An Amazon S3 connection lets the Amazon S3 steps — Upload a file, Download a file, List objects, Delete an object, Copy an object, Get a presigned URL and Create a bucket — and the New object trigger work with your buckets: on Amazon S3, or on an S3-compatible store such as Cloudflare R2, Wasabi, DigitalOcean Spaces or MinIO.
Who can do this
- Workspace Admins and Editors.
- Plan: Amazon S3 is a premium connection. You can add it and test its steps on any plan; publishing a workflow that uses it needs Starter, Pro or Enterprise.
Before you start
- An access key for Bizomate. In AWS, make an IAM user for Bizomate with only the S3 permissions its workflows need on the buckets they use, then Security credentials › Create access key. Keep the secret — it is shown once. For R2, Wasabi or Spaces, make the store's own access key.
- The region of your buckets — eu-west-1, us-east-1, ap-southeast-1.
- For an S3-compatible store, its endpoint —
https://<account>.r2.cloudflarestorage.com, for example. It must be https and on the public internet.
Steps
- Select Connections in the bar at the top, then + Add connection.
- Under Cloud Storage, select Amazon S3. It reads with the diamond for paid plans.
- In Connection name, type a name — for example Consulace invoices.
- In Access key ID, paste the key; in Secret access key, its secret.
- Region — the buckets' region. Empty is us-east-1, or auto with an endpoint.
- Endpoint — only for an S3-compatible store. Leave it empty for Amazon S3.
- Only this bucket — only for a key allowed one bucket, which cannot list the others.
- Leave Test the connection before saving ticked, then select Save connection.
What happens next
- The connection appears under Cloud Storage; in the step picker its steps are under Developer.
- Test lists your buckets, answering for example "Reached Amazon S3 · 4 buckets" — or, for an S3-compatible store, its host in place of Amazon S3. With Only this bucket, it checks that bucket: "Reached the bucket consulace-invoices · Amazon S3".
Good to know
- Connections made before 3 October 2026 with the old API key form read Needs reconnecting — "Amazon S3 now asks for an access key, secret and region. Reconnect it to use the Amazon S3 steps." Select Reconnect and fill in the new fields.
- Bizomate reaches only the public internet, and uses only the key you give it.
- The secret is never shown again; to change any field, Reconnect and fill them in again.
If something goes wrong
| What you see | Why | What to do |
|---|---|---|
| "Amazon S3 refused the access key or secret. Check them on Connections." | The key or secret is wrong, or was deleted. | Create a new access key and reconnect. |
| "Amazon S3 refused: Access Denied … The key lacks the permission, or the bucket's policy does not allow it." | The key may not list buckets. | Give it s3:ListAllMyBuckets, or fill in Only this bucket. |
| "The endpoint must be an https address — …" | The endpoint is http, or not an address. | Give the store's https endpoint. |
| "Could not reach …: … is not on the public internet …" | The endpoint is a private address. | Use the store's public endpoint. |