Amazon S3 Vectors·Browser-First Console
Vector Studio

Manage Amazon S3 Vectors, safely from your browser.

A clean, modern console for AWS vector search. Browse buckets and indexes, ingest embeddings, and run similarity queries. Your AWS credentials are encrypted on your device and never stored on any server.

AES-256-GCM encrypted Stored in IndexedDB only Zero server retention
STS Verified · us-east-1
Vector Buckets (3)S3 API
Click bucket to switch active query
Similarity Search Query
latency: ...
""
Top-K: 1
doc-arch-vault-084Score 0.9842 (Cosine)
values: [0.0214, -0.0482, 0.0891, 0.1140, -0.0039, … 1536 dims]
#crypto-vault#webcrypto-aes#indexeddb
The problem

Vector data is powerful, yet awkward to work with

No friendly console

Amazon S3 Vectors is API-first. Inspecting indexes, vectors, and metadata usually means scripts, the CLI, or raw SDK calls.

Credentials everywhere

Most tools ask you to hand AWS keys to a hosted server or paste them into dashboards you don't control, creating a real security risk.

Hard to explore & debug

Running a similarity search, checking a filter, or verifying an embedding shouldn't require writing throwaway code each time.

The solution

Vector Studio: a secure, browser-first workspace

Everything you need to operate Amazon S3 Vectors, wrapped in a fast UI that keeps your credentials on your machine.

Multi-account connections

Add, test, and switch between AWS accounts. Switching flushes state so accounts never mix.

Explore buckets & indexes

Browse vector buckets, create indexes with custom dimensions and metrics, and view vector data in a real table.

Similarity search

One-click text-to-vector search, a visual metadata filter builder, thresholds, and paginated results.

Built to grow

S3 Vectors today; DynamoDB and other backends are on the way, selectable per connection.

Workflow & Architecture

Three steps, and your keys never leave your machine

Vector Studio operates completely client-side. No cloud key storage, no proxy databases, and zero credential leaks.

STEP 01
Client-Side Only

Set a vault passphrase

On first launch you choose a passphrase. WebCrypto derives a 256-bit encryption key (PBKDF2-SHA256, 210k iterations) in browser memory, never stored or transmitted anywhere.

WebCrypto Subsystem Active
Master Passphrase••••••••••••••••
Key DerivationPBKDF2 (210k)
Cloud Sync0% (Memory Only)
STEP 02
AES-256-GCM

Add an AWS connection

Enter your AWS keys. They are encrypted with AES-256-GCM using your derived key and saved only in your browser's local IndexedDB.

Client KeystoreIndexedDB
Access Key IDAKIA••••••••7X9Q
Payload StateEncrypted Blob
Server DatabaseNone (Isolated)
STEP 03
Stateless SigV4

Explore & similarity search

Browse vector buckets and run similarity search. Requests sign headers with AWS SigV4 just-in-time and credentials are never persisted.

S3 Vector Search18ms
s3://vector-store-prod0.984 Cosine
Auth ProtocolAWS SigV4 JIT
Server Key LogZero (Stateless)
Safe on your side only

Your credentials never live on our servers

Vector Studio is built browser-first. The server is a stateless proxy that has no database and stores nothing.

Encrypted at rest

AWS secrets are encrypted with AES-256-GCM using WebCrypto PBKDF2 (210,000 iterations). Only ciphertext is stored.

Sandboxed storage

Connections live in IndexedDB and strict session cookies on your device. Zero remote database or telemetry.

Shoulder-surfing safe

Sensitive details like Account IDs, ARNs, and bucket names are automatically masked with dots for safe screen sharing.

Universal total wipe

Reset the vault in one click to irreversibly drop IndexedDB, wipe localStorage, and clear all cookies.

Encrypted, private, and easy to use

Forget the passphrase or want a clean slate? Reset the vault in one click to instantly wipe all client storage, keys, and cookies. You're always in total control of your own keys.

Get started