AWS S3: AccessDenied (403) when calling GetObject / PutObject
An IAM policy, bucket policy, ACL/ownership setting, Block Public Access or KMS key policy denied the S3 request.
Seen on:
AWS
Meaning
S3 evaluates several policy layers; any explicit Deny or missing Allow results in AccessDenied. S3 also returns 403 (instead of 404) for missing objects when the caller lacks s3:ListBucket.
Common causes
- IAM policy lacks the action (
s3:GetObject,s3:PutObject) on the right resource ARN (bucket/*for objects) - Bucket policy explicit Deny (e.g. require TLS, VPC endpoint, specific principal)
- Object owned by another account / ACLs disabled mismatch
- Block Public Access prevents public reads
- Object encrypted with a KMS key the caller can’t use (
kms:Decrypt) - Object doesn’t exist and caller lacks ListBucket (403 instead of 404)
- Wrong credentials/role actually in use
⚡ Quick fix
- Confirm the identity:
aws sts get-caller-identity - Check the IAM policy resource: bucket ARN for ListBucket,
bucket/*for object actions - Review the bucket policy for Deny statements
- For SSE-KMS objects, grant
kms:Decrypt/kms:GenerateDataKey - Use IAM Policy Simulator or CloudTrail to see which policy denied
Detailed fix by platform
AWS
- Minimal read policy:json
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "s3:ListBucket", "Resource": "arn:aws:s3:::my-bucket" }, { "Effect": "Allow", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::my-bucket/*" } ] }
Code examples
Debug from the CLI
bash
aws sts get-caller-identity
aws s3api head-object --bucket my-bucket --key path/file.txt
aws s3api get-bucket-policy --bucket my-bucketHow to diagnose
- Identity — Which principal is making the call?
- IAM policy — Allows the action on the right ARN?
- Bucket policy — Any explicit Deny or conditions?
- Object — Exists? Owned by bucket owner?
- KMS — Key policy allows decrypt?
- Public access — Block Public Access settings?
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 2 Oct 2026