You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用匿名Cognito身份通过CLI上传文件至S3失败问题排查

问题:匿名Cognito身份通过AWS CLI上传S3失败(InvalidAccessKeyId)

我有一个iOS客户端,可通过匿名Cognito身份和Amplify SDK成功上传文件至S3。但尝试用AWS CLI模拟相同上传操作时失败,操作步骤如下:

  1. 获取指定身份池ID的身份:
aws cognito-identity get-id --identity-pool-id us-east-1:XXX-XXX

返回结果:

{
    "IdentityId": "us-east-1:YYY-YYY"
}
  1. 获取该身份的凭证:
aws cognito-identity get-credentials-for-identity --identity-id  "us-east-1:YYY-YYY" --region "us-east-1"

返回结果:

{
    "IdentityId": "us-east-1:YYY-YYY",
    "Credentials": {
        "AccessKeyId": "KEY-KEY-KEY",
        "SecretKey": "SECRET-SECRET-SECRET",
        "SessionToken": "long session token here",
        "Expiration": "2030-01-09T01:28:11+02:00"
    }
}
  1. 使用返回的凭证尝试上传文件:
AWS_ACCESS_KEY_ID="KEY-KEY-KEY" AWS_SECRET_ACCESS_KEY="SECRET-SECRET-SECRET" aws s3 --region us-east-1 cp /tmp/txt.txt s3://my-public-bucket/txt.txt

返回错误:

upload failed: /tmp/txt.txt to s3://my-public-bucket/txt.txt An error occurred (InvalidAccessKeyId) when calling the PutObject operation: The AWS Access Key Id you provided does not exist in our records.

请问该密钥是否需要提前注册?我遗漏了什么步骤?

解答
  • 这些临时凭证不需要提前注册,问题出在你没有传入SessionToken——Cognito匿名身份返回的是临时安全凭证,必须同时提供AccessKeyId、SecretKey和SessionToken才能生效。

修复后的上传命令应该包含AWS_SESSION_TOKEN环境变量:

AWS_ACCESS_KEY_ID="KEY-KEY-KEY" AWS_SECRET_ACCESS_KEY="SECRET-SECRET-SECRET" AWS_SESSION_TOKEN="long session token here" aws s3 --region us-east-1 cp /tmp/txt.txt s3://my-public-bucket/txt.txt
  • 补充说明:Amplify SDK会自动处理临时凭证的完整传递(包括会话令牌),所以iOS端可以正常工作;而AWS CLI需要手动显式传入所有三个凭证参数,缺一不可。

内容的提问来源于stack exchange,提问作者UrK

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 17:56:09