RE:NODE

Operations11 min read

S3 GUI clients: Cyberduck, WinSCP and S3 Browser setup

Connect Cyberduck, WinSCP and S3 Browser to an S3-compatible endpoint: path-style settings, HTTP vs HTTPS, keys, and the errors each client shows when one is wrong.

0 readers

To browse an S3-compatible bucket with a mouse, use Cyberduck on Windows or macOS, WinSCP or S3 Browser on Windows, and give each one the same four things: the endpoint hostname, the access key, the secret key, and path-style addressing. The last is the one that fails silently. All three clients assume Amazon's virtual-hosted style by default, put the bucket name in the hostname, and then report a vague connection or "cannot read container" error. In Cyberduck you fix it with the "S3 (Deprecated path style requests)" connection profile; in WinSCP with URL style set to Path; in S3 Browser with the addressing model set to path style. This post walks through each client's exact settings, what to do for plain HTTP versus HTTPS, and the ways S3 behaves differently from the SFTP folders these programs were originally built for.

Which client to use#

ClientPlatformsPriceGood at
CyberduckWindows, macOSFree (donations)Clean interface, bookmarks, works with many backends
WinSCPWindowsFree, open sourceAlready installed by many; scripting; sync
S3 BrowserWindowsFree for personal use, paid ProS3-specific features, detailed settings
Mountain DuckWindows, macOSPaidMounts a bucket as a drive letter or volume
rclone mountWindows, macOS, LinuxFree, open sourceDrive from the command line, scripting

If you only want to drag files in and out now and then, Cyberduck is the least fuss and behaves the same on both systems. If you already use WinSCP for SFTP, adding an S3 site to it means one program for everything. S3 Browser exposes more of the S3 API in its menus than the other two and is the one Windows users reach for when they want to inspect object headers and metadata. Mountain Duck (from the makers of Cyberduck) and rclone mount turn a bucket into something that looks like a disk, which is convenient and comes with caveats covered further down.

The settings every client needs#

Gather these before opening any program:

SettingExampleWhere it comes from
Endpoint hosts3.example.comThe hostname you point at the storage, or the raw address
Port443 for HTTPSThe proxy slot, or the plain HTTP port for the raw address
Access key IDAKIA...Generated for the server, shown in the panel
Secret access key40 charactersSame place; treat as a password
AddressingPath-styleRequired by most S3-compatible endpoints
Regionus-east-1Any value if the provider accepts any

On RE:NODE's S3 storage the access key, secret key and first bucket are created with the server and shown in the panel. The endpoint answers plain HTTP on its own port, and the plan's proxy slot gives you HTTPS: point a hostname such as s3.example.com at the address shown, the certificate is issued and renewed for you, and clients connect on port 443. Use the HTTPS name in every GUI client. Plain HTTP works, but sends your files and every request in the clear, so keep it for a quick test on a network you trust. Your domain and its certificate covers pointing the hostname.

Cyberduck#

Cyberduck ships with an "Amazon S3" connection type that is tuned for AWS and uses virtual-hosted requests. For a path-style endpoint you install a connection profile - a small file that tells Cyberduck how to talk to a particular kind of server.

  1. Open Preferences, then Profiles.
  2. Search for "path style" and tick S3 (Deprecated path style requests). The word "deprecated" refers to Amazon's view of path-style; for an S3-compatible endpoint it is the correct choice.
  3. If you need plain HTTP for a test, also tick S3 (HTTP). There is no combined plain-HTTP path-style profile in the default list, which is one more reason to use the HTTPS hostname.
  4. Click Open Connection (or create a bookmark) and choose the path-style profile from the protocol dropdown.
  5. Fill in Server s3.example.com, Port 443, and the Access Key ID and Secret Access Key from the panel.
  6. Connect. You should see your buckets listed as top-level folders.

Cyberduck also has a hidden setting, s3.bucket.virtualhost.disable, which turns off virtual-hosted requests globally when set to true. The profile is the cleaner route because it affects only the bookmarks that use it, so your AWS bookmarks keep working.

