openapi: 3.2.0 info: title: Amazon S3 (object-level) ACL API description: '2 operations from the Amazon S3 REST API, generated from the authoritative service model. S3 identifies these operations by the `acl` query subresource, which is declared as a required query parameter on each one because an OpenAPI path cannot carry a query string. Generated from boto/botocore `service-2.json` at `aeb03fc4ae530e0b3f47d588b6021581db870c8c` (Apache-2.0). Responses are XML.' version: '2006-03-01' contact: name: AWS Support url: https://aws.amazon.com/premiumsupport/ servers: - url: https://s3.{region}.amazonaws.com variables: region: default: us-east-1 tags: - name: ACL paths: /{Bucket}/{Key}: get: operationId: GetObjectAcl summary: This operation is not supported for directory buckets description: 'This operation is not supported for directory buckets. Returns the access control list (ACL) of an object. To use this operation, you must have s3:GetObjectAcl permissions or READ_ACP access to the object. For more information, see Mapping of ACL permissions and access policy permissions in the Amazon S3 User Guide This functionality is not supported for Amazon S3 on Outposts. By default, GET returns ACL information about the current version of an object. To return ACL information about a different version, use the versionId subresource. If your bucket uses the bucket owner enforced setting for S3 Object Ownership, requests to read ACLs are still supported and return the bucket-owner-full-control ACL with the owner being the account that created the bucket. For more information, see Controlling object ownership and disabling ACLs in the Amazon S3 User Guide. The following operations are related to GetObjectAcl: GetObject GetObjectAttributes DeleteObject PutObject You must URL encode any signed header values that contain spaces. For example, if your header value is my file.txt, containing two spaces after my, you must URL encode this value to my%20%20file.txt.' tags: - ACL parameters: - name: acl in: query required: true description: Selects this operation. S3 identifies it by the `acl` subresource. schema: type: string - name: Bucket in: path required: true description: 'The bucket name that contains the object for which to get the ACL information. Access points - When you use this action with an access point for general purpose buckets, you must provide the alias of ' schema: type: string - name: Key in: path required: true description: The key of the object for which to get the ACL information. schema: type: string - name: versionId in: query required: false description: Version ID used to reference a specific version of the object. This functionality is not supported for directory buckets. schema: type: string - name: x-amz-request-payer in: header required: false schema: type: string enum: - requester - name: x-amz-expected-bucket-owner in: header required: false description: The account ID of the expected bucket owner. If the account ID that you provide does not match the actual owner of the bucket, the request fails with the HTTP status code 403 Forbidden (access denied) schema: type: string responses: '200': description: Success. S3 answers in XML, not JSON. x-output-shape: GetObjectAclOutput '403': description: AccessDenied. S3 validates the signature before it routes the operation, so this does not distinguish an unsupported operation from an unauthorised one. x-s3-greedy-path-segment: 'AWS writes this route as `/{Bucket}/{Key+}`. The trailing `+` marks a greedy segment, which OpenAPI templating cannot express: an S3 object key may contain slashes, so this parameter is not a single path component.' put: operationId: PutObjectAcl summary: 'End of support notice: As of October 1, 2025, Amazon S3 has discontinued…' description: 'End of support notice: As of October 1, 2025, Amazon S3 has discontinued support for Email Grantee Access Control Lists (ACLs). If you attempt to use an Email Grantee ACL in a request after October 1, 2025, the request will receive an HTTP 405 (Method Not Allowed) error. This change affects the following Amazon Web Services Regions: US East (N. Virginia), US West (N. California), US West (Oregon), Asia Pacific (Singapore), Asia Pacific (Sydney), Asia Pacific (Tokyo), Europe (Ireland), and South America (São Paulo). This operation is not supported for directory buckets. Uses the acl subresource to set the access control list (ACL) permissions for a new or existing object in an S3 bucket. You must have the WRITE_ACP permission to set the ACL of an object. For more information, see What permissions can I grant? in the Amazon S3 User Guide. This functionality is not supported for Amazon S3 on Outposts. Depending on your application needs, you can choose to set the ACL on an object using either the request body or the headers. For example, if you have an existing application that updates a bucket ACL using the request body, you can continue to use that approach. For more information, se' tags: - ACL parameters: - name: acl in: query required: true description: Selects this operation. S3 identifies it by the `acl` subresource. schema: type: string - name: x-amz-acl in: header required: false description: The canned ACL to apply to the object. For more information, see Canned ACL. schema: type: string enum: - private - public-read - public-read-write - authenticated-read - aws-exec-read - bucket-owner-read - bucket-owner-full-control - name: Bucket in: path required: true description: The bucket name that contains the object to which you want to attach the ACL. Access points - When you use this action with an access point for general purpose buckets, you must provide the alias of t schema: type: string - name: Content-MD5 in: header required: false description: The Base64 encoded 128-bit MD5 digest of the data. This header must be used as a message integrity check to verify that the request body was not corrupted in transit. For more information, go to RFC 1 schema: type: string - name: x-amz-sdk-checksum-algorithm in: header required: false description: 'Indicates the algorithm used to create the checksum for the object when you use the SDK. This header will not provide any additional functionality if you don''t use the SDK. When you send this header, ' schema: type: string enum: - CRC32 - CRC32C - SHA1 - SHA256 - CRC64NVME - SHA512 - MD5 - XXHASH64 - XXHASH3 - XXHASH128 - name: x-amz-grant-full-control in: header required: false description: Allows grantee the read, write, read ACP, and write ACP permissions on the bucket. This functionality is not supported for Amazon S3 on Outposts. schema: type: string - name: x-amz-grant-read in: header required: false description: Allows grantee to list the objects in the bucket. This functionality is not supported for Amazon S3 on Outposts. schema: type: string - name: x-amz-grant-read-acp in: header required: false description: Allows grantee to read the bucket ACL. This functionality is not supported for Amazon S3 on Outposts. schema: type: string - name: x-amz-grant-write in: header required: false description: Allows grantee to create new objects in the bucket. For the bucket and object owners of existing objects, also allows deletions and overwrites of those objects. schema: type: string - name: x-amz-grant-write-acp in: header required: false description: Allows grantee to write the ACL for the applicable bucket. This functionality is not supported for Amazon S3 on Outposts. schema: type: string - name: Key in: path required: true description: Key for which the PUT action was initiated. schema: type: string - name: x-amz-request-payer in: header required: false schema: type: string enum: - requester - name: versionId in: query required: false description: Version ID used to reference a specific version of the object. This functionality is not supported for directory buckets. schema: type: string - name: x-amz-expected-bucket-owner in: header required: false description: The account ID of the expected bucket owner. If the account ID that you provide does not match the actual owner of the bucket, the request fails with the HTTP status code 403 Forbidden (access denied) schema: type: string responses: '200': description: Success. S3 answers in XML, not JSON. x-output-shape: PutObjectAclOutput '403': description: AccessDenied. S3 validates the signature before it routes the operation, so this does not distinguish an unsupported operation from an unauthorised one. x-s3-greedy-path-segment: 'AWS writes this route as `/{Bucket}/{Key+}`. The trailing `+` marks a greedy segment, which OpenAPI templating cannot express: an S3 object key may contain slashes, so this parameter is not a single path component.' externalDocs: description: Amazon S3 API Reference url: https://docs.aws.amazon.com/AmazonS3/latest/API/