Signing without a full SDK
Build requests with plain http types, sign them in place, and send with any client. Encoded URIs, atomic request mutation, and expiration follow explicit, documented contracts.
Sign HTTP requests, load cloud credentials, and grant scoped access — without pulling in a full vendor SDK.
use reqsign::aws;
// Create a default signer for S3 in us-east-1
let signer = aws::default_signer("s3", "us-east-1");
// Build a request
let mut req = http::Request::builder()
.method(http::Method::GET)
.uri("https://s3.amazonaws.com/my-bucket/my-object")
.body(())
.unwrap()
.into_parts()
.0;
// Sign the request
signer.sign(&mut req, None).await?;
Apache OpenDAL™ signs every cloud storage request — S3, GCS, Azure Blob, COS, TOS, and more — through Reqsign.
uv the Python package manager, authenticates to AWS, Azure, and Google Cloud with Reqsign.
Reqsign keeps each provider's protocol explicit while sharing one composition pattern — so your client stays yours.
Build requests with plain http types, sign them in place, and send with any client. Encoded URIs, atomic request mutation, and expiration follow explicit, documented contracts.
Every provider keeps its own credential semantics. Default chains cover environment, config files, instance metadata, OIDC federation, CLIs, and credential processes.
One Granter abstraction covers S3 Access Grants, S3 Express sessions, Azure user delegation SAS, and GCP Credential Access Boundary — downscoping that vendor SDKs rarely unify.
Context makes file reading, HTTP sending, environment, and command execution pluggable. Swap Tokio and reqwest for your own runtime, or compile to WebAssembly.
Construct the request with the http crate's plain types — reqsign never wraps your HTTP client.
Resolve credentials through the provider's default chain, your own ProvideCredential, or a Granter that downscopes them first.
One sign call mutates the request head atomically — headers or query string — and hands it back for any client to send.
Start with one call, then take over any piece: credentials, runtime, query authentication, or the grant that scopes access before a request is ever signed.
use reqsign::aws::{self, StaticCredentialProvider};
let signer = aws::default_signer("s3", "us-east-1").with_credential_provider(
StaticCredentialProvider::new("AKIDEXAMPLE", "example-secret-key"),
);
Signers and credentials stay service-specific on purpose — the protocol differences are real, and hiding them breaks correctness. What Reqsign shares is the composition pattern.
Five minutes to a signed request — with credentials, presigning, and scoped grants when you need them.