S3 CORS Policy Generator
Generate an AWS S3 CORS configuration in JSON from allowed origins, methods and headers for browser access to your bucket.
Last reviewed by the Radiatus Cloud team
Generate an AWS S3 CORS configuration JSON for browser access.
Want this automated for your stack?
We build CI/CD, Kubernetes & IaC pipelines that scale.
Generate an S3 CORS policy
Cross-Origin Resource Sharing, or CORS, controls which websites may make browser requests to your Amazon S3 bucket. This generator produces a valid S3 CORS configuration in JSON from your allowed origins, the HTTP methods you want to permit, and a max-age for caching the preflight response. Without a correct CORS policy, browser-based uploads and fetches from a bucket fail with cross-origin errors, so this is a common requirement for web applications that use S3 directly.
The configuration allows all headers and exposes the ETag, which covers the usual needs for uploads and downloads.
Enabling browser access to S3
When a web page hosted on one domain needs to read from or upload to an S3 bucket, the browser enforces CORS, and S3 must be configured to allow the page's origin. Listing specific origins rather than a wildcard is more secure, and limiting the methods to only those you need follows the principle of least privilege. The max-age reduces repeated preflight requests by caching the permission.
Apply the JSON to your bucket's CORS configuration in the S3 console or via the API. Review the origins and methods carefully before applying. All generation happens locally in your browser.
Related tools
- CI/CD Security Gap Analyzer — Checklist based analyzer for CI/CD pipeline security gaps.
- Docker Security Scanner — A new tool extracted from the codebase.
- Terraform Scanner — A new tool extracted from the codebase.
- SQL Formatter — Format and indent SQL queries for readability. Handles joins, subqueries and CTEs, supports common dialects, and runs entirely in your browser.
Frequently Asked Questions
What is an S3 CORS policy?
It is a configuration that tells S3 which website origins may make browser requests to the bucket, and which methods and headers are allowed.
Why do I need CORS for S3?
Browsers block cross-origin requests by default, so a web page on another domain can only upload to or read from a bucket if CORS permits its origin.
Should I use a wildcard origin?
Listing specific origins is more secure than a wildcard, since it restricts bucket access to only the sites you trust.
What does MaxAgeSeconds do?
It tells the browser how long to cache the CORS preflight response, reducing repeated preflight requests for better performance.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Enter allowed origins and methods, then generate the CORS JSON.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.