AccessControlListNotSupported: The bucket does not allow ACLs
The upload sets an ACL (like public-read), but the bucket uses “Bucket owner enforced” Object Ownership, which disables ACLs.
Seen on:
AWS
Meaning
Since April 2023 new buckets disable ACLs by default. Tools and plugins that send x-amz-acl: public-read (old WordPress offload plugins, s3 sync --acl, older SDK examples) fail. Use a bucket policy (or CloudFront) for public access instead.
Common causes
- Code/plugin sends ACL headers (public-read, bucket-owner-full-control)
- Bucket created with ACLs disabled (default)
- CLI uses --acl
⚡ Quick fix
- Remove the ACL parameter from uploads
- Grant public read via bucket policy (and disable Block Public Access deliberately) or serve through CloudFront
- Re-enable ACLs only if a legacy tool truly needs them
Detailed fix by platform
AWS CLI
- bash
aws s3 cp file.png s3://my-bucket/ # no --acl aws s3api get-bucket-ownership-controls --bucket my-bucket
How to diagnose
- Ownership — ObjectOwnership value
- Client — Which ACL header is sent?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in AWS
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026