Calculator Apps

💰 Finance

EMI Calculator SIP Calculator GST Calculator Income Tax Calculator Percentage Calculator CTC Calculator PF Interest Calculator Electricity Consumption Calculator Credit Card Interest Calculator UPI Charge Calculator

💖 Health

BMI Calculator Calorie Calculator Body Fat

🛠️ Developer Tools

JSON Formatter JSON Converter Password Generator Word Counter Invoice Generator Youtube Thumbnail Downloader PDF Tools QR Generator Dummy Data Generator Resume Generator Timestamp Converter AI Logo Generator URL Encoder / Decoder Open Graph Generator Data Sanitizer JSON Path Extractor YAML To TOML YAML To JSON Mermaid Live Editor OCR Tool Normal Distribution Calculator Sprite Sheet Splitter Dummy Credit Card Generator Postman To Curl Converter Text & Code Diff Compare JS Formatter XML Formatter Linkedin Post Formatter AI Prompt Generator

🖼️ Image Tools

Image Format Converter Image Size Compressor Favicon Generator Image Crop & Resize Resize Animated WEBP Base64 Image Toolkit HEIC to JPG Converter

📄 CSS Tools

CSS Gradient Generator Box Shadow Generator Flexbox Generator CSS Grid Generator Color Palette Generator CSS Neon Glow Text Generator Bento Grid Generator

🎬 Entertainment Tools

Love Calculator

🛠️ Text Tools

Case Converter Remove Duplicate Lines Text Sorter Reverse Text Remove Empty Lines Find And Replace MarkDown Editor UniCode Converter ASCII Converter Slugify String

☁ Cloud Tools

AWS Cron Generator Azure Cron Generator Google Cron Generator IAM Policy Validator S3 Bucket Policy Generator Terraform Variable Generator Terraform Formatter Terraform Validator Kubernetes Resource Calculator Docker Resource Calculator Shopify Profit Margin Calculator

🛠️ Data Formatter & Converter

SQL Query Formatter CSV to Markdown Table Converter JSON to JSONL Converter PHP Array To JSON Converter

🛠️ security & Analytics utilities

UTM Generator SHA256 Checksum Verifier DMARC Record Generator LangChain Converter Clean Text for LLM Training Data Claude Token & Cost Estimator FBX To OBJ Converter JWT Toolkit

Data Conversion Tool

SQL to JSON JSON to SQL CSV to JSON JSON to CSV XML to JSON JSON to XML JSON to YAML JSON Code Generator
🪣

S3 Bucket Policy Generator

Start from a common preset or build a custom multi-statement bucket policy, with CLI command included.

Quick Presets
Statements
Generated Policy
AWS CLI Command

Create an AWS S3 Bucket Policy

Use this S3 Bucket Policy Generator to create a JSON resource policy for an Amazon S3 bucket without manually assembling every policy element. Enter the bucket name, select a preset or build a custom statement, choose the principal and S3 actions, set the resource scope, and add optional conditions. The tool generates the policy JSON and an AWS CLI command that you can review and copy.

An S3 bucket policy controls who can perform specified actions on a bucket or its objects and under which conditions. Treat the generated policy as a starting point: always verify the principal, actions, resources and conditions before applying it to AWS.

How to Create an S3 Bucket Policy

  1. Enter the bucket name: Use the exact S3 bucket name. The generator uses it to create bucket and object ARNs.
  2. Choose a preset: Select Public Read, IP Restriction, Cross-Account Access, HTTPS Only or a blank policy, depending on your goal.
  3. Set the effect: Choose Allow to grant the selected permissions or Deny to explicitly block them.
  4. Specify the principal: Identify the AWS account, IAM role or other principal affected by the statement. Use * only when anonymous public access is intentional.
  5. Select S3 actions: Choose only the operations required, such as s3:GetObject, s3:PutObject or s3:ListBucket.
  6. Select the resource scope: Use the bucket ARN for bucket-level actions and the object ARN ending in /* for object-level actions.
  7. Add conditions if required: Restrict access by source IP, require HTTPS or apply another supported condition.
  8. Generate and review: Inspect every statement, then copy the JSON or the generated AWS CLI command.

S3 Bucket Policy Fields Explained

Field Purpose
VersionIdentifies the AWS policy language version, commonly 2012-10-17.
StatementContains one or more permission rules.
SidProvides an optional identifier for a statement.
EffectDefines whether the statement allows or denies access.
PrincipalIdentifies the account, role, service or public user affected by a resource-based policy.
ActionLists the Amazon S3 operations covered by the statement.
ResourceSpecifies the bucket or objects to which the actions apply.
ConditionOptionally limits when the statement applies, such as by IP address or secure transport.

