---
"@context": https://schema.org
"@type": TechArticle
"@id": https://www.twilio.com/docs/segment/connections/destinations/catalog/actions-s3#article
headline: AWS S3 (Actions) Destination
description: Store Segment event data as formatted CSV or TXT objects in an Amazon S3 bucket with configurable folder structure, column mappings, and batching.
url: https://www.twilio.com/docs/segment/connections/destinations/catalog/actions-s3
inLanguage: en
dateModified: 2026-10-07T14:22:42.000Z
author:
  "@type": Organization
  name: Twilio Developer Education Team
publisher:
  "@type": Organization
  name: Twilio
---

# AWS S3 (Actions) Destination

The AWS S3 (Actions) destination allows you to store event data as objects in a secure, scalable cloud storage solution. Each event is written to your S3 bucket, organized into a customizable folder structure such as by event type or timestamp. This makes it easy to manage, archive, and analyze data using downstream tools or AWS services.

## Benefits of AWS S3 (Actions) vs AWS S3 Classic

The traditional AWS S3 Classic destination enabled the storage of raw logs containing data Segment received, directly into your S3 bucket. While this provided a straightforward data storage solution, users often needed to implement additional processing to standardize or transform these logs (in JSON format) for downstream analytics or integrations.

The AWS S3 (Actions) destination enhances this capability with configurable options to format and structure event data prior to storage. This approach offers several key benefits:

* **Standardized Data Formatting**. AWS S3 (Actions) lets you define consistent output formats for your data, either CSV or TXT file formats, in a folder definition that you choose. The previous AWS S3 Classic Destination only allowed raw JSON payloads stored within a specific folder called `"segment-logs"`.
* **Configurable Data Translation**. AWS S3 (Actions) supports translation rules that can map raw event attributes to more meaningful or actionable representations. You can configure these rules to meet specific data schema requirements by either adding in custom columns or using the default ones.
* **Enhanced Delivery Controls**. The destination provides advanced options for batch size controls and file naming conventions. These controls can help optimize efficiency and simplify data retrieval workflows.

## Supported Integrations

The AWS S3 (Actions) Destination supports the following Segment features as supported native Destination integration points:

* [Reverse ETL](/docs/segment/connections/reverse-etl/)
* [Classic and Linked Audiences](/docs/segment/engage/audiences/)
* [Connections](/docs/segment/connections/)

## Getting started

To configure the AWS S3 (Actions) destination and deploy standardized event data to your Amazon S3 bucket, follow these steps:

### Prerequisites

Ensure you have the following in place before configuring the AWS S3 (Actions) destination:

* Amazon S3 Bucket: Create a bucket in your AWS account or use an existing one where you want to store the event data.
* AWS IAM Permissions: Verify that you have appropriate IAM roles with write access to the S3 bucket and permissions for the Segment connection.
* IAM Access IDs: Prepare your AWS IAM ARN ID and IAM External ID. These will be needed to authenticate and authorize Segment with your S3 bucket.

### Step 1: Create an IAM role in the AWS console

To set up the IAM role to properly authorize Segment with the AWS S3 (Actions) destination:

1. Log in to your AWS account.
2. Create a new or use an existing bucket with `PutObject`, `GetObject`, `ListObject` access to the S3 bucket.
3. Navigate to **IAM > Roles > Create Role**.
4. Provide the following policy permissions for the IAM that was just created:

```json
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "PutObjectsInBucket",
            "Effect": "Allow",
            "Action": [
                "s3:PutObject",
                "s3:PutObjectAcl"
            ],
            "Resource": "arn:aws:s3:::<YOUR_BUCKET_NAME>/*"
        }
    ]
}
```

5. Click on the Trust Relationships tab and edit the trust policy to allow the IAM user to assume the role. If a user is not already created, refer to the AWS documentation to create a user.

```json
{
   "Version": "2012-10-17",
   "Statement": [
     {
       "Sid": "",
       "Effect": "Allow",
       "Principal": {
         "AWS":                      
            "arn:aws:iam::595280932656:role/customer-s3-prod-action-destination-access"
       },
       "Action": "sts:AssumeRole",
       "Condition": {
         "StringEquals": {
           "sts:ExternalId": "<YOUR_EXTERNAL_ID>"
         }
       }
     }
   ]
 }
```

### Step 2: Add the AWS S3 (Actions) Destination in Segment

To finish the setup, enable the AWS S3 (Actions) Destination in your workspace:

1. Add the **AWS S3 (Actions)** destination from the Destinations tab of the catalog.
2. Select the data source you want to connect to the destination.
3. Provide a unique name for the destination.
4. Complete the destination settings:
   * Enter the name of the region in which the bucket you created above resides.
   * Enter the name of the bucket you created above. Be sure to enter the bucket's **name** and not URI.
   * Enter the ARN of the IAM role you created above. The ARN should follow the format `arn:aws:iam::ACCOUNT_ID:role/ROLE_NAME.`
   * Enter the IAM External ID, which is a value set in the Trust Relationship under your AWS IAM Role.
5. Enable the destination.

