DevOps

S3 CORS Policy Generator

Generate an AWS S3 CORS configuration in JSON from allowed origins, methods and headers for browser access to your bucket.

Last reviewed by the Radiatus Cloud team

Generate an AWS S3 CORS configuration JSON for browser access.

Want this automated for your stack?

We build CI/CD, Kubernetes & IaC pipelines that scale.

Talk to an engineer

Generate an S3 CORS policy

Cross-Origin Resource Sharing, or CORS, controls which websites may make browser requests to your Amazon S3 bucket. This generator produces a valid S3 CORS configuration in JSON from your allowed origins, the HTTP methods you want to permit, and a max-age for caching the preflight response. Without a correct CORS policy, browser-based uploads and fetches from a bucket fail with cross-origin errors, so this is a common requirement for web applications that use S3 directly.

The configuration allows all headers and exposes the ETag, which covers the usual needs for uploads and downloads.

Enabling browser access to S3

When a web page hosted on one domain needs to read from or upload to an S3 bucket, the browser enforces CORS, and S3 must be configured to allow the page's origin. Listing specific origins rather than a wildcard is more secure, and limiting the methods to only those you need follows the principle of least privilege. The max-age reduces repeated preflight requests by caching the permission.

Apply the JSON to your bucket's CORS configuration in the S3 console or via the API. Review the origins and methods carefully before applying. All generation happens locally in your browser.

Related tools

Frequently Asked Questions

What is an S3 CORS policy?

It is a configuration that tells S3 which website origins may make browser requests to the bucket, and which methods and headers are allowed.

Why do I need CORS for S3?

Browsers block cross-origin requests by default, so a web page on another domain can only upload to or read from a bucket if CORS permits its origin.

Should I use a wildcard origin?

Listing specific origins is more secure than a wildcard, since it restricts bucket access to only the sites you trust.

What does MaxAgeSeconds do?

It tells the browser how long to cache the CORS preflight response, reducing repeated preflight requests for better performance.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Enter allowed origins and methods, then generate the CORS JSON.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.