Reg-suit’s S3 “Access Denied” error is not, by itself, proof of an India-specific problem. Find the failed S3 operation, verify the AWS identity used by the CI job, and check the permissions and controls that apply to that request. The right change depends on whether Reg-suit was reading snapshots, uploading results, listing objects, or performing another operation.
What Reg-suit needs S3 to do
Reg-suit is a CLI for visual regression testing. Its S3 publisher plugin reads earlier snapshot images for comparison and publishes current images and comparison reports to a configured bucket. The plugin documents bucketName as required and supports optional AWS SDK client settings through sdkOptions. See the Reg-suit S3 publisher documentation and the Reg-suit project README.
The plugin lists these S3 actions as permissions it may need. Treat them as a starting point, not a reason to grant every action to every workflow: match access to the operation and plugin version actually in use.
s3:GetObjectands3:GetObjectAclfor object reads and ACL access.s3:PutObjectands3:PutObjectAclfor uploads and ACL access.s3:DeleteObjectfor object deletion.s3:ListBucketfor bucket listing.
Fix the denial in a safe order
- Identify the failed operation. Read the full CI log and determine whether the failure occurred while fetching expected snapshots, publishing or uploading current results, deleting objects, or listing keys. Preserve the AWS error text and request context. The operation points to the relevant action and resource scope.
- Verify the CI job’s effective identity. Check which AWS credentials the process actually receives and whether environment variables referenced in
regconfig.jsonare populated as intended. Reg-suit supports environment-value substitution in plugin configuration; a local developer’s successful credentials do not prove that CI is using the same principal. AWS evaluates the permissions of the principal making the request. See AWS guidance for troubleshooting S3 403 errors. - Match the permission to the resource ARN. Check for an applicable Allow for the failed action and confirm its resource matches the request. Bucket-level actions such as
s3:ListBucketapply to the bucket ARN; object actions such ass3:GetObjectands3:PutObjectapply to object ARNs. An Allow for the wrong resource does not grant the requested access. Use the plugin’s documented action list as a guide, then scope grants to the bucket and object paths the workflow needs. - Inspect every applicable policy layer. Review the principal’s identity policies and, where relevant, the bucket policy—especially for cross-account access. Also look for explicit Deny statements, permissions boundaries, session policies, and AWS Organizations policies. An applicable explicit Deny blocks access; session policies can further restrict a role session. AWS explains these policy interactions in its IAM policies documentation.
- Check encryption and S3 controls relevant to the request. If the bucket uses SSE-KMS, verify that the caller is authorized for the KMS key operation as well as the S3 operation. Depending on the setup, review Object Lock, VPC endpoint policies, access-point configuration, and Organizations controls. These are not universal causes; investigate them when the operation and bucket configuration make them applicable. AWS’s S3 403 troubleshooting guide covers these diagnostic areas.
- Confirm the actual bucket and client regions. Verify the bucket’s region and the S3 client settings used by Reg-suit, including any
sdkOptionsconfiguration. Region is worth checking, but the available Reg-suit and AWS documentation does not establish India as a distinct cause of this error. - Retest the same workflow. After making a narrowly scoped change, rerun the job and confirm that the denied read, write, listing, or other operation now succeeds. If it still fails, retain the request ID and recheck the remaining policies and controls. AWS recommends contacting Support if its S3 403 troubleshooting does not resolve the issue.
How to distinguish the likely causes
| What to inspect | Clue | Next check |
|---|---|---|
| Denied action | The error occurs during a particular read, upload, delete, or list step. | Match that operation to the plugin’s S3 action list and installed behavior. |
| Resource scope | The action appears allowed, but the request is still denied. | Check whether the policy targets the bucket ARN for listing or the relevant object ARN for object access. |
| Runtime credentials | Local execution works but CI fails, or the CI role is unexpected. | Verify the identity and configuration values available to the actual job process. |
| Cross-account access | The caller and bucket belong to different accounts. | Review both the caller’s permissions and the bucket policy for the required access. |
| Restrictive policy | An Allow exists but access remains denied. | Check explicit Deny statements, boundaries, session policies, and Organizations policies. |
| Encryption or network controls | The bucket uses KMS, an endpoint, or an access point. | Check the relevant KMS permissions and S3 control policies for the request path. |
| Region configuration | The client’s configured region may not match the bucket’s region. | Confirm both values; do not assume the user’s location determines the cause. |
Do not make the bucket public
Making the bucket public is not a safe shortcut for a CI permission error. AWS states, “By default, all Amazon S3 resources are private.” Prefer an explicit, narrowly scoped permission for the workflow identity and resource it needs. See AWS S3 access-control documentation.
#1 Best Overall
Or skip the browser setup
If the underlying need is to capture website screenshots rather than run Reg-suit’s S3 publisher, ScreenshotNeo offers a screenshot API and MCP server. A one-call request returns an image or PDF; it does not fix Reg-suit’s AWS permissions or publish files to your bucket. The API accepts parameters used by other screenshot APIs, which can make switching easier.
Quick Recap
Best Value
Rank #3
Rank #2
For example, using cURL:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
See the ScreenshotNeo API documentation for request options. Cookie banners, popups, and chat widgets are removed before the shot; bot checks, blank pages, and failed loads are never billed. Its MCP server lets AI agents take screenshots. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. Sign up for free.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

