" /><link rel="alternate" href="https://docs.aws.amazon.com/fr_fr/IAM/latest/UserGuide/reference_sigv.html" hreflang="fr" /><link rel="alternate" href="https://docs.aws.amazon.com/it_it/IAM/latest/UserGuide/reference_sigv.html" hreflang="it-it" /><link rel="alternate" href="https://docs.aws.amazon.com/it_it/IAM/latest/UserGuide/reference_sigv.html" hreflang="it" /><link rel="alternate" href="https://docs.aws.amazon.com/ja_jp/IAM/latest/UserGuide/reference_sigv.html" hreflang="ja-jp" /><link rel="alternate" href="https://docs.aws.amazon.com/ja_jp/IAM/latest/UserGuide/reference_sigv.html" hreflang="ja" /><link rel="alternate" href="https://docs.aws.amazon.com/ko_kr/IAM/latest/UserGuide/reference_sigv.html" hreflang="ko-kr" /><link rel="alternate" href="https://docs.aws.amazon.com/ko_kr/IAM/latest/UserGuide/reference_sigv.html" hreflang="ko" /><link rel="alternate" href="https://docs.aws.amazon.com/pt_br/IAM/latest/UserGuide/reference_sigv.html" hreflang="pt-br" /><link rel="alternate" href="https://docs.aws.amazon.com/pt_br/IAM/latest/UserGuide/reference_sigv.html" hreflang="pt" /><link rel="alternate" href="https://docs.aws.amazon.com/zh_cn/IAM/latest/UserGuide/reference_sigv.html" hreflang="zh-cn" /><link rel="alternate" href="https://docs.aws.amazon.com/zh_tw/IAM/latest/UserGuide/reference_sigv.html" hreflang="zh-tw" /><link rel="alternate" href="https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_sigv.html" hreflang="x-default" /><meta name="feedback-item" content="IAM" /><meta name="this_doc_product" content="AWS Identity and Access Management" /><meta name="this_doc_guide" content="User Guide" /><head xmlns="http://www.w3.org/1999/xhtml"> <script defer="" src="/assets/r/awsdocs-doc-page.2.0.0.js"></script><link href="/assets/r/awsdocs-doc-page.2.0.0.css" rel="stylesheet"/></head>
<script defer="" id="awsc-panorama-bundle" type="text/javascript" src="https://prod.pa.cdn.uis.awsstatic.com/panorama-nav-init.js" data-config="{'appEntity':'aws-documentation','region':'us-east-1','service':'iam'}"></script><meta id="panorama-serviceSubSection" value="User Guide" /><meta id="panorama-serviceConsolePage" value="AWS Signature Version 4 for API requests" /></head><body class="awsdocs awsui"><div class="awsdocs-container"><p><a href="reference_sigv.md">View a markdown version of this page</a></p><awsdocs-header></awsdocs-header><awsui-app-layout id="app-layout" class="awsui-util-no-gutters" ng-controller="ContentController as $ctrl" header-selector="awsdocs-header" navigation-hide="false" navigation-width="$ctrl.navWidth" navigation-open="$ctrl.navOpen" navigation-change="$ctrl.onNavChange($event)" tools-hide="$ctrl.hideTools" tools-width="$ctrl.toolsWidth" tools-open="$ctrl.toolsOpen" tools-change="$ctrl.onToolsChange($event)"><div id="guide-toc" dom-region="navigation"><awsdocs-toc></awsdocs-toc></div><div id="main-column" dom-region="content" tabindex="-1"><awsdocs-view class="awsdocs-view"><div id="awsdocs-content"><head><title>AWS Signature Version 4 for API requests - AWS Identity and Access Management</title><meta name="pdf" content="/pdfs/IAM/latest/UserGuide/iam-ug.pdf#reference_sigv" /><meta name="rss" content="aws-iam-release-notes.rss" /><meta name="forums" content="https://repost.aws/tags/TAO7Z4bI5hQVWMiYFs34QhIA" /><meta name="feedback" content="https://docs.aws.amazon.com/forms/aws-doc-feedback?hidden_service_name=IAM&amp;topic_url=https://docs.aws.amazon.com/en_us/IAM/latest/UserGuide/reference_sigv.html" /><meta name="feedback-yes" content="feedbackyes.html?topic_url=https://docs.aws.amazon.com/en_us/IAM/latest/UserGuide/reference_sigv.html" /><meta name="feedback-no" content="feedbackno.html?topic_url=https://docs.aws.amazon.com/en_us/IAM/latest/UserGuide/reference_sigv.html" /><meta name="keywords" content="IAM,AWS Identity and Access Management,IAM user,user,IAM group,group,IAM role,role,permission policy,trust policy,policy,access key,password,Amazon Resource Names,ARNs,IAM quotas,AWS STS quotas,VPC endpoints,SigV4,SigV4a,JSON policy elements,AWS sigv4,AWS sigv4a,AWS request signing,AWS API authentication" /><link rel="alternate" type="text/markdown" href="reference_sigv.md" title="Markdown version" /><script type="application/ld+json">
