aws4fetch is a compact AWS client and signing utility for modern JavaScript environments that support fetch and SubtleCrypto, such as web browsers and Cloudflare Workers. It helps you call AWS services by signing requests (AWS Signature Version 4), with optional retries using exponential backoff and jitter. It exports AwsClient for signed fetch calls and AwsV4Signer for creating signed Requests directly.
Project status
- The GitHub source appears quiet and not actively maintained, with the last upstream push on 2024-12-06 and no evidence of updates since then relative to today (2026-10-02).
- The update cadence looks sporadic, with updates roughly every few months in 2024 (v1.0.18 in 2024-03, v1.0.19 in 2024-07, v1.0.20 in 2024-08), then a longer gap afterward before the last push in 2024-12.
AI summary generated
Recent updates
v1.0.20
v1.0.20 updates hostname parsing in guessServiceRegion to enforce DNS label length limits (63 characters). The only functional code change is tighter regex matching for AWS-related hostnames, plus minor documentation cleanup in the README.
v1.0.19
v1.0.19 adds support for AWS Lambda Function URLs by enhancing request signing logic to recognize Lambda URL hostnames. The release also includes smaller type accuracy updates, a performance improvement to hex encoding, and refreshed example code.
Featuresv1.0.17
Release v1.0.17 adds an .mjs build of aws4fetch to improve Node.js ESM compatibility (referencing issue #42). The distribution and package exports were adjusted so ESM imports resolve to the new .mjs artifact, and Node ESM/CommonJS smoke tests were added.
Featuresv1.0.16
v1.0.16 updates the package metadata to add an explicit Node and bundler entrypoint map via the package.json "exports" field. This is intended to make esbuild compilation and module resolution work correctly without relying on implicit defaults.
Featuresv1.0.15
v1.0.15 extends aws4fetch's automatic service and region guessing to recognize Cloudflare R2 and Backblaze B2 hostname patterns. The release notes broadly describe this, and the code changes confirm the behavior is implemented in guessServiceRegion and covered by new tests.
Featuresv1.0.14
v1.0.14 changes how aws4fetch handles S3 unsigned payload hashing when generating signed URLs, specifically to avoid adding the X-Amz-Content-Sha256 header during S3 query signing. The release notes mention this fix only, but the code diff also includes additional runtime error-handling around Request construction and a TypeScript declaration change.
v1.0.18
v1.0.18 focuses on TypeScript type fixes, specifically improving the type path mappings for each package export. The diff also shows changes to the build configuration and several devDependency version bumps, which are not mentioned in the release notes.
v1.0.13
This release updates aws4fetch to treat the HTTP Connection header as an unsigned header, matching behavior described in AWS SDKs. No API surface changes are indicated in the diff.
v1.0.12
Release v1.0.12 makes a small change to the generated UMD wrapper so it prefers using `globalThis` when available. In addition, the repo’s dev tooling dependencies were updated (as reflected in package.json and package-lock.json), but no other runtime logic changes are evident from the provided diff.
Featuresv1.0.11
v1.0.11 focuses on correcting how S3 request signing derives the encoded path when the path contains plus characters. The release notes state that %2B characters are handled correctly for S3, and the code changes adjust the URL pathname decoding logic accordingly.