{"_id":"aws-sigv4-sign","_rev":"6-bc88e3a83493e6d2d334d0574b064381","name":"aws-sigv4-sign","dist-tags":{"latest":"2.0.1"},"versions":{"1.0.0":{"name":"aws-sigv4-sign","version":"1.0.0","keywords":["aws","aws-sdk","aws-sigv4","fetch","http","request","sign","signer","signed","signature","sigv4","signature-v4","signaturev4"],"license":"MIT","_id":"aws-sigv4-sign@1.0.0","maintainers":[{"name":"chriszirkel","email":"chris.zirkel@gmail.com"}],"homepage":"https://github.com/zirkelc/aws-sigv4/packages/aws-sigv4-sign#readme","bugs":{"url":"https://github.com/zirkelc/aws-sigv4/issues"},"dist":{"shasum":"286f182f57ffe405b8bcb7a686a1cac9f3902cd0","tarball":"https://registry.npmjs.org/aws-sigv4-sign/-/aws-sigv4-sign-1.0.0.tgz","fileCount":7,"integrity":"sha512-tGdWeneEiho+vq6fTehmQ+ItEOG8D3BEmKPsiXdL2Y4l4/hkOdb50fNgpgIpcEQgOIKCsIezui2troZTqJHxag==","signatures":[{"sig":"MEUCIAdPqfqyhYQFj0W2JI5h1ER4q3fBszHm0Tfsh+nqgwmPAiEA6F1YSkS0mMuFMt2rZY4HRQZKxhgMJG0OGSvKvBNbfYk=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":14496},"main":"./dist/index.cjs","type":"module","_from":"file:aws-sigv4-sign-1.0.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18"},"exports":{".":{"import":"./dist/index.js","require":"./dist/index.cjs"}},"scripts":{"test":"vitest","build":"tsup && pnpm pack | tail -n1 | xargs attw"},"_npmUser":{"name":"chriszirkel","email":"chris.zirkel@gmail.com"},"_resolved":"/private/var/folders/_y/_4h8lsmx5053g1g2x562lt0m0000gn/T/d6cbce290799be8c84955b562541fb8f/aws-sigv4-sign-1.0.0.tgz","_integrity":"sha512-tGdWeneEiho+vq6fTehmQ+ItEOG8D3BEmKPsiXdL2Y4l4/hkOdb50fNgpgIpcEQgOIKCsIezui2troZTqJHxag==","repository":{"url":"git+https://github.com/zirkelc/aws-sigv4.git","type":"git","directory":"packages/aws-sigv4-sign"},"_npmVersion":"10.5.2","description":"SignatureV4 sign function implemented with the official @aws-sdk v3","directories":{},"_nodeVersion":"20.13.1","dependencies":{"@aws-sdk/types":"^3.609.0","@smithy/signature-v4":"^3.1.2","@aws-crypto/sha256-js":"^5.2.0","@smithy/protocol-http":"^4.0.3","@aws-sdk/credential-provider-node":"^3.609.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/aws-sigv4-sign_1.0.0_1736675407990_0.9023385234091139","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"aws-sigv4-sign","version":"1.1.0","keywords":["aws","aws-sdk","aws-sigv4","fetch","http","request","sign","signer","signed","signature","sigv4","signature-v4","signaturev4"],"license":"MIT","_id":"aws-sigv4-sign@1.1.0","maintainers":[{"name":"chriszirkel","email":"chris.zirkel@gmail.com"}],"homepage":"https://github.com/zirkelc/aws-sigv4/packages/aws-sigv4-sign#readme","bugs":{"url":"https://github.com/zirkelc/aws-sigv4/issues"},"dist":{"shasum":"d31e955585a0957bed00148ed7e346547def5118","tarball":"https://registry.npmjs.org/aws-sigv4-sign/-/aws-sigv4-sign-1.1.0.tgz","fileCount":7,"integrity":"sha512-yBCJu8LbcZTp6xq+pcdSKs91yoDdsr6xwv0hapw1u9RXJ2SJFhSP9iXLWMleh+snqXi0COl+DTbw6t9nUeyphQ==","signatures":[{"sig":"MEQCIAPit7XRhAB4JF+urA1VFtzq1zYjo8gzkNJf25wlX7NsAiAVyvkh7fKSZaywmtxRbOzSvXQIAKRHzfvmgKWfqsNydg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":15948},"main":"./dist/index.cjs","type":"module","_from":"file:aws-sigv4-sign-1.1.