{
    "@context" : "https://schema.org",
    "@type" : "BreadcrumbList",
    "itemListElement" : [
      {
        "@type" : "ListItem",
        "position" : 1,
        "name" : "AWS",
        "item" : "https://aws.amazon.com"
      },
      {
        "@type" : "ListItem",
        "position" : 2,
        "name" : "AWS Identity and Access Management",
        "item" : "https://docs.aws.amazon.com/iam/index.html"
      },
      {
        "@type" : "ListItem",
        "position" : 3,
        "name" : "User Guide",
        "item" : "https://docs.aws.amazon.com/IAM/latest/UserGuide"
      },
      {
        "@type" : "ListItem",
        "position" : 4,
        "name" : "Reference information for AWS Identity and Access Management",
        "item" : "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference.html"
      },
      {
        "@type" : "ListItem",
        "position" : 5,
        "name" : "AWS Signature Version 4 for API requests",
        "item" : "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference.html"
      }
    ]
}
</script></head><body><div id="main"><div style="display: none"><a href="/pdfs/IAM/latest/UserGuide/iam-ug.pdf#reference_sigv" target="_blank" rel="noopener noreferrer" title="Open PDF"></a></div><div id="breadcrumbs" class="breadcrumb"><a href="/index.html">Documentation</a><a href="/iam/index.html">AWS Identity and Access Management</a><a href="introduction.html">User Guide</a></div><div id="page-toc-src"><a href="#how-aws-signing-works">How AWS SigV4 works</a><a href="#how-sigv4a-works">How AWS SigV4a works</a><a href="#when-do-you-need-to-sign">When to sign requests</a><a href="#why-requests-are-signed">Why requests are signed</a><a href="#reference_aws-signing-resources">Additional resources</a></div><div id="main-content" class="awsui-util-container"><div id="main-col-body"><awsdocs-language-banner data-service="$ctrl.pageService"></awsdocs-language-banner><h1 class="topictitle" id="reference_sigv">AWS Signature Version 4 for API requests</h1><div class="awsdocs-page-header-container"><awsdocs-page-header></awsdocs-page-header><awsdocs-filter-selector id="awsdocs-filter-selector"></awsdocs-filter-selector></div><div class="awsdocs-note awsdocs-important"><div class="awsdocs-note-title"><awsui-icon name="status-warning" variant="error"></awsui-icon><h6>Important</h6></div><div class="awsdocs-note-text"><p>If you use an AWS SDK (see <a href="https://aws.amazon.com/developer/" rel="noopener noreferrer" target="_blank"><span>Sample Code and
                Libraries</span><awsui-icon class="awsdocs-link-icon" name="external"></awsui-icon></a>) or AWS Command Line Interface (AWS CLI) tool to send API requests to AWS, you can
            skip the signature process, as the SDK and CLI clients authenticate your requests by
            using the access keys that you provide. Unless you have a good reason not to, we
            recommend that you always use an SDK or the CLI.</p><p>In Regions that support multiple signature versions, manually signing requests means
            you must specify which signature version to use. When you supply requests to
            Multi-Region Access Points, SDKs and the CLI automatically switch to using Signature
            Version 4A without additional configuration.</p></div></div><p>Authentication information that you send in a request must include a signature. AWS
        Signature Version 4 (SigV4) is the AWS signing protocol for adding authentication
        information to AWS API requests.</p><p>You don't use your secret access key to sign API requests. Instead, you use the SigV4
        signing process. Signing requests involves:</p><div class="orderedlist">
         
