Troubleshooting S3
If you encounter issues while using Hippius S3, check this guide for common errors and their solutions.
Authentication errors
If you receive an InvalidAccessKeyId, SignatureDoesNotMatch, or AccessDenied error during initial connection:
- Check key format: your Access Key ID must start with
hip_. - Verify secrets: ensure there are no leading or trailing spaces in your Secret Access Key.
- Token expiry: if you are using a master or sub token, confirm it has not expired in the Hippius Console.
Upload fails
If an upload fails to start or gets interrupted:
- Empty balance: your account balance must cover what you store. Check Billing in the console.
- Invalid bucket name: names must be 3–63 characters, lowercase letters, numbers, and hyphens only, and must not look like an IP address.
- File size: use multipart uploads for files larger than 5 GB. The console itself caps uploads at 100 MB — use a client for anything larger. See Upload large files.
Access denied
If you can connect but cannot read or write objects:
- Sub-token permissions: confirm the token is Object Read Only or Object Read & Write, matching the operation you are trying.
- Account read only or suspended: on pay as you go, an unpaid balance turns S3 read only after 7 days and suspends it after 14. Top up in Billing. See S3 plans and pay as you go.
- Bucket scope: confirm the sub-token was granted access to this specific bucket. See Give an app scoped credentials.
Slow uploads
If transfer speeds are lower than expected:
- Multipart uploads: for large files, make sure the client is using multipart. SDKs usually do this automatically; some tools need it turned on.
- Parallel transfers: increase concurrent connections. In rclone, use
--transfers 8and--s3-upload-concurrency 8.
For rclone, combining --transfers 8 --s3-upload-concurrency 8 --progress gives you fast parallel uploads with real-time feedback.
Endpoint errors
If your client talks to the default S3 endpoint instead of Hippius, or reports a DNS error:
- Missing endpoint URL: set the endpoint to
https://s3.hippius.com. In the AWS CLI that is the--endpoint-urlflag. - Wrong region: set the region to
decentralized. - Addressing style: use path-style addressing (
forcePathStyle: trueor equivalent). Virtual-hosted style is not supported.
Connection details are in the S3 Quickstart.
Deleting a bucket and all its contents
To remove a bucket along with everything inside it, use the --force flag. It empties the bucket first, then deletes it:
aws s3 rb s3://my-bucket --force \
--endpoint-url https://s3.hippius.com
A bucket with Object Lock keeps its locked versions: see Object Lock.
Getting help
Still stuck?
- Join the discussion on our Discord server.
- See Help & Support for more resources.