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18"},"exports":{".":{"import":"./dist/index.js","require":"./dist/index.cjs"}},"scripts":{"test":"vitest","build":"tsup && pnpm pack | tail -n1 | xargs attw"},"_npmUser":{"name":"chriszirkel","email":"chris.zirkel@gmail.com"},"_resolved":"/tmp/87fe0d69ea50eb6d9c197994370af693/aws-sigv4-sign-1.1.0.tgz","_integrity":"sha512-yBCJu8LbcZTp6xq+pcdSKs91yoDdsr6xwv0hapw1u9RXJ2SJFhSP9iXLWMleh+snqXi0COl+DTbw6t9nUeyphQ==","repository":{"url":"git+https://github.com/zirkelc/aws-sigv4.git","type":"git","directory":"packages/aws-sigv4-sign"},"_npmVersion":"10.8.2","description":"SignatureV4 sign function implemented with the official AWS SDK","directories":{},"_nodeVersion":"20.18.2","dependencies":{"@smithy/signature-v4":"^3.1.2","@aws-crypto/sha256-js":"^5.2.0","@smithy/protocol-http":"^4.0.3","@aws-sdk/credential-provider-node":"^3.609.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@aws-sdk/types":"^3.609.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-sigv4-sign_1.1.0_1739367672281_0.48696673337000473","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"aws-sigv4-sign","version":"1.2.0","keywords":["aws","aws-sdk","aws-sigv4","fetch","http","request","sign","signer","signed","signature","sigv4","signature-v4","signaturev4"],"license":"MIT","_id":"aws-sigv4-sign@1.2.0","maintainers":[{"name":"chriszirkel","email":"chris.zirkel@gmail.com"}],"homepage":"https://github.com/zirkelc/aws-sigv4/packages/aws-sigv4-sign#readme","bugs":{"url":"https://github.com/zirkelc/aws-sigv4/issues"},"dist":{"shasum":"8b43cdcd6ba92e0b94fc3f6dd1233c5204782240","tarball":"https://registry.npmjs.org/aws-sigv4-sign/-/aws-sigv4-sign-1.2.0.tgz","fileCount":7,"integrity":"sha512-KumnqSHHeNVLAcKvoyRJv8vSj4uT+mcto5eOccjHtzZJaytFedoH7+FxlRMn/7J1Mw8F95mc/10wLH/j0chJfg==","signatures":[{"sig":"MEYCIQDmp9my0Hapyh5sL8KChQfKJNcRnbvXOHx6ZBMf9qyucgIhAN6GjC4HTmYW7uAqDqW6HB906d9UHlso7ZNBLPkPRkxJ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":22146},"main":"./dist/index.cjs","type":"module","_from":"file:aws-sigv4-sign-1.2.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","browser":{"@aws-sdk/credential-provider-node":false},"engines":{"node":">=18"},"exports":{".":{"import":"./dist/index.js","require":"./dist/index.cjs"}},"scripts":{"test":"vitest","build":"tsup && pnpm pack | tail -n1 | xargs attw"},"_npmUser":{"name":"chriszirkel","email":"chris.zirkel@gmail.com"},"_resolved":"/tmp/0d87bbb24757c09920774dc4138c3a3e/aws-sigv4-sign-1.2.0.tgz","_integrity":"sha512-KumnqSHHeNVLAcKvoyRJv8vSj4uT+mcto5eOccjHtzZJaytFedoH7+FxlRMn/7J1Mw8F95mc/10wLH/j0chJfg==","repository":{"url":"git+https://github.com/zirkelc/aws-sigv4.git","type":"git","directory":"packages/aws-sigv4-sign"},"_npmVersion":"10.8.2","description":"SignatureV4 sign function implemented with the official AWS SDK","directories":{},"_nodeVersion":"20.18.3","dependencies":{"@smithy/signature-v4":"^3.1.2","@aws-crypto/sha256-js":"^5.2.0","@smithy/protocol-http":"^4.0.3","@aws-sdk/credential-provider-node":"^3.609.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@aws-sdk/types":"^3.609.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-sigv4-sign_1.2.0_1742016096179_0.4601616722774109","host":"s3://npm-registry-packages-npm-production"}},"1.2.1":{"name":"aws-sigv4-sign","version":"1.2.1","keywords":["aws","aws-sdk","aws-sigv4","fetch","http","request","sign","signer","signed","signature","sigv4","signature-v4","signaturev4"],"license":"MIT","_id":"aws-sigv4-sign@1.2.1","maintainers":[{"name":"chriszirkel","email":"chris.zirkel@gmail.com"}],"homepage":"https://github.com/zirkelc/aws-sigv4/packages/aws-sigv4-sign#readme","bugs":{"url":"https://github.com/zirkelc/aws-sigv4/issues"},"dist":{"shasum":"20dadc10a9c8052a02fadda876adc68103dedbd6","tarball":"https://registry.npmjs.org/aws-sigv4-sign/-/aws-sigv4-sign-1.2.1.tgz","fileCount":7,"integrity":"sha512-iS0pV4xGzhexBCMG9ggXM5CaxTHa3KxOxkw2tphLgA/60vSycSWjJWso0s4xzGRrtABSi0b3LlxG5Jek7NjuqA==","signatures":[{"sig":"MEUCIQCzsefX7rY8nW3jq2Uvvv3MNi/jndA3m8M38t1KUcuSJAIgC8jp9qhNFBbsoOa4CYmU6lWyTwxZYMenXzsETG6SODs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":26489},"main":"./dist/index.cjs","type":"module","_from":"file:aws-sigv4-sign-1.2.1.