Troubleshooting Amazon S3 (403 Forbidden for HEAD requests)
If an Amazon S3 origin serves GET requests successfully but returns403 Forbidden for HEAD requests, check the permissions and request configuration. The mismatch typically has one of four causes:
- Restricted object-level permissions: The bucket or IAM policy permits public read access, but the object’s Access Control List (ACL) denies access to the IAM user or role — AWS S3 returns 403 for HEAD in this case.
-
Different policies in effect: The IAM identity making the HEAD request lacks
s3:GetObjectAttributesor equivalent metadata-read permissions, causing AWS S3 to return 403 for HEAD while GET succeeds under a broader policy. - Incorrect parameters in presigned URLs: A presigned URL generated with mismatched parameters (access key, secret access key, bucket name, or object key) causes AWS to return 403. The parameters must be consistent for both HEAD and GET requests.
- Different owners for bucket and object: When the bucket and object belong to different AWS accounts and the object owner hasn’t granted the necessary permissions to the bucket owner, AWS returns 403 for HEAD and 200 for GET.