Worked Example: Create a Public-Read S3 Policy

Suppose the bucket my-example-bucket contains public website images. Visitors should be able to download objects, but they must not upload, overwrite or delete them. Configure the generator with Allow, principal *, action s3:GetObject, and object resource arn:aws:s3:::my-example-bucket/*.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "PublicReadGetObject",
      "Effect": "Allow",
      "Principal": "*",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::my-example-bucket/*"
    }
  ]
}

This example makes every object covered by the resource publicly readable. It does not grant upload, delete or bucket-listing permission. Amazon S3 Block Public Access settings can reject or override public access. Keep public access blocked unless the bucket is intentionally public and you understand the exposure.

Bucket-Level and Object-Level Resources

Choosing the correct ARN is essential. Bucket-level actions such as s3:ListBucket normally use arn:aws:s3:::my-example-bucket. Object-level actions such as s3:GetObject, s3:PutObject and s3:DeleteObject normally use arn:aws:s3:::my-example-bucket/*. A policy can require separate statements when it combines bucket-level and object-level actions.

How to Add the Generated Policy in AWS

  1. Open Amazon S3 in the AWS Management Console.
  2. Select the required general-purpose bucket.
  3. Open the Permissions tab.
  4. Under Bucket policy, choose Edit.
  5. Paste the reviewed JSON and choose Save changes.
  6. Test with the intended IAM role, account or request source.

You can also save the JSON as policy.json and apply it with the generated AWS CLI command:

aws s3api put-bucket-policy \
  --bucket my-example-bucket \
  --policy file://policy.json

Common Errors

  • Policy has invalid resource: Confirm that the ARN contains the exact bucket name and uses /* for object actions.
  • Invalid principal: Verify the AWS account ID or IAM role ARN and confirm that the referenced identity exists.
  • Access Denied: Check IAM policies, explicit denies, service control policies and Block Public Access settings.
  • Objects work but listing fails: s3:GetObject does not include s3:ListBucket; they use different resources.
  • Public-read policy does not work: Account-, organization- or bucket-level Block Public Access may still prevent public access.
  • Overly broad access: Avoid wildcard principals, actions and resources unless they are deliberately required.

Best Practices

  • Grant the minimum actions and resources required.
  • Keep S3 Block Public Access enabled by default.
  • Use IAM role ARNs instead of long-term user credentials where practical.
  • Add an explicit HTTPS-only deny rule for production data when appropriate.
  • Test allowed and denied operations before deploying to production.
  • Remember that an applicable explicit Deny overrides an Allow.

Generator Limitations

Correctly formatted JSON is not a guarantee that a policy is secure or that AWS will allow the request. Final access can depend on IAM policies, permissions boundaries, session policies, service control policies, resource ownership and S3 Block Public Access. Review and test the generated policy with the actual AWS identities and resources.

Related AWS Tools

Frequently Asked Questions

How do I create an S3 bucket policy?
Enter the bucket name, add a statement, choose the effect, principal, S3 actions and resource, add any conditions, and generate the JSON. Review it before pasting it under the bucket’s Permissions tab in Amazon S3.
What is the difference between an S3 bucket policy and an IAM policy?
A bucket policy is resource-based and is attached to an S3 bucket. An IAM policy is identity-based and is attached to an IAM user, group or role. AWS can evaluate both when deciding whether to allow a request.
What ARN should I use for S3 objects?
Use arn:aws:s3:::bucket-name/* for objects. Use arn:aws:s3:::bucket-name for the bucket itself and bucket-level actions such as s3:ListBucket.
Can one S3 policy contain multiple statements?
Yes. Use separate statements for different principals, effects, resource types or conditions. This often makes a policy easier to review and maintain.
Why does my public S3 bucket policy still return Access Denied?
Check S3 Block Public Access at the organization, account and bucket levels, as well as explicit denies and the object resource ARN. Public access should be enabled only when intentional.
Can I restrict S3 access by IP address?
Yes. Add an IP-address condition with the trusted public IP address or CIDR range. Test from both allowed and disallowed networks before deployment.
Can I create an HTTPS-only S3 bucket policy?
Yes. Add a deny statement for requests where the secure-transport condition is false. Review the generated statement carefully because an explicit deny overrides allows.
Does the generator apply the policy to my AWS account?
No. It generates policy JSON and an AWS CLI command. You must review and apply the policy through the S3 console, AWS CLI or your deployment workflow.