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","browser":{"@aws-sdk/credential-provider-node":false},"engines":{"node":">=18"},"exports":{".":{"import":"./dist/index.js","require":"./dist/index.cjs"}},"scripts":{"test":"vitest","build":"tsup && pnpm pack | tail -n1 | xargs attw"},"_npmUser":{"name":"chriszirkel","email":"chris.zirkel@gmail.com"},"_resolved":"/tmp/14bebf8fbbffda0a94c65dfa3ebe5f81/aws-sigv4-sign-1.2.1.tgz","_integrity":"sha512-iS0pV4xGzhexBCMG9ggXM5CaxTHa3KxOxkw2tphLgA/60vSycSWjJWso0s4xzGRrtABSi0b3LlxG5Jek7NjuqA==","repository":{"url":"git+https://github.com/zirkelc/aws-sigv4.git","type":"git","directory":"packages/aws-sigv4-sign"},"_npmVersion":"10.8.2","description":"SignatureV4 sign function implemented with the official AWS SDK","directories":{},"_nodeVersion":"20.18.3","dependencies":{"@smithy/signature-v4":"^3.1.2","@aws-crypto/sha256-js":"^5.2.0","@smithy/protocol-http":"^4.0.3","@aws-sdk/credential-provider-node":"^3.609.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@aws-sdk/types":"^3.609.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-sigv4-sign_1.2.1_1742286883126_0.9693657170593988","host":"s3://npm-registry-packages-npm-production"}},"2.0.0":{"name":"aws-sigv4-sign","version":"2.0.0","keywords":["aws","aws-sdk","aws-sigv4","fetch","http","request","sign","signature","signature-v4","signaturev4","signed","signer","sigv4"],"license":"MIT","_id":"aws-sigv4-sign@2.0.0","maintainers":[{"name":"chriszirkel","email":"chris.zirkel@gmail.com"}],"homepage":"https://github.com/zirkelc/aws-signature-v4/packages/aws-sigv4-sign#readme","bugs":{"url":"https://github.com/zirkelc/aws-signature-v4/issues"},"dist":{"shasum":"8948babb458aae5959d4aab861499edd3c563ca4","tarball":"https://registry.npmjs.org/aws-sigv4-sign/-/aws-sigv4-sign-2.0.0.tgz","fileCount":7,"integrity":"sha512-QMFmnNHVTiaVKUe3BV75XQCD2EJvWu8yERkSAR765uyQh2Ar5LR5I5R9xjVtO9WxN3aGBiUkQGnImb4XMA7lYQ==","signatures":[{"sig":"MEUCIAK0I+/bapSSohIgPaDuCfOlnnhrSzHjVUBYjbvqzPfpAiEA04tTgM0ioC/2+rSWUvlVjTLYsb+jFYoJmsl6oeKBrK4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/aws-sigv4-sign@2.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":34278},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.mts","module":"./dist/index.mjs","browser":{"@aws-sdk/credential-provider-node":false},"engines":{"node":">=20"},"exports":{".":{"import":"./dist/index.mjs","require":"./dist/index.cjs"}},"scripts":{"test":"vitest","build":"tsdown","typecheck":"tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:99fbf995-6b54-4bc9-a697-bdb35e81a23f"}},"repository":{"url":"git+https://github.com/zirkelc/aws-signature-v4.git","type":"git","directory":"packages/aws-sigv4-sign"},"description":"SignatureV4 sign function implemented with the official AWS SDK","directories":{},"_nodeVersion":"22.23.1","dependencies":{"@smithy/signature-v4":"^5.6.4","@aws-crypto/sha256-js":"^5.2.0","@smithy/protocol-http":"^5.5.8","@aws-sdk/credential-provider-node":"^3.972.66"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@aws-sdk/types":"^3.974.0"},"_npmOperationalInternal":{"tmp":"tmp/aws-sigv4-sign_2.0.0_1785404444981_0.20785388475001954","host":"s3://npm-registry-packages-npm-production"}},"2.0.1":{"name":"aws-sigv4-sign","version":"2.0.1","description":"SignatureV4 sign function implemented with the official AWS