         
         
    <ol><li>
            <p>Creating a canonical request based on the request details.</p>
        </li><li>
            <p>Calculating a signature using your AWS credentials.</p>
        </li><li>
            <p>Adding this signature to the request as an Authorization header.</p>
        </li></ol></div><p>AWS then replicates this process and verifies the signature, granting or denying access
        accordingly.</p><p>Symmetric SigV4 requires you to derive a key that is scoped to a single AWS service, in
        a single AWS region, on a particular day. This makes the key and calculated signature
        different for each region, meaning you must know the region the signature is destined
        for.</p><p>Asymmetric Signature Version 4 (SigV4a) is an extension that supports signing with a new
        algorithm, and generating individual signatures that are verifiable in more than one AWS
        region. With SigV4a, you can sign a request for multiple regions, with seamless routing and
        failover between regions. When you use the AWS SDK or AWS CLI to invoke functionality that
        requires multi-region signing, the signature type is automatically changed to use SigV4a.
        For details, see <a href="#how-sigv4a-works">How AWS SigV4a works</a>.</p>
        <h2 id="how-aws-signing-works">How AWS SigV4 works</h2>
        <p>The following steps describe the general process of computing a signature with SigV4:</p>
        <div class="orderedlist">
             
             
             
        <ol><li>
                <p>The <b>string to sign</b> depends on the request
                    type. For example, when you use the HTTP Authorization header or the query
                    parameters for authentication, you use a combination of request elements to
                    create the string to sign. For an HTTP POST request, the <code class="code">POST</code>
                    policy in the request is the string you sign.</p>
            </li><li>
                <p>The <b>signing key</b> is a series of calculations,
                    with the result of each step fed into the next. The final step is the signing
                    key.</p>
            </li><li>
                <p>When an AWS service receives an authenticated request, it recreates the
                        <b>signature</b> using the authentication
                    information contained in the request. If the signatures match, the service
                    processes the request. Otherwise, it rejects the request.</p>
            </li></ol></div>
        <p>For more information, see <a href="./reference_sigv-signing-elements.html">Elements of an AWS API request signature</a>.</p>
     
        <h2 id="how-sigv4a-works">How AWS SigV4a works</h2>        
        <p>SigV4a uses asymmetric signatures based on public-private key cryptography. SigV4a
            goes through a similar scoped credentials derivation process as SigV4, except SigV4a
            uses the same key to sign all requests without needing to derive a distinct signing key
            based on the date, service, and region. An <a href="https://csrc.nist.gov/glossary/term/ecdsa" rel="noopener noreferrer" target="_blank"><span>Elliptic Curve Digital Signature
                Algorithm</span><awsui-icon class="awsdocs-link-icon" name="external"></awsui-icon></a> (ECDSA) keypair can be derived from your existing AWS secret
            access key.</p>
        <p>The system uses asymmetric cryptography to verify multi-region signatures, so that
            AWS only needs to store your public keys. Public keys are not secret and can't be used
            to sign requests. Asymmetric signatures are required for multi-region API requests, such
            as with Amazon S3 Multi-Region Access Points.</p>
        <p>The following steps describe the general process of computing a signature with SigV4a:</p>
        <div class="orderedlist">
             
             
             
        <ol><li>
                <p>The <b>string to sign</b> depends on the request
                    type. For example, when you use the HTTP Authorization header or the query
                    parameters for authentication, you use a combination of request elements to
                    create the string to sign. For an HTTP POST request, the <code class="code">POST</code>
                    policy in the request is the string you sign.</p>
            </li><li>
                <p>The <b>signing key</b> is derived from an AWS
                    secret access key through a series of calculations, with the result of each step
                    fed into the next. The final step produces the keypair.</p>
            </li><li>
                <p>When an AWS service receives a request signed with SigV4a, AWS verifies
                    the signature using only the public half of the keypair. If the signature is
                    valid, the request is authenticated and the service processes the request.
                    Requests with invalid signatures are rejected.</p>
            </li></ol></div>

        <p>For more information about SigV4a for multi-Region API requests, see the <a href="https://github.com/aws-samples/sigv4a-signing-examples" rel="noopener noreferrer" target="_blank"><span>sigv4a-signing-examples</span><awsui-icon class="awsdocs-link-icon" name="external"></awsui-icon></a> project on GitHub.</p>
     
        <h2 id="when-do-you-need-to-sign">When to sign requests</h2>

        <p>When you write custom code that sends API requests to AWS, you must include code
            that signs the requests. You might write custom code because:</p>
        <div class="itemizedlist">
             
             
        <ul class="itemizedlist"><li class="listitem">
                <p>You are working with a programming language for which there is no AWS
                    SDK.</p>
            </li><li class="listitem">
                <p>You need complete control over how requests are sent to AWS.</p>
            </li></ul></div>
        <p>While API requests authenticate access with AWS SigV4, AWS SDKs and the AWS CLI
            authenticate your requests by using the access keys that you provide. For more
            information about authenticating with AWS SDKs and the AWS CLI, see <a href="#reference_aws-signing-resources">Additional resources</a>.</p>
     
