An Amazon S3 connection lets the Amazon S3 steps — Upload a file, Download a file, List objects, Delete an object, Copy an object, Get a presigned URL and Create a bucket — and the New object trigger work with your buckets: on Amazon S3, or on an S3-compatible store such as Cloudflare R2, Wasabi, DigitalOcean Spaces or MinIO.

Who can do this

  • Workspace Admins and Editors.
  • Plan: Amazon S3 is a premium connection. You can add it and test its steps on any plan; publishing a workflow that uses it needs Starter, Pro or Enterprise.

Before you start

  • An access key for Bizomate. In AWS, make an IAM user for Bizomate with only the S3 permissions its workflows need on the buckets they use, then Security credentials › Create access key. Keep the secret — it is shown once. For R2, Wasabi or Spaces, make the store's own access key.
  • The region of your buckets — eu-west-1, us-east-1, ap-southeast-1.
  • For an S3-compatible store, its endpoint — https://<account>.r2.cloudflarestorage.com, for example. It must be https and on the public internet.

Steps

  1. Select Connections in the bar at the top, then + Add connection.
  2. Under Cloud Storage, select Amazon S3. It reads with the diamond for paid plans.
  3. In Connection name, type a name — for example Consulace invoices.
  4. In Access key ID, paste the key; in Secret access key, its secret.
  5. Region — the buckets' region. Empty is us-east-1, or auto with an endpoint.
  6. Endpoint — only for an S3-compatible store. Leave it empty for Amazon S3.
  7. Only this bucket — only for a key allowed one bucket, which cannot list the others.
  8. Leave Test the connection before saving ticked, then select Save connection.

What happens next

  • The connection appears under Cloud Storage; in the step picker its steps are under Developer.
  • Test lists your buckets, answering for example "Reached Amazon S3 · 4 buckets" — or, for an S3-compatible store, its host in place of Amazon S3. With Only this bucket, it checks that bucket: "Reached the bucket consulace-invoices · Amazon S3".

Good to know

  • Connections made before 3 October 2026 with the old API key form read Needs reconnecting — "Amazon S3 now asks for an access key, secret and region. Reconnect it to use the Amazon S3 steps." Select Reconnect and fill in the new fields.
  • Bizomate reaches only the public internet, and uses only the key you give it.
  • The secret is never shown again; to change any field, Reconnect and fill them in again.

If something goes wrong

What you see Why What to do
"Amazon S3 refused the access key or secret. Check them on Connections." The key or secret is wrong, or was deleted. Create a new access key and reconnect.
"Amazon S3 refused: Access Denied … The key lacks the permission, or the bucket's policy does not allow it." The key may not list buckets. Give it s3:ListAllMyBuckets, or fill in Only this bucket.
"The endpoint must be an https address — …" The endpoint is http, or not an address. Give the store's https endpoint.
"Could not reach …: … is not on the public internet …" The endpoint is a private address. Use the store's public endpoint.