Visitar URL original
Build. Sign. Send. | Apache Reqsign™
Skip to main content
Apache Reqsign™ — Request Signing

Build. Sign. Send.

Sign HTTP requests, load cloud credentials, and grant scoped access — without pulling in a full vendor SDK.

9signing providers
5granting operations
5WASM-ready providers
0vendor SDKs required
$ cargo add reqsign --features aws
use reqsign::aws;
// Create a default signer for S3 in us-east-1
let signer = aws::default_signer("s3", "us-east-1");

// Build a request
let mut req = http::Request::builder()
.method(http::Method::GET)
.uri("https://s3.amazonaws.com/my-bucket/my-object")
.body(())
.unwrap()
.into_parts()
.0;

// Sign the request
signer.sign(&mut req, None).await?;
Proven in production

Apache OpenDAL™ signs every cloud storage request — S3, GCS, Azure Blob, COS, TOS, and more — through Reqsign.

uv the Python package manager, authenticates to AWS, Azure, and Google Cloud with Reqsign.

Why Reqsign

The signing layer, and nothing else.

Reqsign keeps each provider's protocol explicit while sharing one composition pattern — so your client stays yours.

01

Signing without a full SDK

Build requests with plain http types, sign them in place, and send with any client. Encoded URIs, atomic request mutation, and expiration follow explicit, documented contracts.

02

Credentials that fit the provider

Every provider keeps its own credential semantics. Default chains cover environment, config files, instance metadata, OIDC federation, CLIs, and credential processes.

03

Scoped access you can grant

One Granter abstraction covers S3 Access Grants, S3 Express sessions, Azure user delegation SAS, and GCP Credential Access Boundary — downscoping that vendor SDKs rarely unify.

04

A runtime you control

Context makes file reading, HTTP sending, environment, and command execution pluggable. Swap Tokio and reqwest for your own runtime, or compile to WebAssembly.

How it works

Three steps. Your client stays in charge.

  1. 01

    Build

    Construct the request with the http crate's plain types — reqsign never wraps your HTTP client.

  2. 02

    Load or grant

    Resolve credentials through the provider's default chain, your own ProvideCredential, or a Granter that downscopes them first.

  3. 03

    Sign, then send

    One sign call mutates the request head atomically — headers or query string — and hands it back for any client to send.

Capabilities

From default chains to downscoped grants.

Start with one call, then take over any piece: credentials, runtime, query authentication, or the grant that scopes access before a request is ever signed.

Start signing

Ship your own client, not an SDK.

Five minutes to a signed request — with credentials, presigning, and scoped grants when you need them.