        <h2 id="why-requests-are-signed">Why requests are signed</h2>
        <p>The signing process helps secure requests in the following ways:</p>
        <div class="itemizedlist">
             
             
             
        <ul class="itemizedlist"><li class="listitem">
                <p><span class="topcom">Verify the identity of the requester</span></p>
                <p>Authenticated requests require a signature that you create by using your
                    access keys (access key ID, secret access key). If you are using temporary
                    security credentials, the signature calculations also require a security token.
                    For more information, see <a href="./security-creds-programmatic-access.html">AWS security credentials programmatic access</a>.</p>
            </li><li class="listitem">
                <p><span class="topcom">Protect data in transit</span></p>
                <p>To prevent tampering with a request while it's in transit, some of the request
                    elements are used to calculate a hash (digest) of the request, and the resulting
                    hash value is included as part of the request. When an AWS service receives
                    the request, it uses the same information to calculate a hash and matches it
                    against the hash value in your request. If the values don't match, AWS denies
                    the request.</p>
            </li><li class="listitem">
                <p><span class="topcom">Protect against potential replay attacks</span></p>
                <p>In most cases, a request must reach AWS within five minutes of the time
                    stamp in the request. Otherwise, AWS denies the request.</p>
            </li></ul></div>
        <p>AWS SigV4 can be expressed in the HTTP Authorization header or as a query string in
            the URL. For more information, see <a href="./reference_sigv-authentication-methods.html">Authentication methods</a>.</p>
     
        <h2 id="reference_aws-signing-resources">Additional resources</h2>
        <div class="itemizedlist">
             
             
             
             
        <ul class="itemizedlist"><li class="listitem">
                <p>For more information about the SigV4 signing process for different services,
                    see <a href="./reference_sigv-examples.html">Request signature examples</a>.</p>
            </li><li class="listitem">
                <p>To configure credentials for programmatic access for the AWS CLI, see <a href="https://docs.aws.amazon.com/cli/latest/userguide/cli-chap-authentication.html">Authentication and access credentials</a> in the <em>AWS
                        Command Line Interface User Guide</em>.</p>
            </li><li class="listitem">
                <p>The AWS SDKs include source code on GitHub for signing AWS API requests.
                    For code samples, see <a href="./reference_sigv-examples.html#signature-v4-examples-sdk">Example projects in AWS samples repository</a>.</p>
                <div class="itemizedlist">
                     
                     
                     
                     
                     
                     
                     
