{"id":13624095,"url":"https://github.com/tedder/requests-aws4auth","last_synced_at":"2026-04-02T01:36:21.096Z","repository":{"id":28180586,"uuid":"31682127","full_name":"tedder/requests-aws4auth","owner":"tedder","description":"Amazon Web Services version 4 authentication for the Python Requests module","archived":false,"fork":false,"pushed_at":"2024-07-21T21:28:37.000Z","size":208,"stargazers_count":188,"open_issues_count":20,"forks_count":64,"subscribers_count":3,"default_branch":"main","last_synced_at":"2026-03-28T01:16:12.239Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":"iis-io-team/gitlab_www_project","license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/tedder.png","metadata":{"files":{"readme":"README.md","changelog":"HISTORY.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2015-03-04T21:59:07.000Z","updated_at":"2026-03-15T22:25:57.000Z","dependencies_parsed_at":"2024-11-05T21:36:01.670Z","dependency_job_id":null,"html_url":"https://github.com/tedder/requests-aws4auth","commit_stats":{"total_commits":129,"total_committers":21,"mean_commits":6.142857142857143,"dds":0.6976744186046512,"last_synced_commit":"89399ca176f05e5887f8acd246c3c9975f965336"},"previous_names":["sam-washington/requests-aws4auth"],"tags_count":22,"template":false,"template_full_name":null,"purl":"pkg:github/tedder/requests-aws4auth","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tedder%2Frequests-aws4auth","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tedder%2Frequests-aws4auth/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tedder%2Frequests-aws4auth/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tedder%2Frequests-aws4auth/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/tedder","download_url":"https://codeload.github.com/tedder/requests-aws4auth/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tedder%2Frequests-aws4auth/sbom","scorecard":{"id":796918,"data":{"date":"2025-08-11","repo":{"name":"github.com/tedder/requests-aws4auth","commit":"89399ca176f05e5887f8acd246c3c9975f965336"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":4.5,"checks":[{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Code-Review","score":2,"reason":"Found 7/25 approved changesets -- score normalized to 2","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/tedder/requests-aws4auth/codeql-analysis.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/tedder/requests-aws4auth/codeql-analysis.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/tedder/requests-aws4auth/codeql-analysis.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/tedder/requests-aws4auth/codeql-analysis.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pythonpackage.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/tedder/requests-aws4auth/pythonpackage.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pythonpackage.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/tedder/requests-aws4auth/pythonpackage.yml/main?enable=pin","Warn: pipCommand not pinned by hash: .github/workflows/pythonpackage.yml:29","Warn: pipCommand not pinned by hash: .github/workflows/pythonpackage.yml:30","Warn: pipCommand not pinned by hash: .github/workflows/pythonpackage.yml:31","Info:   0 out of   6 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   3 pipCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/codeql-analysis.yml:1","Warn: no topLevel permission defined: .github/workflows/pythonpackage.