---
title: "How to share S3 files with customers (without IAM)"
seoTitle: "Share S3 Files with Customers and Clients, No IAM"
image: "/blog-images/share-customers-quicks3.jpg"
description: "Send a customer one file, collect files from a client, or give them their own folder in your S3, R2, or B2 bucket. No IAM users, access keys, or public buckets."
publishDate: 2026-09-28
tags: ["Sharing", "Access Control", "Guides", "S3-Compatible"]
draft: false
---

Your files live in a bucket, and your customers need some of them. A monthly report. The final cut of a video. A folder of product photos they have to send you. None of them has an AWS account, and none of them should.

Ask how to do this on Stack Overflow and the answers are always the same: don't create IAM users for outsiders, don't make the bucket public, generate presigned URLs from your own app. That last one is good advice if you have an app and a developer with time to build the pages around it. quickS3 is that app, already built. It connects to the bucket you have and gives you three ways to share with customers, from a single file to a private folder they come back to every week.

## Pick the right way to share

| What you need | Use | Does the customer need an account? |
|---|---|---|
| Send one file | A share link | No |
| Get files from a customer | A file request | No |
| Give a customer their own folder to browse, download, and upload | An invite with a role | Yes, their email address is enough |

All three keep your bucket private and your storage keys on quickS3's servers. Files go straight between the customer's browser and your storage provider, and every download and upload lands in your audit log.

## Send one file with a share link

1. Open the file in quickS3 and click the share icon in its row.
2. Pick how long the link should work: 1 hour, 6 hours, 24 hours, 7 days, or 30 days.
3. Click **Create link**, copy it, and send it to your customer.

![The quickS3 "Share file" dialog for a PDF, with link expiration options from 1 hour to 30 days](/blog-images/share-bucket/4-share-file.png)

Your customer opens a short `quicks3.com/shrt/…` link and downloads the file. They don't sign in, and they can't see anything else in the bucket. Each download shows up in your audit log as **Download via share link**.

The link has no password, so anyone it's forwarded to can use it too. Pick the shortest time that works, and keep contracts and anything confidential for a customer folder instead. If a link goes to the wrong person, open **Shared links** in the sidebar and revoke it. It stops working at once.

## Collect files with a file request

Sometimes the files go the other way: a supplier sends invoices, a customer sends photos, a partner sends their raw footage. A file request is an upload link into one folder.

1. Open the folder that should receive the files and click **Request files** in the toolbar.
2. Choose how long the link works. 7 days is selected to start with.
3. Set the limits: the largest file, the total size, and the number of files.
4. Add a note if it helps, like "Please send the signed PDFs and your logo".
5. Click **Create link**, copy it, and send it.

![The quickS3 "Request files" dialog with a 7-day link, 1 GB largest file, 5 GB total, and a 100-file limit](/docs/screenshots/v1.6.0/request-files-dialog-light.png)

![The upload link quickS3 creates, with a Copy button and a reminder that it can be revoked from the Shared links page](/docs/screenshots/v1.6.0/request-files-link-light.png)

Your customer gets a simple page with your note, the limits, and the expiry date. They drag their files in and watch each one upload. They can't see the folder, your other files, or anything other people sent.

![The quickS3 "Send files" page a customer sees, with one file sent and a second finishing its upload](/docs/screenshots/v1.6.0/file-request-upload-page-light.png)

Each visit gets its own dated subfolder, like `incoming/2026-09-28-k3v9x2ab/`, so two uploads never mix and no file overwrites another. The limits stop one link from filling your storage, and the link closes on its own when it expires or reaches them.

![The quickS3 Shared links page, listing a file request with 2 of 100 files received and two download links, each with Copy and Revoke buttons](/docs/screenshots/v1.6.0/shared-links-page-light.png)

## Give a customer their own folder

For a customer you work with every week, links get tiring for both of you. Give them a folder instead. They sign in, see their files, download what they need, and upload if you let them.

### Set up the folder once

A simple layout works for most teams: one folder per customer.

```
customers/
  acme/
  globex/
  initech/
```

If your files are already organised another way, keep it. A role can point at any folder, on any bucket you've connected.