If the key you were given can only see one bucket and not list all of them, connect with the path field (under More Options in the connection dialog) set to /bucket-name, and Cyberduck opens straight into the bucket instead of trying to list every bucket first.

Two Cyberduck settings are worth changing for larger transfers: under Preferences, Transfers, set downloads and uploads to use multiple connections, and if you upload big files often, leave multipart upload enabled (it is by default) so a dropped connection resumes a part instead of starting over.

WinSCP#

WinSCP added Amazon S3 as a file protocol alongside SFTP, FTP and WebDAV. Its defaults also assume virtual-hosted style.

  1. In the Login dialog, choose New Site.
  2. Set File protocol to Amazon S3.
  3. Host name: s3.example.com. Port number: 443.
  4. Access key ID and Secret access key from the panel.
  5. Click Advanced, go to Environment, then S3, and change URL style from Virtual Host to Path. In the same page you can set the default region; leave it empty or use us-east-1 unless the provider asks for a specific name.
  6. Save the site and log in.

If you skip step 5, WinSCP tries to resolve bucket-name.s3.example.com, and the error is about a host name that cannot be resolved - which sends people looking at DNS for a problem that is a single dropdown.

WinSCP's strength is everything around the connection. Its synchronise function (Commands, Synchronize) compares a local folder with a bucket prefix and copies the differences, and the same site can be driven from a script with winscp.com /script=... for scheduled jobs. For heavy scheduled work a dedicated tool such as rclone is still better - see rclone with S3 storage - but for a Windows user who wants a scripted upload of a folder every night, WinSCP is often already installed.

S3 Browser#

S3 Browser is a Windows client built only for S3, so its account dialog has more S3 vocabulary in it.

  1. Accounts, Add new account.
  2. Account type: S3 Compatible Storage.
  3. REST Endpoint: s3.example.com (add :port only if it is not the standard port for the scheme).
  4. Access Key ID and Secret Access Key from the panel.
  5. Tick Use secure transfer (SSL/TLS) for the HTTPS hostname. Untick it only for the raw plain-HTTP port.
  6. Open the advanced settings for the account and set the addressing model to path style. Leave the signature version at the newest one offered (Signature V4).
  7. Save and connect.

The free edition is licensed for personal use and limits some features, such as the number of accounts; the Pro edition removes those limits and is required for commercial use. The program's strength is that it shows you what S3 actually stores: each object's HTTP headers, its metadata and, where the server supports it, its access settings. When an image downloads instead of displaying because it was uploaded as binary/octet-stream, S3 Browser is where you see that and fix the Content-Type.

Mounting a bucket as a drive#

Mountain Duck and rclone mount make a bucket appear as a drive letter on Windows or a volume on macOS and Linux, so any program can open files in it. This is convenient for browsing and for occasional edits, and it is a poor fit for anything that writes a lot.

bash
$ rclone mount store:media X: --vfs-cache-mode writes

On Windows rclone mount needs WinFsp installed; on macOS it needs macFUSE or uses an NFS-based mount in recent versions. --vfs-cache-mode writes buffers files locally while they are being written and uploads them when closed, which is what most applications expect.

The caveat is structural. S3 has no partial writes: changing one byte of a 2 GB file means uploading the whole 2 GB again. A program that saves often, or a database, or a game server writing its world, will generate an enormous amount of traffic and may see files in inconsistent states. Use mounts for reading and for files that are written once. For anything else, copy files explicitly.

How S3 differs from the disk you are used to#

GUI clients do a good job of making a bucket look like a folder tree, but the illusion leaks in a few predictable places.

Folders are not real. A key is one string - photos/2026/october/cat.jpg - and the client draws folders by splitting on /. Creating an empty folder in a GUI client usually uploads an empty placeholder object called photos/2026/ so the folder has something to show. Other tools may not create or expect those placeholders, so a folder made in one client can look different in another, and deleting the last file in a folder can make the folder vanish.