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"SAST","score":7,"reason":"SAST tool detected but not run on all commits","details":["Info: SAST configuration detected: CodeQL","Warn: 4 commits out of 13 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}}]},"last_synced_at":"2025-08-23T09:16:16.971Z","repository_id":28180586,"created_at":"2025-08-23T09:16:16.971Z","updated_at":"2025-08-23T09:16:16.971Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":31252838,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-03-31T18:32:52.363Z","status":"ssl_error","status_checked_at":"2026-03-31T18:32:51.507Z","response_time":111,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-01T21:01:38.742Z","updated_at":"2026-04-02T01:36:21.076Z","avatar_url":"https://github.com/tedder.png","language":"Python","funding_links":[],"categories":["Python"],"sub_categories":[],"readme":"[![image](https://img.shields.io/pypi/v/requests-aws4auth.svg)](https://pypi.python.org/pypi/requests-aws4auth)\n[![image](https://img.shields.io/pypi/l/requests-aws4auth.svg)](https://pypi.python.org/pypi/requests-aws4auth)\n\nAmazon Web Services version 4 authentication for the Python [Requests](https://github.com/kennethreitz/requests) library.\n\nFeatures\n========\n\n-   Requests authentication for all AWS services that support AWS auth v4\n-   Independent signing key objects\n-   Automatic regeneration of keys when scope date boundary is passed\n-   Support for STS temporary credentials\n\nImplements header-based authentication, GET URL parameter and POST\nparameter authentication are not supported.\n\nSupported Services\n==================\n\nThis package has been tested as working against:\n\nAppStream, AppSync, Auto-Scaling, CloudFormation, CloudFront, CloudHSM,\nCloudSearch, CloudTrail, CloudWatch Monitoring, CloudWatch Logs,\nCodeDeploy, Cognito Identity, Cognito Sync, Config, DataPipeline, Direct\nConnect, DynamoDB, Elastic Beanstalk, ElastiCache, EC2, EC2 Container\nService, Elastic Load Balancing, Elastic MapReduce, ElasticSearch,\nElastic Transcoder, Glacier, Identity and Access Management (IAM), Key\nManagement Service (KMS), Kinesis, Lambda, Opsworks, Redshift,\nRelational Database Service (RDS), Route 53, Simple Storage Service\n(S3), Simple Notification Service (SNS), Simple Queue Service (SQS),\nStorage Gateway, Security Token Service (STS)\n\nThe following services do not support AWS auth version 4 and are not\nusable with this package:\n\nSimple Email Service (SES), Simple Workflow Service (SWF),\nImport/Export, SimpleDB, DevPay, Mechanical Turk\n\nThe AWS Support API has not been tested as it requires a premium\nsubscription.\n\nPython versions\n========\nIn the 1.x semantic versions, the minimum python support will be gradually raised:\n\n* 1.0.x: Support python2.7 and python3.3+.\n* 1.1.x: python2.7 is not supported, is best-effort. Support python3.3+.\n* 1.2.x: [Requires-Python](https://packaging.python.org/guides/dropping-older-python-versions/#specify-the-version-ranges-for-supported-python-distributions) will be set to python3.3+, explicitly removing earlier versions. python\u003c3.7 is not supported, is best-effort.\n* 1.3.x: [Requires-Python](https://packaging.python.org/guides/dropping-older-python-versions/#specify-the-version-ranges-for-supported-python-distributions) will be set to python3.7+, explicitly removing earlier versions. (best-effort is TBD)\n\nInstallation\n============\n\nInstall via pip:\n\n``` {.sourceCode .bash}\n$ pip install requests-aws4auth\n```\n\nrequests-aws4auth requires the\n[Requests](https://github.com/kennethreitz/requests) library by Kenneth\nReitz.\n\nrequests-aws4auth is tested on Python 2.7 and 3.5 and up.\n\nBehaviour changes in 0.8\n========================\n\nVersion 0.8 introduces request date checking and automatic key\nregeneration behaviour as default. This has implications for sharing\nauthentication objects between threads, and for storage of secret keys.\nSee the relevant sections below for details. See also the discussion in\n[GitHub issue\n\\#10](https://github.com/sam-washington/requests-aws4auth/issues/10).\n\nBasic usage\n===========\n\n``` {.sourceCode .python}\n\u003e\u003e\u003e import requests\n\u003e\u003e\u003e from requests_aws4auth import AWS4Auth\n\u003e\u003e\u003e endpoint = 'http://s3-eu-west-1.amazonaws.com'\n\u003e\u003e\u003e auth = AWS4Auth('\u003cACCESS ID\u003e', '\u003cACCESS KEY\u003e', 'eu-west-1', 's3')\n\u003e\u003e\u003e response = requests.get(endpoint, auth=auth)\n\u003e\u003e\u003e response.text\n\u003c?xml version=\"1.0\" encoding=\"UTF-8\"?