SDK","keywords":["aws","aws-sdk","aws-sigv4","fetch","http","request","sign","signature","signature-v4","signaturev4","signed","signer","sigv4"],"homepage":"https://github.com/zirkelc/aws-signature-v4/packages/aws-sigv4-sign#readme","bugs":{"url":"https://github.com/zirkelc/aws-signature-v4/issues"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/zirkelc/aws-signature-v4.git","directory":"packages/aws-sigv4-sign"},"type":"module","main":"./dist/index.cjs","module":"./dist/index.mjs","browser":{"@aws-sdk/credential-provider-node":false},"exports":{".":{"require":"./dist/index.cjs","import":"./dist/index.mjs"}},"publishConfig":{"access":"public"},"dependencies":{"@aws-crypto/sha256-js":"^5.2.0","@aws-sdk/credential-provider-node":"^3.972.66","@smithy/protocol-http":"^5.5.8","@smithy/signature-v4":"^5.6.4"},"devDependencies":{"@aws-sdk/types":"^3.974.0"},"engines":{"node":">=20"},"scripts":{"test":"vitest","typecheck":"tsc --noEmit","build":"tsdown"},"types":"./dist/index.d.mts","_nodeVersion":"22.23.1","_id":"aws-sigv4-sign@2.0.1","dist":{"integrity":"sha512-Jd6mxwZhRynum+etGvXyYcaAMUAgkMqclpE6JjzmDJE/HKKBfjjYPzZQ/BpI8X6cmnZ4uWW1YjveJ8cYKjvJig==","shasum":"ffe84ba5815fb8b0bf80afe4a6f52885ec82a6fc","tarball":"https://registry.npmjs.org/aws-sigv4-sign/-/aws-sigv4-sign-2.0.1.tgz","fileCount":7,"unpackedSize":34703,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/aws-sigv4-sign@2.0.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQC5c7ieb4wrO6eJa06K5JRGpELV5YbwzscvzOzMA7+GmAIgbHPR3R2Hr0Iwy4T1hD7rpq5Q+CCN3p76dL1xAGv6OrI="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:99fbf995-6b54-4bc9-a697-bdb35e81a23f"}},"directories":{},"maintainers":[{"name":"chriszirkel","email":"chris.zirkel@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/aws-sigv4-sign_2.0.1_1785406716934_0.14636266889414462"},"_hasShrinkwrap":false}},"time":{"created":"2025-01-12T09:50:07.890Z","modified":"2026-07-30T10:18:37.336Z","1.0.0":"2025-01-12T09:50:08.170Z","1.1.0":"2025-02-12T13:41:12.527Z","1.2.0":"2025-03-15T05:21:36.360Z","1.2.1":"2025-03-18T08:34:43.335Z","2.0.0":"2026-07-30T09:40:45.124Z","2.0.1":"2026-07-30T10:18:37.061Z"},"bugs":{"url":"https://github.com/zirkelc/aws-signature-v4/issues"},"license":"MIT","homepage":"https://github.com/zirkelc/aws-signature-v4/packages/aws-sigv4-sign#readme","keywords":["aws","aws-sdk","aws-sigv4","fetch","http","request","sign","signature","signature-v4","signaturev4","signed","signer","sigv4"],"repository":{"type":"git","url":"git+https://github.com/zirkelc/aws-signature-v4.git","directory":"packages/aws-sigv4-sign"},"description":"SignatureV4 sign function implemented with the official AWS SDK","maintainers":[{"name":"chriszirkel","email":"chris.zirkel@gmail.com"}],"readme":"<div align=\"center\">\n\n<h1>aws-sigv4-sign</h1>\n\n<p align=\"center\">SignatureV4 sign function implemented with the official AWS SDK</p>\n<p align=\"center\">\n  <a href=\"https://www.npmjs.com/package/aws-sigv4-sign\" alt=\"aws-sigv4-sign\"><img src=\"https://img.shields.io/npm/dt/aws-sigv4-sign?label=aws-sigv4-sign\"></a> <a href=\"https://github.com/zirkelc/aws-signature-v4/actions/workflows/ci.yml\" alt=\"CI\"><img src=\"https://img.shields.io/github/actions/workflow/status/zirkelc/aws-signature-v4/ci.yml?branch=main\"></a>\n</p>\n\n</div>\n\nThis library signs HTTP requests with [AWS Signature Version 4](https://docs.aws.amazon.com/general/latest/gr/signature-version-4.html) and returns a standard [`Request`](https://developer.mozilla.org/en-US/docs/Web/API/Request) carrying the signed headers, ready to hand to any HTTP client. Signing is done by [`@smithy/signature-v4`](https://www.npmjs.com/package/@smithy/signature-v4), the same signer the AWS SDK uses, so signatures are computed exactly the way AWS expects.