### Step 3: Configure the AWS S3 (Actions) Destination mappings

To finish the configuration, add mappings to your new AWS S3 (Actions) Destination:

1. Add a new **Sync to S3** Action into the destination.
2. Define the Event Trigger. If multiple types are accepted in the Event Trigger, the generated files will automatically be split by type in S3 (for example, you might have a Track events file and an Identify events file).
3. Configure the Column Mappings. If you don't need any of the default columns, leave the value blank. You can also choose to add new mapping fields to set up customized columns as needed.
4. Configure any additional settings as required.
5. Enable the Mapping.
6. Verify that Segment is sending data to your S3 bucket by navigating to `<your_S3_bucket>/` in the AWS console.

## Hashing and normalizing column values

The Sync to S3 action can normalize (`lowercase`, `trim`, or `lowercase_trim`) and/or hash (`SHA256`) specific column values before writing them to the file, using the **Columns to Hash or Normalize** field. Values are normalized first, then hashed. Values that are already hashed are passed through unchanged.

Add a separate item to the **Columns to Hash or Normalize** field for each column you want to transform, specifying the column name, hash algorithm, and normalization for that column.

## Known behaviors

* **Filename prefix:** Don't include a file extension in the **Filename prefix** field (for example, use `orders_export`, not `orders_export.csv`). Set the extension with the **File extension** field instead. If the prefix ends in an extension that differs from the one you set in the **File extension** field, Segment might not append a timestamp to each batch and each batch might overwrite the data from the previous file, causing data loss.
* **Column names:** Column headers come from your mapping field names. Don't use the following characters in column names, or the header row won't line up with your data rows:
  * Delimiter (`,` `\t` `|` `;` `:`)
  * Quote (`"`)
  * Newline (`\n`, `\r`)

## Destination Settings

| Field           | Description                                                                                                                                                                         | Required | Type     |
| --------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------- | -------- |
| IAM External ID | The External ID to your IAM role. Generate a secure string and treat it like a password.                                                                                            | Yes      | password |
| IAM Role ARN    | IAM role ARN with write permissions to the S3 bucket. Format: arn:aws:iam::account-id:role/role-name                                                                                | Yes      | string   |
| AWS Bucket Name | Name of the S3 bucket where the files will be uploaded to.                                                                                                                          | Yes      | string   |
| AWS Region Code | Region Code where the S3 bucket is hosted. See \[AWS S3 Documentation]\(https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-regions-availability-zones.html#concepts-regions) | Yes      | string   |

## Available Actions

Build your own Mappings. Combine supported [triggers](/docs/segment/connections/destinations/actions/#components-of-a-destination-action) with the following AWS S3-supported actions:

> \[!NOTE]
>
> Individual destination instances support a maximum of 5 mappings.

* [Sync to S3](#sync-to-s3)

### Sync to S3

Syncs Segment event data to S3.

Sync to S3 is a **Cloud** action. The default Trigger is `type = "identify" or type = "track"`

| Field                        | Description                                                                                                          | Required | Type    |
| ---------------------------- | -------------------------------------------------------------------------------------------------------------------- | -------- | ------- |
| Columns                      | Column to write to the S3 CSV file.                                                                                  | Yes      | OBJECT  |
| Audience Action Column Name  | Name of the column that will contain the action for the audience. true if the user is in the audience, false if not. | No       | STRING  |
| Batch Size Column Name       | Specify the column name to store the batch size when the event is sent to S3. Leave blank if no column is required   | No       | STRING  |
| Enable Batching              | Enable Batching Hidden Field                                                                                         | Yes      | BOOLEAN |
| Batch Size                   | Maximum number of events to include in each batch. Actual batch sizes may be lower.                                  | No       | NUMBER  |
| AWS Subfolder Name           | Name of the S3 Subfolder where the files will be uploaded to. e.g. segmentdata/ or segmentdata/audiences/            | No       | STRING  |
| Filename prefix              | Prefix to append to the name of the uploaded file.                                                                   | No       | STRING  |
| Delimeter                    | Character used to separate tokens in the resulting file.                                                             | Yes      | STRING  |
| File Extension               | File extension for the uploaded file.                                                                                | Yes      | STRING  |
| Columns to Hash or Normalize | Columns whose values will be normalized and/or hashed before writing to the file.                                    | No       | OBJECT  |

## FAQs

### When connecting this destination to an Audience, how do I make sure events are batched by audience?

The AWS S3 destination batches events based on the configured S3 subfolder name and the **Columns to Hash or Normalize** settings. If you use a single mapping to sync multiple Audiences and the subfolder name is a static value, events from different Audiences that share the same subfolder and hashing/normalization configuration are combined into the same batch and file. Creating a separate mapping per Audience is one way to avoid this, but it isn't required.

Instead, map the S3 subfolder name field dynamically to `computation_key` (the Audience name) or `computation_id` (the Audience ID), referencing the full event path. For example: enter `context.personas.computation_key` instead of a static folder name.

With this dynamic mapping, Segment writes each Audience's events to their own subfolder.
