AWS Presigned URL Inspector
Inspect SigV4 credential scope, signed headers and expiration without requesting the URL
The tool does not request the URL and cannot verify signature correctness without AWS credentials.
Credential scope, signing time, expiry, and SignedHeaders will appear here.
About this tool
Inspect AWS4-HMAC-SHA256 query fields without requesting the URL. The tool checks supported parameter shapes, credential scope and calendar dates, then reports signed headers and expiration at the moment of inspection. Required parameter names are case-sensitive and duplicates are rejected. Signature and credential fragments are masked in the report, but no cryptographic verification or AWS access check is performed.
Scenario Recipes
Triage an S3 link reported as expired
Goal: Separate timestamp problems from signature or policy problems
- Paste the complete presigned URL without requesting it.
- Compare signed-at and expires-at values with the current status.
- If time remains valid, investigate credentials, session expiry, policy, object path, and canonical signing inputs.
Result: A timestamp and credential-scope report that narrows the AWS investigation.
Frequently Asked Questions
What does Not expired at inspection mean?
It means the computer clock was at or after X-Amz-Date and before that time plus X-Amz-Expires when Inspect was clicked. The label is a snapshot, not a live countdown or confirmation that AWS accepts the URL.
Which expiry and date forms are supported?
This inspector accepts real UTC calendar timestamps in YYYYMMDDTHHMMSSZ form and decimal integer durations from 1 to 604800 seconds, matching the S3 SigV4 query range. Credential scope must use the same date. Impossible dates, scientific notation and duplicate fields are rejected.
Does a well-formed 64-character signature prove authenticity?
No. Checking hexadecimal length only checks syntax. Verification also needs the signing key and the exact canonical request; the URL alone cannot establish the signature, host ownership or account permissions.
Why might a URL fail before its stated expiry?
Temporary credentials can expire earlier; permissions, policies, key revocation, object state and request method or headers can also invalidate access. The page does not test these conditions.
Is it safe to share the copied report?
The report masks the access key identifier and excludes signature and session-token values, but still includes the host, resource path, region and service. Review those details before sharing. Input is not uploaded or saved as a draft.
Keep browsing