Renaming is copying. S3 has no rename. Renaming a file is a server-side copy to the new key and a delete of the old one; renaming a folder is that operation for every object under it. For a folder with ten thousand files, a "rename" is twenty thousand requests and takes a while.

Editing is replacing. Opening a file "in place" downloads it to a temporary location; saving uploads the whole thing as a new object. There is no partial update, which is why editing large files over S3 is slow.

Timestamps are upload times. S3's Last-Modified is when the object was written to the bucket, not when the file was last changed on your computer. Some clients store the original modification time in metadata and show that instead; others do not. Do not use a GUI client's dates to decide which copy of a file is newer.

There is no undo. Storage without versioning has no recycle bin. A deleted object is gone. That is worth remembering before dragging a folder onto the wrong side of the window, and it is the reason a bucket you use by hand should not be the only copy of anything.

Troubleshooting#

MessageClientCauseFix
"Cannot read container configuration"CyberduckVirtual-hosted profile on a path-style endpointUse the path-style profile
Host name cannot be resolved, naming bucket.s3...WinSCP, othersVirtual-hosted URL styleSet URL style to Path
"The request signature we calculated does not match"AnyWrong secret, or a proxy changing the Host headerRe-copy the secret; check the proxy
"The AWS Access Key Id you provided does not exist"AnyClient is talking to Amazon, not your endpointCheck the server field
SSL handshake or "wrong version number"AnyHTTPS spoken to the plain HTTP port, or the reverseMatch the scheme to the port
Certificate name mismatchAnyConnecting by IP, or virtual-hosted styleUse the hostname with path-style
Access denied listing bucketsAnyKey limited to one bucketOpen the bucket path directly

The second-to-last pair is easy to confuse. "Wrong version number" means the client spoke TLS to a port that answers plain HTTP (or the other way round); a certificate mismatch means TLS worked but the name on the certificate does not match what the client asked for. The first is a scheme and port problem, the second a hostname problem. Path-style vs virtual-hosted URLs explains why the bucket name in the hostname breaks certificates.

When nothing makes sense, test the same keys with the AWS CLI. If aws s3 ls works with the same endpoint and keys, the server is fine and the GUI client's settings are the problem; S3 storage with the AWS CLI has the setup.

Keys on a shared or work computer#

A GUI client saves the secret key so you do not have to type it each time. Cyberduck stores it in the system keychain (macOS Keychain or Windows Credential Manager), WinSCP in its configuration unless you set a master password, and S3 Browser in its account settings. On a computer other people use, set WinSCP's master password, do not save the secret at all, or use a key generated for a bucket that holds nothing sensitive. If a laptop with saved keys is lost, regenerate the keys in the panel the same day - that invalidates the copy on the laptop and every other copy in one step.

FAQ#

Is there an S3 client for Linux with a GUI?

Cyberduck has no Linux version. On Linux the common choices are a file manager over an rclone mount, or rclone's experimental web interface started with rclone rcd --rc-web-gui. Most Linux users end up preferring rclone on the command line.

Can I use FileZilla for S3?

Only FileZilla Pro, the paid edition, supports S3; the free FileZilla client does not. If you already pay for it, set the protocol to S3 and the endpoint to your hostname, and look for its path-style option in the S3 settings.

Why do I see empty files named like folders?

They are folder placeholders some clients create so that an empty folder can exist in a store that has no real folders. They are harmless, zero bytes each, and safe to leave alone.

Can I make a file public from the GUI client?

Some clients have a "make public" or permissions option that sets an object ACL. Whether that does anything depends on what the storage server supports, so do not rely on it. To share a file, generate a time-limited link instead - Cyberduck and S3 Browser can both create presigned URLs, and presigned URLs explains how they work.

Why are uploads slow compared to SFTP?

Many small files are the usual reason: each object is a separate HTTP request with its own signature and round trip. Raise the number of parallel transfers in the client's settings, or zip folders of tiny files before uploading.


Comments

Completely anonymous: no account, no email, no cookie. We store the name you type, the text and the time - nothing else. Links are limited and markup is not rendered.

0/2000