                     
                <ul class="itemizedlist"><li class="listitem">
                        <p>AWS SDK for .NET – <a href="https://github.com/aws/aws-sdk-net/blob/main/sdk/src/Core/Amazon.Runtime/Signing/AWSSigV4Signer.cs" rel="noopener noreferrer" target="_blank"><span>AWSSigV4Signer.cs</span><awsui-icon class="awsdocs-link-icon" name="external"></awsui-icon></a></p>
                    </li><li class="listitem">
                        <p>AWS SDK for C++ – <a href="https://github.com/aws/aws-sdk-cpp/blob/main/src/aws-cpp-sdk-core/source/auth/signer/AWSAuthV4Signer.cpp" rel="noopener noreferrer" target="_blank"><span>AWSAuthV4Signer.cpp</span><awsui-icon class="awsdocs-link-icon" name="external"></awsui-icon></a></p>
                    </li><li class="listitem">
                        <p>AWS SDK for Go – <a href="https://github.com/aws/smithy-go/blob/a4c9efcda6aa54c75d1a130d1320a2709eebf51d/aws-http-auth/sigv4/sigv4.go" rel="noopener noreferrer" target="_blank"><span>sigv4.go</span><awsui-icon class="awsdocs-link-icon" name="external"></awsui-icon></a></p>
                    </li><li class="listitem">
                        <p>AWS SDK for Java – <a href="https://github.com/aws/aws-sdk-java-v2/blob/master/core/auth/src/main/java/software/amazon/awssdk/auth/signer/internal/BaseAws4Signer.java" rel="noopener noreferrer" target="_blank"><span>BaseAws4Signer.java</span><awsui-icon class="awsdocs-link-icon" name="external"></awsui-icon></a></p>
                    </li><li class="listitem">
                        <p>AWS SDK for JavaScript – <a href="https://github.com/smithy-lang/smithy-typescript/tree/main/packages/signature-v4" rel="noopener noreferrer" target="_blank"><span>signature-v4</span><awsui-icon class="awsdocs-link-icon" name="external"></awsui-icon></a></p>
                    </li><li class="listitem">
                        <p>AWS SDK for PHP – <a href="https://github.com/aws/aws-sdk-php/blob/master/src/Signature/SignatureV4.php" rel="noopener noreferrer" target="_blank"><span>SignatureV4.php</span><awsui-icon class="awsdocs-link-icon" name="external"></awsui-icon></a></p>
                    </li><li class="listitem">
                        <p>AWS SDK for Python (Boto) – <a href="https://github.com/boto/botocore/blob/develop/botocore/signers.py" rel="noopener noreferrer" target="_blank"><span>signers.py</span><awsui-icon class="awsdocs-link-icon" name="external"></awsui-icon></a></p>
                    </li><li class="listitem">
                        <p>AWS SDK for Ruby – <a href="https://github.com/aws/aws-sdk-ruby/blob/version-3/gems/aws-sigv4/lib/aws-sigv4/signer.rb" rel="noopener noreferrer" target="_blank"><span>signer.rb</span><awsui-icon class="awsdocs-link-icon" name="external"></awsui-icon></a></p>
                    </li></ul></div>
            </li><li class="listitem">
                <p>If you encounter errors when signing requests, see <a href="./reference_sigv-troubleshooting.html">Troubleshoot Signature Version 4 signing for AWS API requests</a>.</p>
            </li></ul></div>
    <awsdocs-copyright class="copyright-print"></awsdocs-copyright><awsdocs-thumb-feedback right-edge="{{$ctrl.thumbFeedbackRightEdge}}"></awsdocs-thumb-feedback></div><noscript><div><div><div><div id="js_error_message"><p><img src="https://d1ge0kk1l5kms0.cloudfront.net/images/G/01/webservices/console/warning.png" alt="Warning" /> <strong>Javascript is disabled or is unavailable in your browser.</strong></p><p>To use the Amazon Web Services Documentation, Javascript must be enabled. Please refer to your browser's Help pages for instructions.</p></div></div></div></div></noscript><div id="main-col-footer" class="awsui-util-font-size-0"><div id="doc-conventions"><a target="_top" href="/general/latest/gr/docconventions.html">Document Conventions</a></div><div class="prev-next"><div id="previous" class="prev-link" accesskey="p" href="./reference_aws-services-that-work-with-iam.html">Services that work with IAM</div><div id="next" class="next-link" accesskey="n" href="./reference_sigv-signing-elements.html">SigV4 request
            elements</div></div></div><awsdocs-page-utilities></awsdocs-page-utilities></div><div id="quick-feedback-yes" style="display: none;"><div class="title">Did this page help you? - Yes</div><div class="content"><p>Thanks for letting us know we're doing a good job!</p><p>If you've got a moment, please tell us what we did right so we can do more of it.</p><p><awsui-button id="fblink" rel="noopener noreferrer" target="_blank" text="Feedback" click="linkClick($event)" href="https://docs.aws.amazon.com/forms/aws-doc-feedback?hidden_service_name=IAM&amp;topic_url=https://docs.aws.amazon.com/en_us/IAM/latest/UserGuide/reference_sigv.html"></awsui-button></p></div></div><div id="quick-feedback-no" style="display: none;"><div class="title">Did this page help you? - No</div><div class="content"><p>Thanks for letting us know this page needs work. We're sorry we let you down.</p><p>If you've got a moment, please tell us how we can make the documentation better.</p><p><awsui-button id="fblink" rel="noopener noreferrer" target="_blank" text="Feedback" click="linkClick($event)" href="https://docs.aws.amazon.com/forms/aws-doc-feedback?hidden_service_name=IAM&amp;topic_url=https://docs.aws.amazon.com/en_us/IAM/latest/UserGuide/reference_sigv.html"></awsui-button></p></div></div></div></body></div></awsdocs-view><div class="page-loading-indicator" id="page-loading-indicator"><awsui-spinner size="large"></awsui-spinner></div></div><div id="tools-panel" dom-region="tools"><awsdocs-tools-panel id="awsdocs-tools-panel"></awsdocs-tools-panel></div></awsui-app-layout><awsdocs-cookie-banner class="doc-cookie-banner"></awsdocs-cookie-banner></div></body></html>