\u003e\n    \u003cListAllMyBucketsResult xmlns=\"http://s3.amazonaws.com/doc/2006-03-01\"\u003e\n        \u003cOwner\u003e\n        \u003cID\u003ebcaf1ffd86f461ca5fb16fd081034f\u003c/ID\u003e\n        \u003cDisplayName\u003ewebfile\u003c/DisplayName\u003e\n        ...\n```\n\nThis example would list your buckets in the `eu-west-1` region of the\nAmazon S3 service.\n\nSTS Temporary Credentials\n=========================\n\n``` {.sourceCode .python}\n\u003e\u003e\u003e from requests_aws4auth import AWS4Auth\n\u003e\u003e\u003e auth = AWS4Auth('\u003cACCESS ID\u003e', '\u003cACCESS KEY\u003e', 'eu-west-1', 's3',\n                    session_token='\u003cSESSION TOKEN\u003e')\n...\n```\n\nThis example shows how to construct an AWS4Auth object for use with STS\ntemporary credentials. The `x-amz-security-token` header is added with\nthe session token. Temporary credential timeouts are not managed \\-- in\ncase the temporary credentials expire, they need to be re-generated and\nthe AWS4Auth object re-constructed with the new credentials.\n\nDynamic STS Credentials using botocore RefreshableCredentials\n=============================================================\n\n``` {.sourceCode .python}\n\u003e\u003e\u003e from requests_aws4auth import AWS4Auth\n\u003e\u003e\u003e from botocore.session import Session\n\u003e\u003e\u003e credentials = Session().get_credentials()\n\u003e\u003e\u003e auth = AWS4Auth(region='eu-west-1', service='es',\n                    refreshable_credentials=credentials)\n...\n```\n\nThis example shows how to construct an AWS4Auth instance with\nautomatically refreshing credentials, suitable for long-running\napplications using AWS IAM assume-role.\nThe RefreshableCredentials instance is used to generate valid static\ncredentials per-request, eliminating the need to recreate the AWS4Auth\ninstance when temporary credentials expire.\n\nDate handling\n=============\n\nIf an HTTP request to be authenticated contains a `Date` or `X-Amz-Date`\nheader, AWS will only accept the authorised request if the date in the\nheader matches the scope date of the signing key (see the [AWS REST API date\ndocs](http://docs.aws.amazon.com/general/latest/gr/sigv4-date-handling.html).)).\n\nFrom version 0.8 of requests-aws4auth, if the header date does not match\nthe scope date, an `AWS4Auth` instance will automatically regenerate its\nsigning key, using the same scope parameters as the previous key except\nfor the date, which will be changed to match the request date. If a\nrequest does not include a date, the current date is added to the\nrequest in an `X-Amz-Date` header, and the signing key is regenerated if\nthis differs from the scope date.\n\nThis means that `AWS4Auth` now extracts and parses dates from the values\nof `X-Amz-Date` and `Date` headers. Supported date formats are:\n\n-   RFC 7231 (e.g. Mon, 09 Sep 2011 23:36:00 GMT)\n-   RFC 850 (e.g. Sunday, 06-Nov-94 08:49:37 GMT)\n-   C time (e.g. Wed Dec 4 00:00:00 2002)\n-   Amz-Date format (e.g. 20090325T010101Z)\n-   ISO 8601 / RFC 3339 (e.g. 2009-03-25T10:11:12.13-01:00)\n\nIf either header is present but `AWS4Auth` cannot extract a date because\nall present date headers are in an unrecognisable format, `AWS4Auth`\nwill delete any `X-Amz-Date` and `Date` headers present and replace with\na single `X-Amz-Date` header containing the current date. This behaviour\ncan be modified using the `raise_invalid_date` keyword argument of the\n`AWS4Auth` constructor.\n\nAutomatic key regeneration\n==========================\n\nIf you do not want the signing key to be automatically regenerated when\na mismatch between the request date and the scope date is encountered,\nuse the alternative `StrictAWS4Auth` class, which is identical to\n`AWS4Auth` except that upon encountering a date mismatch it just raises\na `DateMismatchError`. You can also use the `PassiveAWS4Auth` class,\nwhich mimics the `AWS4Auth` behaviour prior to version 0.8 and just\nsigns and sends the request, whether the date matches or not. In this\ncase it is up to the calling code to handle an authentication failure\nresponse from AWS caused by the date mismatch.