You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Boto3通过Python访问AWS S3时遭遇AccessDenied错误,无法列出存储桶内容

Troubleshooting AccessDenied Error When Listing S3 Bucket with Boto3 and MFA

Hey there! As someone who's fumbled through similar S3 permission snags when starting out with AWS and Boto3, let's break down the most likely reasons you're hitting this error and how to fix them.

1. Make Sure Your IAM Permissions Are Set Correctly

First things first: the IAM entity (user or role linked to your mfa_0729 profile) needs the s3:ListBucket permission specifically for your my-bucket-name bucket.

Double-check your IAM policy to ensure it includes something like this (adjust the resource and condition to match your setup):

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": "s3:ListBucket",
            "Resource": "arn:aws:s3:::my-bucket-name",
            "Condition": {
                "StringLike": {
                    "s3:prefix": "my-claim-name*"
                }
            }
        }
    ]
}

The condition here ensures you can list objects starting with your StartAfter prefix. If you don't need the prefix restriction, you can omit the condition and just grant s3:ListBucket on the full bucket ARN.

2. Verify Your MFA Session Credentials Are Active

Even though you stored the session token in your profile, it's worth confirming the credentials your Boto3 session is using are valid and complete. Add a quick debug print to check:

print(f"Access Key: {credentials.access_key}")
print(f"Secret Key: {credentials.secret_key}")
print(f"Session Token: {credentials.token}")
  • If the session token is empty or expired (MFA sessions usually last 12 hours), you'll need to generate a new set of credentials via STS (either using the AWS CLI or Boto3's STS client).
  • Ensure your ~/.aws/credentials (or C:\Users\<YourUsername>\.aws\credentials on Windows) file for the mfa_0729 profile has all three required values: aws_access_key_id, aws_secret_access_key, and aws_session_token.

3. Check the Bucket Policy for Deny Statements

Bucket policies take priority over IAM policies, so even if your IAM user has permissions, a Deny statement in the bucket policy could block access.

Head to the S3 console, navigate to your bucket's Permissions tab, and review the Bucket Policy. Look for any statements that might deny s3:ListBucket access to your user/role ARN. If you find one, either remove it (if appropriate) or add an explicit Allow statement that overrides the Deny.

4. Test with AWS CLI to Isolate the Issue

To rule out code-specific problems, test the same operation using the AWS CLI:

aws s3 ls s3://my-bucket-name/my-claim-name --profile mfa_0729
  • If the CLI throws the same AccessDenied error, the problem is with your credentials or permissions—not your Python code.
  • If the CLI works, double-check your Boto3 code for typos (like a misspelled bucket name or StartAfter value) — your current code looks solid, but small typos happen!

5. Rule Out Higher-Level IAM Restrictions

If you're part of an AWS Organization, check if there's a Service Control Policy (SCP) that restricts S3 access for your account. Also, verify if your IAM user has a Permission Boundary that limits the permissions they can use. Both of these can override your individual IAM policy.

内容的提问来源于stack exchange,提问作者RB17

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.29 23:02:51