\n\n## Why?\n\nMost AWS services (API Gateway, Lambda Function URLs, AppSync, IAM, OpenSearch) can be locked behind IAM authentication. Once they are, an unsigned request is rejected with `403 Forbidden`, because every request must carry an `Authorization` header derived from your credentials, the request itself, and the current time. However, you may not want to:\n\n- **Adopt a service-specific SDK client**: pulling in `@aws-sdk/client-*` just to call your own HTTP endpoint is a lot of dependency for one request\n- **Hand-roll the signature**: SigV4 covers the method, URL, query string, headers and body, and getting the canonical form wrong fails with an opaque `403`\n- **Change HTTP client**: you already use Axios, Ky, Got or `node:https`, and signing should not dictate that choice\n\nThis library computes the signature and gives you back plain headers, leaving the transport entirely up to you.\n\n> [!TIP]\n> Using the [`fetch`](https://developer.mozilla.org/en-US/docs/Web/API/fetch) API? Use [`aws-sigv4-fetch`](https://github.com/zirkelc/aws-signature-v4/tree/main/packages/aws-sigv4-fetch), which wraps this library in a drop-in `fetch` replacement that signs every request for you.\n\n## Installation\n\n```bash\nnpm install aws-sigv4-sign\n```\n\nRequires Node.js >= 20. Ships both ES Module and CommonJS builds with bundled TypeScript declarations, so no `@types/*` package is needed.\n\n```ts\n// ESM\nimport { signRequest } from 'aws-sigv4-sign';\n\n// CommonJS\nconst { signRequest } = require('aws-sigv4-sign');\n```\n\n## Usage\n\n`signRequest` mirrors the [`fetch`](https://developer.mozilla.org/en-US/docs/Web/API/fetch) argument shape and appends a required options object. The input can be a `string`, a [`URL`](https://developer.mozilla.org/en-US/docs/Web/API/URL) or a [`Request`](https://developer.mozilla.org/en-US/docs/Web/API/Request), with an optional [`RequestInit`](https://developer.mozilla.org/en-US/docs/Web/API/RequestInit) in between.\n\n```ts\nimport { signRequest } from 'aws-sigv4-sign';\n\nconst signedRequest = await signRequest('https://mylambda.lambda-url.eu-west-1.on.aws/', {\n  service: 'lambda',\n  region: 'eu-west-1',\n});\n\nconst response = await fetch(signedRequest);\n```\n\n### Reading the signed headers\n\nThe returned `Request` carries the signing headers on its [`headers`](https://developer.mozilla.org/en-US/docs/Web/API/Request/headers) property. Convert them to a plain object to pass them to a client that does not accept a `Request`.\n\n```ts\nconst signedRequest = await signRequest(url, { service: 'lambda', region: 'eu-west-1' });\n\nconst headers = Object.fromEntries(signedRequest.headers.entries());\n\nheaders.authorization; // AWS4-HMAC-SHA256 Credential=.../20250101/eu-west-1/lambda/aws4_request, SignedHeaders=..., Signature=...\nheaders.host; // mylambda.lambda-url.eu-west-1.on.aws\nheaders['x-amz-date']; // 20250101T000000Z\nheaders['x-amz-content-sha256']; // hex-encoded SHA-256 of the body\nheaders['x-amz-security-token']; // only when the credentials include a session token\n```\n\n### Sending with any HTTP client\n\nEvery client works the same way: sign, read the headers, send. Pass `signedRequest.url` rather than the original input, so the URL that was signed is the URL that is sent.