# Amazon S3 Setup: Connect & Transfer Files

> How to connect Blober to Amazon S3 buckets. Browse, upload, download, and transfer objects between S3 and other cloud providers or local storage.

Amazon Simple Storage Service (S3) is a highly scalable object storage service and one of the most popular cloud storage solutions. In Blober, S3 paths use this format:

```plaintext
bucket-name/path/to/file.ext
```

> **Using a non-AWS S3 service?**
>
> This guide is for **Amazon S3**. To connect a non-AWS service that speaks the S3 API (MinIO, Ceph, Storj, Hetzner, and many more), use the [**S3-Compatible**](/kb/docs/providers/s3-compatible/) connector instead.

## Capabilities

* ✅ Browse buckets and objects
* ✅ Upload files (including large files)
* ✅ Download files
* ✅ Delete objects
* ✅ Copy/move within S3 and across providers
* ✅ Storage class selection

## Prerequisites

* An AWS account ([create one](https://aws.amazon.com/free/))
* An S3 bucket (or permission to list buckets)
* IAM user or role with S3 permissions
* Access key ID and secret access key

## Required Credentials

[]()

### Access Key ID

* **Format:** 20 uppercase alphanumeric characters
* **Example:** `AKIAIOSFODNN7EXAMPLE`

[]()

### Secret Access Key

* **Format:** 40 characters
* **Example:** `wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY`

## Optional Settings

[]()

### Storage Class

* **Default:** `STANDARD`

| Storage Class         | Use Case                           | Retrieval        |
| --------------------- | ---------------------------------- | ---------------- |
| `STANDARD`            | Frequently accessed data           | Immediate        |
| `INTELLIGENT_TIERING` | Unknown/changing access patterns   | Immediate        |
| `STANDARD_IA`         | Infrequent access, rapid retrieval | Immediate        |
| `ONEZONE_IA`          | Infrequent, non-critical data      | Immediate        |
| `GLACIER_IR`          | Archive with instant retrieval     | Immediate        |
| `GLACIER`             | Long-term archive                  | Minutes to hours |
| `DEEP_ARCHIVE`        | Lowest cost archive                | 12-48 hours      |

## Setup (AWS Console)

### 1. Create an S3 Bucket

1. Go to [S3 Console](https://console.aws.amazon.com/s3/)
2. Click **"Create bucket"**
3. Enter a bucket name (must be globally unique)
4. Choose your preferred AWS Region
5. Configure settings as needed
6. Click **"Create bucket"**

### 2. Create an IAM User

1. Go to [IAM Console](https://console.aws.amazon.com/iam/)
2. Click **Users** => **Create user**
3. Enter a username (e.g., `blober-s3-user`)
4. Click **Next**
5. Select **Attach policies directly**
6. For quick setup: Attach `AmazonS3FullAccess`
   * For production: Create a custom policy (see below)
7. Click through to **Create user**

### 3. Generate Access Keys

1. Click on your new user
2. Go to **Security credentials** tab
3. Under **Access keys**, click **Create access key**
4. Select **Application running outside AWS**
5. **Save the Access Key ID and Secret Access Key** (shown only once!)

### 4. Configure in Blober

1. In Blober, go to **Workflows** => **New Workflow**
2. Select **Amazon S3** as source or destination
3. Enter your Access Key ID and Secret Access Key
4. Test by browsing your buckets

## Troubleshooting

### "Access Denied" or "403 Forbidden"

* Double-check your Access Key ID and Secret Access Key
* Verify the IAM user has the correct S3 permissions
* Ensure the bucket policy doesn't block your IAM user

### Buckets not showing up

* Your IAM user needs `s3:ListAllMyBuckets` permission
* If using a restricted policy, add `ListBucket` for specific buckets

### Slow transfers

* Choose an S3 region geographically close to you
* Large files are automatically uploaded in parts for reliability
* Check your network speed - S3 performance depends on your connection

## Best Practices

### Security

* Create a dedicated IAM user for Blober - avoid using root credentials
* Use the **minimum permissions** needed (don't use `AmazonS3FullAccess` in production)
* Rotate access keys periodically
* Enable MFA on your AWS account

### Cost Management

* Use **Intelligent Tiering** for data with unpredictable access patterns
* Move old backups to **Glacier** or **Deep Archive** for significant savings
* Enable [S3 Lifecycle rules](https://docs.aws.amazon.com/AmazonS3/latest/userguide/object-lifecycle-mgmt.html) to automate tier transitions
* Monitor costs in the [AWS Billing Console](https://console.aws.amazon.com/billing/)

> **Terms Compliance**
>
> Your use of Amazon S3 through Blober is subject to [AWS's Customer Agreement](https://aws.amazon.com/agreement/) and the [S3 Service Terms](https://aws.amazon.com/service-terms/). See our [Terms of Service](/kb/docs/terms-and-privacy/terms-of-service/) for details.

## External References

* [AWS IAM Access Keys](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_access-keys.html)
* [S3 Storage Classes](https://aws.amazon.com/s3/storage-classes/)
* [IAM Best Practices](https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html)
* [S3 Security Best Practices](https://docs.aws.amazon.com/AmazonS3/latest/userguide/security-best-practices.html)
* [AWS S3 Pricing](https://aws.amazon.com/s3/pricing/)
* [S3-Compatible storage in Blober](/kb/docs/providers/s3-compatible/) - connect non-AWS services that speak the S3 API