This is expected @MontyGvMC it was never documented that you should set authorization header and also pre-signed requests. It is expected that multiple schemes are not provided for authentication in a ...