\n\n```ts\nconst signedRequest = await signRequest(url, { service: 'lambda', region: 'eu-west-1' });\nconst headers = Object.fromEntries(signedRequest.headers.entries());\n\n// Axios\nimport axios from 'axios';\nawait axios(signedRequest.url, { headers });\n\n// Ky\nimport ky from 'ky';\nawait ky.get(signedRequest.url, { headers });\n\n// Got\nimport got from 'got';\nawait got(signedRequest.url, { headers });\n\n// node:https\nimport { request } from 'node:https';\nrequest(signedRequest.url, { headers }, (res) => {\n  /* ... */\n}).end();\n```\n\n### Sending a body\n\nThe body is part of the signature, so it has to be passed to `signRequest` in the `RequestInit` and sent unchanged. With a body, the options move to the third argument.\n\n```ts\nconst signedRequest = await signRequest(\n  'https://mylambda.lambda-url.eu-west-1.on.aws/',\n  {\n    method: 'POST',\n    body: JSON.stringify({ a: 1 }),\n    headers: { 'Content-Type': 'application/json' },\n  },\n  { service: 'lambda', region: 'eu-west-1' },\n);\n```\n\n### Service and region\n\n`service` is required and must match the AWS service you are calling. A mismatch fails with `Credential should be scoped to correct service: 'service'`. `region` is optional and defaults to `us-east-1`.\n\nCommon values:\n\n| Target                           | `service`     |\n| -------------------------------- | ------------- |\n| API Gateway (REST and HTTP APIs) | `execute-api` |\n| Lambda Function URL              | `lambda`      |\n| AppSync                          | `appsync`     |\n| IAM                              | `iam`         |\n| OpenSearch / Elasticsearch       | `es`          |\n| S3                               | `s3`          |\n\n### Credentials\n\nCredentials are **optional in Node.js** and **required in the browser**. When omitted in Node.js they are resolved with [`@aws-sdk/credential-provider-node`](https://www.npmjs.com/package/@aws-sdk/credential-provider-node), which checks, in order: environment variables, SSO token cache, web identity tokens, shared credentials and config files, and finally the EC2/ECS instance metadata service.\n\n```ts\n// Credentials are picked up from the environment\nconst signedRequest = await signRequest(url, { service: 'lambda', region: 'eu-west-1' });\n```\n\n> [!IMPORTANT]\n> The default provider is constructed once and reused for the lifetime of the process. The AWS SDK caches the credentials it resolves and refreshes them before they expire, so only the first signed request pays for the lookup. Because the provider is pinned, changes to `AWS_PROFILE` or the other credential environment variables after the first signed request are not picked up; pass `credentials` explicitly if you need to switch identities at runtime.\n\nYou can always pass credentials explicitly, which skips the lookup. The option accepts either a static [`AwsCredentialIdentity`](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/Package/-smithy-types/Interface/AwsCredentialIdentity/) or an [`AwsCredentialIdentityProvider`](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/Package/-smithy-types/Interface/AwsCredentialIdentityProvider/) function:\n\n```ts\nconst signedRequest = await signRequest(url, {\n  service: 'lambda',\n  region: 'eu-west-1',\n  credentials: {\n    accessKeyId: process.env.AWS_ACCESS_KEY_ID!,\n    secretAccessKey: process.env.AWS_SECRET_ACCESS_KEY!,\n    // sessionToken: only for temporary credentials, adds the x-amz-security-token header\n    sessionToken: process.env.AWS_SESSION_TOKEN,\n  },\n});\n```\n\nIn the browser there is no environment to resolve from, so omitting `credentials` throws. Use temporary, scoped credentials from Amazon Cognito or a web federated identity provider