You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

S3预签名URL访问返回403(SignatureDoesNotMatch)问题排查求助

S3预签名URL访问返回403(SignatureDoesNotMatch)问题排查求助

我最近在生成S3预签名URL来获取存储桶里的PDF文件时,一直碰到403的SignatureDoesNotMatch错误,折腾了好一阵没解决,来求助各位大佬帮忙看看还有哪些地方可能出问题!

先贴一下我生成预签名URL的代码:

import boto3
from botocore.config import Config
from botocore.exceptions import ClientError


def create_presigned_url(bucket_name, object_name, expiration=60):
    """Generate a presigned URL to share an S3 object

    :param bucket_name: string
    :param object_name: string
    :param expiration: Time in seconds for the presigned URL to remain valid
    :return: Presigned URL as string. If error, returns None.
    """

    
    s3_client = boto3.client(
        's3',
        region_name='us-east-1',
        config=Config(signature_version='s3v4') # 我反复加了又删,用来调试
    )
    try:
        response = s3_client.generate_presigned_url(
            'get_object',
            Params={'Bucket': bucket_name, 'Key': object_name},
            ExpiresIn=expiration,
        )
    except ClientError as e:
        print(f"Error: {e}")
        return None

    
    return response

生成的URL格式大概是这样(已经隐去了敏感的访问密钥信息):

https://my-bucket.s3.amazonaws.com/my-file.pdf?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=ABCDEFER%2F20251216%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20251216T164853Z&X-Amz-Expires=60&X-Amz-SignedHeaders=host&X-Amz-Signature=xxxx123456789abcdef

我已经尝试过这些操作,但都没效果:

  • 给S3客户端加/移除signature_version='s3v4'配置
  • 把URL里的斜杠编码成%2f
  • 反复确认桶名、对象名完全正确
  • 检查生成URL用的IAM用户权限,确认有s3:GetObject权限
  • 核对本地服务器时间和AWS的时间,确保没有偏差(避免过期时间校验问题)

访问这个URL返回的完整错误XML如下:

<Error>
<Code>SignatureDoesNotMatch</Code>
<Message>The request signature we calculated does not match the signature you provided. Check your key and signing method.</Message>
<AWSAccessKeyId>xxxxxxxxxxxxxx</AWSAccessKeyId>
<StringToSign>AWS4-HMAC-SHA256 20251216T175250Z 20251216/us-east-1/s3/aws4_request abcdefgh123456</StringToSign>
<SignatureProvided>abcdefgh123456</SignatureProvided>
<StringToSignBytes>41...66</StringToSignBytes>
<CanonicalRequest>GET /test.pdf X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=Axxxxxxx%2F20251216%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20251216T175250Z&X-Amz-Expires=60&X-Amz-SignedHeaders=host host:my-bucket.s3.us-east-1.amazonaws.com host UNSIGNED-PAYLOAD</CanonicalRequest>
<CanonicalRequestBytes>47 ...41</CanonicalRequestBytes>
<RequestId>ABCDEFGH</RequestId>
<HostId>/w5fnLdpA+p0zGm9Zb0Df3E0mZdwEYOxUYGUMwP2/T1VpvLBZmiHoxBGoNx4aRMpL7fyBz3w9kw=</HostId>
</Error>

想问问大家,除了我已经排查的这些点,还有哪些可能的原因会导致这个签名不匹配的问题?有没有什么我漏掉的调试方向?

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.23 12:05:52