How to download a file from S3, or share it with a link that expires

Updated · 2 min read

Someone needs a file that's sitting in an S3 bucket: a report, a backup, an export. Downloading one file in the console is easy once you've found it. Whole folders, and "can you send me that?", are where it gets awkward. For sharing, S3 can make a presigned link: an ordinary https link that works for anyone, with no AWS account, until it expires.

In the AWS console

Download a file. Open S3, click the bucket, click through the folders, tick the file and click Download. The console downloads one file at a time, and it can't download a folder.

Share a link. Tick the file, then choose Object actions → Share with a presigned URL. Pick how long the link should last (the console allows up to 12 hours) and click Create presigned URL. The link is copied to your clipboard.

With the AWS CLI

See what's in a folder:

aws s3 ls s3://my-bucket/reports/

Download one file into the current directory:

aws s3 cp s3://my-bucket/reports/2026-09.pdf .

Download a whole folder:

aws s3 cp s3://my-bucket/reports/ ./reports --recursive

aws s3 sync s3://my-bucket/reports ./reports does the same but skips files you already have, which is better for big folders you fetch more than once.

Make a link that lasts a day. --expires-in is in seconds; the default is 3600 (an hour) and the most is 604800 (seven days):

aws s3 presign s3://my-bucket/reports/2026-09.pdf --expires-in 86400

The CLI signs the link on your machine without asking S3 anything, so it doesn't check the file exists. Open the link once before you send it.

  • Anyone who has the link can download the file until it expires. Treat it like the file itself.
  • A link can stop working early. It never outlives the credentials that signed it. If you're signed in through IAM Identity Center (SSO) or a role, those might last an hour or a few, whatever --expires-in says.
  • You can't cancel one link. You can delete or move the file, or take away the signer's permission to read it, which stops every link they've made for it.
  • An error saying the region is wrong (something like "the region 'us-east-1' is wrong; expecting 'eu-west-1'") means the link was signed for the wrong region. Add --region with the bucket's region to the presign command.

Or in Cloud GUI

Cloud GUI's Files page shows every bucket in your account, whatever region it's in, and lets you click through folders with sizes and dates in plain English. With editing turned on (Pro), you can download, upload and delete files too. Downloads go straight from S3 to your browser over a link that lasts five minutes, so the file never passes through Cloud GUI's servers. It doesn't make share links: use aws s3 presign for those.

See your whole AWS account in one calm view

Cloud GUI shows your files and functions from every region at once, in plain English, with what's failing up front. It connects with a read-only role you create and can delete any time. Free for one AWS account.

More guides

Free tool
IAM policy explainer

Paste an IAM policy and read it in plain English, with the risky parts flagged. It runs in your browser; nothing is sent anywhere.