### Create a role for the customer

1. Open **Roles** and click **Create role**.
2. Pick **Start empty**, so the role grants nothing you don't add.
3. Name it after the customer, like "Customer: Acme".
4. Add a rule: **Allow**, your connection and bucket, and the prefix `customers/acme`.
5. Tick **Read** so they can browse and download. Tick **Write** too if they should upload.
6. Click **Save role**.

Don't give customers **Delete** or **Share** unless you have a reason. Without Delete, nothing they do can remove your files. Without Share, they can't create public links to them.

If there's a subfolder the customer shouldn't open, like `customers/acme/internal/`, add a **Deny** rule for it. A deny always wins, whatever other roles the person has.

### Invite them

1. Open **People** and click **Invite**.
2. Enter your customer's email and tick their role.
3. Click **Send invite**.

![The quickS3 invite dialog with an email address entered and a role ticked](/blog-images/share-bucket/3-invite.png)

They sign in with a magic link or their Google account. There's no password to set up, no S3 client to install, and no AWS console. They see the folders you allowed and nothing else.

When the project ends, remove them from **People**. Their access stops on their next click. There's no key to rotate and nothing to hunt down.

For more detail on roles and rules, see [how to give someone access to your S3 bucket](/blog/give-someone-access-to-your-s3-bucket/).

## What your customers never see

- **Your storage keys.** They're encrypted on quickS3's servers and never sent to any browser, not even yours.
- **Your provider.** Customers don't need an account on AWS, Cloudflare, Backblaze, or anyone else, and they never see a console.
- **Other customers.** Each person only sees the folders their role allows. Acme can't list or open Globex's folder.
- **Your other files.** Share links cover one file. File requests only accept uploads.

And you see everything they do: each download, upload, and denied request is in the audit log, under the customer's email (or under yours, for links you created), for 14 days.

## Why not the usual ways?

**An IAM user or access key per customer.** It works, but the customer needs an S3 client before they see a single file, and the key lives on in their password manager long after the project ends. On AWS, limiting a key to one folder means writing a JSON policy for every customer.

**Presigned URLs.** Good for one file, and quickS3 uses them under the hood for every transfer. On their own, though, someone has to generate each link, AWS caps them at 7 days, and there's no page for the customer to browse a folder or upload into.

**A public bucket.** Everyone can read everything, which is why AWS blocks public access on new buckets by default.

**Copying files to Google Drive or WeTransfer.** Now the files live in two places, the copy goes stale, and you're paying for storage twice. With quickS3 the bucket stays the one source of truth.

## FAQ

### Do my customers need an AWS, Cloudflare, or Backblaze account?

No. For share links and file requests they need nothing at all. For their own folder, they need an email address to sign in to quickS3.

### Do customers count as users on my plan?

Customers you invite to a folder count as users, like teammates. People who only open a share link or upload through a file request don't count.

### Can a customer upload large files?

Yes. Uploads go straight from their browser to your storage, not through quickS3. With a file request, you set the largest file and the total size allowed.

### Can one customer see another customer's files?

No. Each customer's role allows only their folder. They can't list or open anything outside it.

### Does this work with R2, B2, Wasabi, and DigitalOcean Spaces?

Yes. quickS3 works with AWS S3, Cloudflare R2, Backblaze B2, Wasabi, DigitalOcean Spaces, Azure Blob Storage, MinIO, and other S3-compatible storage. Customers see the same page whichever one you use.

### My customer's upload fails with a network error. What's wrong?

Your bucket probably blocks uploads from browsers. Add a CORS rule on the bucket; the [CORS guide](/docs/files/cors/) has one to copy for each provider.

---

quickS3 turns the bucket you already have into a place your customers can use: a link for one file, a drop box for theirs, and a private folder for ongoing work. Your keys stay put, your files stay in your bucket, and you can see and undo every bit of access.

The Team plan is $19 per month for 10 users, then $2 per user, with a 14-day free trial and no credit card needed. [Sign up](/app/), connect a bucket, and send your first share link.
