# S3 and optional use of sts (temporary credentials)

**URL:** <https://community.transloadit.com/t/s3-and-optional-use-of-sts-temporary-credentials/16773>\
**Category:** Uppy\
**Created:** [September 6, 2023, 9:39am UTC](https://community.transloadit.com/t/s3-and-optional-use-of-sts-temporary-credentials/16773 "2023-09-06T09:39:25Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sveinare](https://yyz2.discourse-cdn.com/flex032/user_avatar/community.transloadit.com/sveinare/32/939_2.png) [@sveinare](https://community.transloadit.com/u/sveinare)\
**Post date:** [September 6, 2023, 9:39am UTC](https://community.transloadit.com/t/s3-and-optional-use-of-sts-temporary-credentials/16773/1 "2023-09-06T09:39:25Z")

</div>

Hi,

Trying to follow the guide and setup Uppy with S3 and multipart-upload. Using own server and have created the endpoints given in the guide:

> **[AWS S3 | Uppy](https://uppy.io/docs/aws-s3-multipart/#use-with-your-own-server)**
>
> The @uppy/aws-s3 plugin can be used to upload files directly to a S3 bucket or

But if I dont define “getTemporarySecurityCredentials” (as function or bool), I get an error.  
(as [AWS S3 | Uppy](https://uppy.io/docs/aws-s3-multipart/#gettemporarysecuritycredentialsoptions))

Do I really HAVE to make an STS-endpoint? Can’t I just presigned every part?

---

<div class="post-metadata">

**Author:** ![Merlijn](https://yyz2.discourse-cdn.com/flex032/user_avatar/community.transloadit.com/merlijn/32/1382_2.png) [@Merlijn](https://community.transloadit.com/u/Merlijn)\
**Post date:** [September 6, 2023, 9:44am UTC](https://community.transloadit.com/t/s3-and-optional-use-of-sts-temporary-credentials/16773/2 "2023-09-06T09:44:28Z")

</div>

Hi, you don’t have to define an STS endpoint so setting it to `false` is fine. However I would expect the default to be `false` so you don’t have to explicitly pass it. If you are seeing errors, please [create a bug report](https://github.com/transloadit/uppy/issues/new?assignees=&labels=Bug&projects=&template=1-bug.yml).

---

<div class="post-metadata">

**Author:** ![sveinare](https://yyz2.discourse-cdn.com/flex032/user_avatar/community.transloadit.com/sveinare/32/939_2.png) [@sveinare](https://community.transloadit.com/u/sveinare)\
**Post date:** [September 6, 2023, 10:20am UTC](https://community.transloadit.com/t/s3-and-optional-use-of-sts-temporary-credentials/16773/3 "2023-09-06T10:20:31Z")

</div>

When I remove the function, I get this error:

 ![image](https://canada1.discourse-cdn.com/flex032/uploads/transloadit/original/1X/97424280594af6d4d9d5823f30bb678fce1de647.png)

BTW: Using this example as my starting-point:

> <https://github.com/transloadit/uppy/blob/main/examples/aws-nodejs/public/index.html>

---

<div class="post-metadata">

**Author:** ![sveinare](https://yyz2.discourse-cdn.com/flex032/user_avatar/community.transloadit.com/sveinare/32/939_2.png) [@sveinare](https://community.transloadit.com/u/sveinare)\
**Post date:** [September 6, 2023, 10:32am UTC](https://community.transloadit.com/t/s3-and-optional-use-of-sts-temporary-credentials/16773/4 "2023-09-06T10:32:25Z")

</div>

Posted as bug: [Can't use S3 w/multipart without having to define "getTemporarySecurityCredentials" · Issue #4665 · transloadit/uppy · GitHub](https://github.com/transloadit/uppy/issues/4665)

---

<div class="post-metadata">

**Author:** ![aduh95](https://yyz2.discourse-cdn.com/flex032/user_avatar/community.transloadit.com/aduh95/32/490_2.png) [@aduh95](https://community.transloadit.com/u/aduh95)\
**Post date:** [September 6, 2023, 10:43am UTC](https://community.transloadit.com/t/s3-and-optional-use-of-sts-temporary-credentials/16773/5 "2023-09-06T10:43:52Z")

</div>

Hey, in this example you have the following condition: [Uppy – AWS upload example](https://github.com/transloadit/uppy/blob/a16de335933731d52da9ee82ca6a0948f930af75/examples/aws-nodejs/public/index.html#L72-L75)

```auto
if (typeof crypto?.subtle === 'object') {
  // If WebCrypto is available, let's do signing from the client.
  return uppy.getPlugin('myAWSPlugin').createSignedURL(file, options)
}

```

Calling `createSignedURL` only works if you are using STS – because the client cannot create a signed URL without it. If you just want to use the server to sign stuff, you need to remove both `getTemporarySecurityCredentials` (or set it to `false`, it’s the same), and remove that condition.

---

<div class="post-metadata">

**Author:** ![sveinare](https://yyz2.discourse-cdn.com/flex032/user_avatar/community.transloadit.com/sveinare/32/939_2.png) [@sveinare](https://community.transloadit.com/u/sveinare)\
**Post date:** [September 6, 2023, 3:04pm UTC](https://community.transloadit.com/t/s3-and-optional-use-of-sts-temporary-credentials/16773/6 "2023-09-06T15:04:02Z")

</div>

Thanks. That solved my problem. I will now close/cancel the issue.
