INSERTCART AWS WEB · HOSTING GUIDE

Fix S3 and CloudFront 403 Access Denied errors

Diagnose object paths, CloudFront origins, and private-bucket access without making your S3 bucket public.

By InsertCart · Updated 7 October 2026

Identify the URL that fails

First check whether the error comes from the public CloudFront URL or a direct S3 URL. The new deployment service blocks public S3 access by design. A direct S3 URL returning Access Denied can be expected while the CloudFront website works correctly. Use the website URL shown in Manage websites.

Check that index.html exists in the active release

In your AWS S3 console, open the website bucket and inspect releases/<release-id>/index.html. The release ID should match the current release in the dashboard and the origin path in CloudFront. An upload containing only an extra folder level or a file named Index.html can miss the requested object. The new uploader validates the entry point before publishing.

Check the CloudFront origin

The private-bucket setup uses the S3 REST origin, an origin access control, and a bucket policy allowing that specific distribution to read objects. An S3 static website endpoint is a different origin type and does not use this private-bucket OAC configuration. Inspect the distribution’s Origins tab and compare it with the bucket policy rather than combining two hosting patterns.

Check the bucket policy and AWS account

The bucket policy’s distribution ARN must match your distribution and AWS account. It should grant CloudFront object reads. If you changed the origin, bucket, or distribution manually, the generated policy may no longer match. Keep Block Public Access enabled for the new OAC setup; making the bucket public is unnecessary for this architecture.

An organization service control policy, permissions boundary, explicit deny, or manually configured encryption key can also prevent access. The generated website uses S3’s default encryption. If you switch to a customer-managed encryption key, evaluate its permissions separately.

Check nested URLs and cached errors

CloudFront’s default root object applies at the distribution root. A link to /about/ does not automatically become /about/index.html with a REST S3 origin. Use explicit file URLs such as /about/index.html, or configure a viewer-request rewrite in AWS for your routing needs. A single-page app may need a deliberate fallback strategy; avoid returning the homepage for every missing image or crawler file.

After fixing the cause, wait for CloudFront propagation and invalidate the affected paths if an old error remains cached. A cache invalidation cannot fix a wrong bucket policy or a missing file. Read the update guide for the deployment process.

For the underlying private origin configuration, see AWS’s origin access documentation.

Ready to publish?

Bring your static website files and connect your own AWS account.

Open the launch workspace ↗

Browse hosting guides · Connection security · Understand costs