How to download a file from S3, or share it with a link that expires
Updated · 2 min read
Someone needs a file that's sitting in an S3 bucket: a report, a backup, an export. Downloading one file in the console is easy once you've found it. Whole folders, and "can you send me that?", are where it gets awkward. For sharing, S3 can make a presigned link: an ordinary https link that works for anyone, with no AWS account, until it expires.
In the AWS console
Download a file. Open S3, click the bucket, click through the folders, tick the file and click Download. The console downloads one file at a time, and it can't download a folder.
Share a link. Tick the file, then choose Object actions → Share with a presigned URL. Pick how long the link should last (the console allows up to 12 hours) and click Create presigned URL. The link is copied to your clipboard.
With the AWS CLI
See what's in a folder:
aws s3 ls s3://my-bucket/reports/Download one file into the current directory:
aws s3 cp s3://my-bucket/reports/2026-09.pdf .Download a whole folder:
aws s3 cp s3://my-bucket/reports/ ./reports --recursiveaws s3 sync s3://my-bucket/reports ./reports does the same but skips files you already have, which is better for big folders you fetch more than once.
Make a link that lasts a day. --expires-in is in seconds; the default is 3600 (an hour) and the most is 604800 (seven days):
aws s3 presign s3://my-bucket/reports/2026-09.pdf --expires-in 86400The CLI signs the link on your machine without asking S3 anything, so it doesn't check the file exists. Open the link once before you send it.
Things to know about links
- Anyone who has the link can download the file until it expires. Treat it like the file itself.
- A link can stop working early. It never outlives the credentials that signed it. If you're signed in through IAM Identity Center (SSO) or a role, those might last an hour or a few, whatever
--expires-insays. - You can't cancel one link. You can delete or move the file, or take away the signer's permission to read it, which stops every link they've made for it.
- An error saying the region is wrong (something like "the region 'us-east-1' is wrong; expecting 'eu-west-1'") means the link was signed for the wrong region. Add
--regionwith the bucket's region to thepresigncommand.
Or in Cloud GUI
Cloud GUI's Files page shows every bucket in your account, whatever region it's in, and lets you click through folders with sizes and dates in plain English. With editing turned on (Pro), you can download, upload and delete files too. Downloads go straight from S3 to your browser over a link that lasts five minutes, so the file never passes through Cloud GUI's servers. It doesn't make share links: use aws s3 presign for those.