\n\nSecret key storage\n==================\n\nTo allow automatic key regeneration, the secret key is stored in the\n`AWS4Auth` instance, in the signing key object. If you do not want this\nto occur, instantiate the instance using an `AWS4Signing` key which was\ncreated with the `store_secret_key` parameter set to False:\n\n``` {.sourceCode .python}\n\u003e\u003e\u003e sig_key = AWS4SigningKey(secret_key, region, service, date, False)\n\u003e\u003e\u003e auth = StrictAWS4Auth(access_id, sig_key)\n```\n\nThe `AWS4Auth` class will then raise a `NoSecretKeyError` when it\nattempts to regenerate its key. A slightly more conceptually elegant way\nto handle this is to use the alternative `StrictAWS4Auth` class, again\ninstantiating it with an `AWS4SigningKey` instance created with\n`store_secret_key = False`.\n\nMultithreading\n==============\n\nIf you share `AWS4Auth` (or even `StrictAWS4Auth`) instances between\nthreads you are likely to encounter problems. Because `AWS4Auth`\ninstances may unpredictably regenerate their signing key as part of\nsigning a request, threads using the same instance may find the key\nchanged by another thread halfway through the signing process, which may\nresult in undefined behaviour.\n\nIt may be possible to rig up a workable instance sharing mechanism using\nlocking primitives and the `StrictAWS4Auth` class, however this poor\nauthor can\\'t think of a scenario which works safely yet doesn\\'t suffer\nfrom at some point blocking all threads for at least the duration of an\nHTTP request, which could be several seconds. If several requests come\nin in close succession which all require key regenerations then the\nsystem could be forced into serial operation for quite a length of time.\n\nIn short, it\\'s probably best to create a thread-local instance of\n`AWS4Auth` for each thread that needs to do authentication.\n\nAPI reference\n=============\n\nSee the doctrings in `aws4auth.py` and `aws4signingkey.py`.\n\nTesting\n=======\n\nA test suite is included in the test folder.\n\nThe package passes all tests in the AWS auth v4\n[test_suite](http://docs.aws.amazon.com/general/latest/gr/signature-v4-test-suite.html),\nand contains tests against the supported live services. See docstrings\nin `test/requests_aws4auth_test.py` for details about running the tests.\n\nConnection parameters are included in the tests for the AWS Support API,\nshould you have access and want to try it. The documentation says it\nsupports auth v4 so it should work if you have a subscription. Do pass\non your results!\n\nUnsupported AWS features / todo\n===============================\n\n-   Currently does not support Amazon S3 chunked uploads\n-   Tests for new AWS services\n-   Requires Requests library to be present even if only using\n    AWS4SigningKey\n-   Coherent documentation\n\nVersion release notes\n=====================\n\n- update `HISTORY.md`\n- update `requests_aws4auth/__init__.py`\n- create a [release](https://github.com/tedder/requests-aws4auth/releases) on github\n\ndocker env:\n```\ndocker run -v `pwd`:/opt/app/ -v ~/.pypirc:/root/.pypirc  -it python:3.12 /bin/bash\n```\n\nprep:\n```\npython3 -m pip install --user --upgrade setuptools wheel testresources twine\n```\n\nbuild and release, creds in `~/.pypirc`:\n```\nrm -f dist/*; \\\npython3 setup.py sdist bdist_wheel \u0026\u0026 \\\npython3 -m twine upload --repository testpypi dist/* \u0026\u0026 \\\npython3 -m twine upload --repository pypi dist/*\n```\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftedder%2Frequests-aws4auth","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ftedder%2Frequests-aws4auth","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftedder%2Frequests-aws4auth/lists"}