
Cross-cloud S3-compatible object storage CLI to list, export, and download buckets across AWS, Aliyun, Tencent, Huawei and more, with anonymous browsing and bucket discovery scanning.
中文 | English
A cross-cloud object storage CLI based on the S3 protocol. One binary for all major providers: AWS S3, Aliyun OSS, Tencent COS, Huawei OBS, Baidu BOS, Kingsoft KS3, UCloud US3, JD Cloud OSS, Google Cloud Storage, Cloudflare R2, Scaleway, Wasabi, DigitalOcean Spaces, Yandex, Exoscale, Arvan Cloud, Backblaze B2, MinIO and any other S3-compatible service.
https://... URLs; provider domains are recognized and
bucket/region parsed automatically. URL query parameters (prefix, delimiter, max-keys,
continuation-token, marker, start-after) act as listing filters, similar to
aws-s3-bucket-browserhttps://files.example.com/mybucket/) are handled automatically via path-style parsing?token=abc auth gateways)
are injected into every API request (list/download/upload/presign) before SigV4 signing-d-style full-scan cases)txt / csv / xlsx / yaml / markdown (--export)cp -r downloads everything matching
--include/--exclude/--prefix, preserving the key directory structurefind probes (batch: multiple args / stdin) which cloud
storage hosts a bucket, accepting bucket names and full bucket URLs; anonymous probes
also detect whether anonymous directory listing is allowed, highlighting anonymously
listable buckets in bright green, with --export to txt/csv/xlsx/yaml/md including a
dedicated listable_url fieldoss serve offers a REST API + OpenAPI 3 document + MCP tool
endpoint on one port; oss mcp stdio|http|sse exposes ls/stat/cat/presign/find as MCP tools
for clients like Claude--color auto|always|never)OSS_LANG=zh|en).part writes-x proxy, -H custom headers (UA / Cookie …), -k skip TLS verificationOption 1: Homebrew (macOS / Linux, recommended)
brew install ejfkdev/tap/oss
Option 2: go install (requires Go 1.24+)
go install github.com/ejfkdev/oss@latest
Option 3: prebuilt binaries
Download the archive for your platform from GitHub Releases
(linux/darwin/windows × amd64/arm64) and extract. Release binaries are stripped;
Linux/Windows builds are UPX-compressed (macOS builds are not: UPX-packed Mach-O binaries are
killed by the kernel). Every release ships with a SHA256 checksum file.
Option 4: build from source (requires Go 1.24+):
git clone https://github.com/ejfkdev/oss && cd oss
make build # produces ./oss
make install # installs into $GOPATH/bin
make release # cross-compiles all platforms into dist/
# Browse a public bucket anonymously (no credentials)
oss ls https://noaa-nwm-pds.s3.amazonaws.com/?delimiter=/
oss ls "https://noaa-nwm-pds.s3.amazonaws.com/?prefix=nwm.20250101/&delimiter=/&max-keys=20"
oss cp -r https://noaa-nwm-pds.s3.amazonaws.com/nwm.20250101/ ./nwm/ --jobs 32
# Aliyun OSS
oss ls oss://mybucket/logs/ --ak <AK> --sk <SK> --region cn-hangzhou
export OSS_ACCESS_KEY_ID=xxx OSS_SECRET_ACCESS_KEY=yyy # or use env vars
oss ls mybucket --provider aliyun # bare bucket name
# Tencent COS / Huawei OBS
oss ls s3://bucket-1250000000 --provider tencent --region ap-guangzhou
oss ls https://bucket.obs.cn-north-4.myhuaweicloud.com/prefix/
# Yandex / Exoscale / Arvan
oss ls s3://mybucket --provider yandex
oss ls s3://mybucket --provider exoscale --region ch-gva-2
# MinIO / self-hosted S3
oss ls s3://mybucket -e http://127.0.0.1:9000 --ak minioadmin --sk minioadmin
oss ls http://127.0.0.1:9000/mybucket/prefix/ # IP/port auto-detected as path-style
# Proxy, custom UA / Cookie
oss ls s3://mybucket -x http://127.0.0.1:7890 \
-H "User-Agent: my-agent/1.0" -H "Cookie: session=abc"
# Path-forwarded bucket (reverse proxy mounting a bucket under a path)
oss ls "https://files.example.com/mybucket/?prefix=2026/&max-keys=10"
oss cp "https://files.example.com/mybucket/<key>" ./
# Access with extra parameters (token etc. is attached to every request)
oss ls "http://gateway.example.com/bucket?token=abc"
oss cp "http://gateway.example.com/bucket/file.bin?token=abc" ./
| Form | Example |
|---|---|
| scheme | s3://bucket/prefix, oss://, cos://, obs:// |
| bare bucket | mybucket/prefix (with --provider / -e) |
| HTTP URL | https://bucket.s3.us-east-1.amazonaws.com/prefix?prefix=logs/ |
Provider domains recognized automatically (endpoint / region / bucket are parsed):
| Provider | Domain example |
|---|---|
| AWS | bucket.s3.region.amazonaws.com, s3.region.amazonaws.com/bucket |
| Aliyun | bucket.oss-cn-hangzhou.aliyuncs.com (incl. accelerate) |
| Tencent | bucket-appid.cos.ap-guangzhou.myqcloud.com |
| Huawei | bucket.obs.cn-north-4.myhuaweicloud.com |
| Baidu BOS | bucket.s3.bj.bcebos.com, s3.bj.bcebos.com/bucket |
| Kingsoft KS3 | bucket.ks3-cn-beijing.ksyuncs.com |
| UCloud US3 | bucket.s3-cn-sh2.ufileos.com |
| JD Cloud OSS | s3.cn-north-1.jdcloud-oss.com/bucket (path-style) |
| CTYun OOS | bucket.oos-cn.ctyunapi.cn (incl. resource-pool & Hong Kong endpoints) |
| CUCloud OSS | bucket.obs-helf.cucloud.cn (industry-cloud regions) |
| China Mobile EOS | bucket.eos-wuxi-1.cmecloud.cn (30 regions) |
| QingCloud QStor | bucket.s3.pek3a.qsstor.com (S3-compatible domain qsstor.com) |
| Scaleway | bucket.s3.fr-par.scw.cloud (fr-par/nl-ams/pl-waw) |
| Wasabi | bucket.s3.us-east-1.wasabisys.com (14 regions) |
| DigitalOcean Spaces | nyc3.digitaloceanspaces.com/bucket (9 regions) |
| Yandex | bucket.storage.yandexcloud.net |
| Exoscale SOS | bucket.ch-gva-2.sos.exoscale.com (6 regions) |
| Arvan Cloud | bucket.s3.ir-thr-at1.arvanstorage.ir |
| Cloudflare R2 | bucket.<account_id>.r2.cloudflarestorage.com |
| GCS | storage.googleapis.com/bucket (HMAC keys) |
Any other host (MinIO, Ceph, path-forwarded buckets, CNAME…) is parsed as path-style:
the first path segment is the bucket, the rest is the key, e.g.
https://files.example.com/mybucket/sub/key.jpg → bucket mybucket, key sub/key.jpg.
If the host points directly at a bucket (CNAME), use --bucket NAME explicitly.
With no target at all, oss ls lists all buckets.
URL query parameters fall into two categories: