Amazon S3
Engine: S3-compatible (AWS SigV4) · Preset: Amazon S3
Configuration
Settings → Hosts → + → Amazon S3.
| Field | Value |
|---|---|
| Endpoint | leave empty — Dropline then uses https://s3.<region>.amazonaws.com |
| Region | The bucket's region, exactly: us-east-1, eu-central-1, ap-northeast-1 |
| Bucket | The bucket name alone, e.g. my-assets |
| Access Key ID | AKIA… from the IAM user |
| Secret Access Key | The matching secret — goes to the keychain |
| Public base URL | Optional. Your CloudFront domain, if you have one |
| Object key template | images/{{date}}/{{uuid}}.{{ext}} |
The region must match the bucket. AWS validates the region inside the
signature, so a mismatch fails with SignatureDoesNotMatch rather than a
redirect. Find it in the S3 console's bucket list.
Create the bucket
- S3 console → Create bucket, pick a name and a region.
- Under Block Public Access, uncheck Block all public access if you want bare links to work in a browser. Leave it on if you will serve exclusively through CloudFront with an origin access control.
- Create it.
A minimal IAM user
Give Dropline a key that can put objects and do nothing else. In IAM → Users → Create user, no console access, then attach an inline policy:
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "DroplineUpload",
"Effect": "Allow",
"Action": "s3:PutObject",
"Resource": "arn:aws:s3:::my-assets/images/*"
}
]
}
Then Security credentials → Create access key → Application running outside AWS. The secret is shown once.
Note the Resource is scoped to the same prefix as the key template. If you
change one, change the other.
Make objects readable
For a bare https://…amazonaws.com/… link to work, the object must be publicly
readable. The usual way is a bucket policy:
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "PublicReadImages",
"Effect": "Allow",
"Principal": "*",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::my-assets/images/*"
}
]
}
This grants read to the world for that prefix only — writing still requires the IAM key.
The link you get back
With Public base URL empty, Dropline returns the path-style URL it uploaded to:
https://s3.eu-central-1.amazonaws.com/my-assets/images/2026/08/19/a1f3….png
That works, but it is long, it names your bucket and it is not cached. Put CloudFront in front and set the public base URL to the distribution's domain:
https://cdn.example.com
The link then becomes:
https://cdn.example.com/images/2026/08/19/a1f3….png
Dropline joins the base and the key with a single / and does nothing else, so
if your distribution serves the bucket under a sub-path, include it in the base.
CORS
Only needed if a browser will fetch these files with JavaScript — a plain
<img> tag does not need CORS. If you do:
[
{
"AllowedHeaders": ["*"],
"AllowedMethods": ["GET"],
"AllowedOrigins": ["https://example.com"],
"MaxAgeSeconds": 3600
}
]
Dropline itself is a native app and is not subject to CORS at all.
Verify
Click Test Upload. On success, open the returned URL in a browser — that proves both the write path and the read path. A success followed by a 404 in the browser means the object is not public, or the base URL is wrong; see Troubleshooting.
Common problems
| Symptom | Cause |
|---|---|
SignatureDoesNotMatch |
Region does not match the bucket, or the secret has stray whitespace |
HTTP 403 with no signature complaint |
The IAM policy does not allow s3:PutObject on that prefix |
HTTP 404 |
Bucket name misspelled, or it lives in another region |
| Upload works, link 404s | Block Public Access still on, or no bucket policy |