AWS

AWS Presigned URL Inspector

Inspect SigV4 credential scope, signed headers and expiration without requesting the URL

Security & Auth
πŸ”’ 100% client-side β€” your data never leaves this page
Maintained by Evanβ€’Updated: September 30, 2026
AWS SigV4 URL

The tool does not request the URL and cannot verify signature correctness without AWS credentials.

Signature summary

Credential scope, signing time, expiry, and SignedHeaders will appear here.

About this tool

Inspect AWS4-HMAC-SHA256 query fields without requesting the URL. The tool checks supported parameter shapes, credential scope and calendar dates, then reports signed headers and expiration at the moment of inspection. Required parameter names are case-sensitive and duplicates are rejected. Signature and credential fragments are masked in the report, but no cryptographic verification or AWS access check is performed.

Scenario Recipes

01

Triage an S3 link reported as expired

Goal: Separate timestamp problems from signature or policy problems

  1. Paste the complete presigned URL without requesting it.
  2. Compare signed-at and expires-at values with the current status.
  3. If time remains valid, investigate credentials, session expiry, policy, object path, and canonical signing inputs.

Result: A timestamp and credential-scope report that narrows the AWS investigation.

Frequently Asked Questions

What does Not expired at inspection mean?

It means the computer clock was at or after X-Amz-Date and before that time plus X-Amz-Expires when Inspect was clicked. The label is a snapshot, not a live countdown or confirmation that AWS accepts the URL.

Which expiry and date forms are supported?

This inspector accepts real UTC calendar timestamps in YYYYMMDDTHHMMSSZ form and decimal integer durations from 1 to 604800 seconds, matching the S3 SigV4 query range. Credential scope must use the same date. Impossible dates, scientific notation and duplicate fields are rejected.

Does a well-formed 64-character signature prove authenticity?

No. Checking hexadecimal length only checks syntax. Verification also needs the signing key and the exact canonical request; the URL alone cannot establish the signature, host ownership or account permissions.

Why might a URL fail before its stated expiry?

Temporary credentials can expire earlier; permissions, policies, key revocation, object state and request method or headers can also invalidate access. The page does not test these conditions.

Is it safe to share the copied report?

The report masks the access key identifier and excludes signature and session-token values, but still includes the host, resource path, region and service. Review those details before sharing. Input is not uploaded or saved as a draft.

Keep browsing