aws-s3-access-grants-boto3-plugin
AWS S3 Access Grants plugin provides the functionality to enable S3 customers to configure S3 Access Grants as a permission layer on top of the S3 Clients.
Decision gist · record as of 2026-08-14
Yes, if you are already using S3 Access Grants in your AWS environment and need boto3 integration. The plugin is low-friction to install and is maintained by AWS. However, the 385-day gap since the last release and unclear license metadata warrant verification before production deployment. Not necessary if you manage S3 permissions through IAM alone.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.9 or later; botocore must be installed and configured with valid AWS credentials.
- Low install friction with only two runtime dependencies (botocore and cacheout).
- The package is aging—last release was 385 days ago—but the repository remains active and not archived, suggesting ongoing maintenance by AWS.
License · maintenance · safety
(unclear) — License treatment is unclear; the description states Apache-2.0 but the metadata fields are null. Verify the actual license terms before use in proprietary or restricted contexts.
last release 2025-07-25 (385 days) · last repo commit 2025-07-25 · 7 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 81,372 downloads/mo, #14,232 on PyPI
Alternatives
Verify before relying
pip install aws-s3-access-grants-boto3-plugin
import botocore.session
from aws_s3_access_grants_boto3_plugin.s3_access_grants_plugin import S3AccessGrantsPlugin
session = botocore.session.get_session()
s3_client = session.create_client('s3')
plugin = S3AccessGrantsPlugin(s3_client, fallback_enabled=True, customer_session=session)
plugin.register()- Whether the Apache-2.0 license claim in the description is authoritative given null metadata fields.
- Current compatibility with the latest botocore versions and any breaking changes since the last release 385 days ago.
- Whether the fallback behavior and copy_object/delete_objects workarounds remain reliable in production S3 environments.
What it is and what it does
This is an official AWS plugin for boto3 that layers S3 Access Grants—a fine-grained permission system—on top of your S3 client. Instead of relying solely on IAM credentials, it allows you to configure and enforce granular access policies directly through S3 Access Grants, which the plugin retrieves and applies transparently when you make S3 API calls.
The plugin registers with your boto3 S3 client and intercepts requests to fetch temporary credentials from Access Grants. It supports a fallback mode that reverts to your original credentials if Access Grants cannot provide them (either because the operation is unsupported or for other reasons). It also handles special cases like copy_object and delete_objects by finding the common ancestor of object keys and using grants on that prefix.
Use it for
- Enforce fine-grained S3 bucket access policies across teams without managing separate IAM roles for each permission level.
- Implement time-limited or scope-limited access to S3 data by configuring Access Grants grants and letting the plugin handle credential retrieval.
- Migrate existing S3 applications to use Access Grants without rewriting authentication logic—register the plugin and let it intercept calls.
- Provide temporary, delegated access to S3 buckets for third-party integrations or cross-account scenarios via Access Grants credentials.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are already using S3 Access Grants in your AWS environment and need boto3 integration.
The plugin is low-friction to install and is maintained by AWS. However, the 385-day gap since the last release and unclear license metadata warrant verification before production deployment. Not necessary if you manage S3 permissions through IAM alone.
Install
aws-s3-access-grants-boto3-plugin on PyPI
Before you install
Low install friction with only two runtime dependencies (botocore and cacheout). The package is aging—last release was 385 days ago—but the repository remains active and not archived, suggesting ongoing maintenance by AWS.
Requires Python 3.9 or later; botocore must be installed and configured with valid AWS credentials.
License in practice
License treatment is unclear; the description states Apache-2.0 but the metadata fields are null. Verify the actual license terms before use in proprietary or restricted contexts.
Quickstart
pip install aws-s3-access-grants-boto3-plugin
import botocore.session
from aws_s3_access_grants_boto3_plugin.s3_access_grants_plugin import S3AccessGrantsPlugin
session = botocore.session.get_session()
s3_client = session.create_client('s3')
plugin = S3AccessGrantsPlugin(s3_client, fallback_enabled=True, customer_session=session)
plugin.register()
Verify before relying
- Whether the Apache-2.0 license claim in the description is authoritative given null metadata fields.
- Current compatibility with the latest botocore versions and any breaking changes since the last release 385 days ago.
- Whether the fallback behavior and copy_object/delete_objects workarounds remain reliable in production S3 environments.
Package facts
| License | Not declared unclear |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagesbotocorecacheout |
| Maintenance | Aging 385 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 81,372 / month, #14,232 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Operating System :: OS IndependentProgramming Language :: Python :: 3 |
Evidence: aws_s3_access_grants_boto3_plugin-1.3.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “S3 access grants boto3”
- aws-s3-access-grants-boto3-pluginA boto3 plugin that integrates AWS S3 Access Grants as a permission…
- s3pathS3Path provides a pathlib-like interface for working with AWS S3…
- aws-cdk.aws-s3Defines AWS S3 buckets and related resources as code using the AWS…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also boto3 · openfga-sdk · botocore · boto · s3transfer · amazon-sns-extended-client · s3path · aiobotocore · boto_session_manager · tentaclio-s3