via [`@aws-sdk/credential-providers`](https://www.npmjs.com/package/@aws-sdk/credential-providers):\n\n```ts\nimport { fromCognitoIdentityPool } from '@aws-sdk/credential-providers';\n\nconst signedRequest = await signRequest(url, {\n  service: 'execute-api',\n  region: 'eu-west-1',\n  credentials: fromCognitoIdentityPool({\n    identityPoolId: 'eu-west-1:...',\n    clientConfig: { region: 'eu-west-1' },\n  }),\n});\n```\n\n> [!WARNING]\n> Never hardcode AWS credentials in a browser application. Doing so exposes your access key ID and secret access key to anyone who loads the page.\n\n## Advanced\n\n### Sign last\n\n> [!IMPORTANT]\n> The signature covers the method, URL, query string, headers and body. Anything you change after signing invalidates it and the request fails with `403 Forbidden`. In particular, do not add headers or query parameters to the request after calling `signRequest`, and send `signedRequest.url` rather than the URL you started with.\n\n### Browser bundles\n\nThe Node-only credential provider is loaded through a dynamic import, and this package maps it to `false` in its `browser` field, so bundlers leave it out of browser builds entirely. This is why credentials must be explicit in the browser.\n\n## API\n\n### `signRequest(input, options)`\n\n```ts\nfunction signRequest(input: string | Request | URL, options: SignRequestOptions): Promise<Request>;\nfunction signRequest(input: string | Request | URL, init: RequestInit, options: SignRequestOptions): Promise<Request>;\n```\n\nReturns a new `Request` with the SigV4 headers applied. The `host` header is always set from the URL, because SigV4 requires it. Two overloads: pass `options` second when there is no `RequestInit`, third when there is.\n\n```ts\nawait signRequest(url, { service: 'lambda' });\nawait signRequest(url, { method: 'POST', body: '{}' }, { service: 'lambda' });\n```\n\n### `parseRequest(input, init?)`\n\n```ts\nfunction parseRequest(\n  input: string | Request | URL,\n  init?: RequestInit,\n): Promise<{\n  url: URL;\n  method: string;\n  headers: Record<string, string>;\n  body?: ArrayBuffer;\n}>;\n```\n\nNormalizes the `fetch`-style arguments into their parts, with header names lowercased and the body read into an `ArrayBuffer`. Values in `init` override those on a `Request` input. `signRequest` uses this internally; it is exported for callers that need the normalized request without signing it.\n\n```ts\nconst { url, method, headers } = await parseRequest(url, { method: 'POST' });\n```\n\n### `getDefaultCredentialProvider()`\n\n```ts\nfunction getDefaultCredentialProvider(): Promise<AwsCredentialIdentityProvider>;\n```\n\nReturns the default provider from [`@aws-sdk/credential-provider-node`](https://www.npmjs.com/package/@aws-sdk/credential-provider-node), constructed once and reused for the lifetime of the process. Rejects in browser environments, where credentials must be explicit. This is what `signRequest` calls when `credentials` is omitted; you rarely need it directly.\n\n```ts\nconst provider = await getDefaultCredentialProvider();\nconst credentials = await provider();\n```\n\n## Types\n\n### `SignRequestOptions`\n\nThe options object accepted by `signRequest`.\n\n```ts\nimport type { SignRequestOptions } from 'aws-sigv4-sign';\n\ntype SignRequestOptions = {\n  service: string; // required, e.g. 'lambda' or 'execute-api'\n  region?: string; // default: 'us-east-1'\n  credentials?: AwsCredentialIdentity | AwsCredentialIdentityProvider; // default: resolved from the environment in Node.js\n};\n```\n\n## License\n\nMIT\n","readmeFilename":""}