Skip to main content

Workflow Outline

This workflow demonstrates how to securely access Harmonized Landsat and Sentinel-2 (HLS) data directly from the cloud, enabled through two methods of generating temporary Amazon Web Services (AWS) S3 credentials, Earthdata Search results, and the Land Processes Distributed Active Archive Center (LPDAAC) credential endpoint. 

Users will use these temporary credentials (access key, secret key, and session token) to configure a new Cloud Storage Connection in ArcGIS Pro, enabling direct access to NASA's protected cloud storage buckets (lp-prod-protected).

Known Limitations

  • Temporary credentials are valid for 1 hour
  • Requires an ArcGIS Pro instance to be running on virtual machine installed from an AWS us-west-2 (Oregon) server
  • NASA’s requestor pays model limits the ability for any/all users to access data through CSC due to egress costs

Data Used

Tools/Tech Used

  • ArcGIS Pro (installed from an AWS us-west-2 Oregon server)

Generate Temporary Cloud Storage Connection Credentials: Earthdata Search Results

  1. Go to Earthdata Search and log in.
  1. Search for data.
    1. Type in “HLS.”
    2. Hit “Search.”
  1. You may receive a pop-up for a guided tour of Earthdata Search. You may either choose to “Take the tour” or “Skip for now.” If this is your first time using Earthdata Search, or you want a refresher, we recommend that you take the tour.
Image
Image
  1. With your search query as “HLS,” look through the matching collections and select “HLS Landsat Operational Land Imager Surface Reflectance and TOA Brightness Daily Global 30m v2.0.” It should be one of the collections near the top of the results.
Image
Image
  1. Filter, view, and select desired granules to add to your project by pressing the green “+” (plus) sign.
  1. Verify desired downloadable data.
    1. Hit the blue “Download” button.
    2. Verify that the information is from your desired collection and you have the desired amount of granules.
    3. Choose the “Download all data” method.
    4. Click the blue “Download Data” button.
Image
Image
  1. On the next screen that appears, instead of continuing to download the files traditionally, navigate to the “AWS S3 Access” tab and select “Get AWS S3 Credentials.”
  2. Securely record this key information:
    1. accessKeyID
    2. secretAccessKey
    3. sessionToken
Image

Generate Temporary Cloud Storage Connection Credentials: General Bucket Access

  1. Read through LPDAAC S3 credential documentation at s3credentialsREADME.
  2. Generate temporary cloud storage connection credentials.
  3. Securely record this key information:
    1. accessKeyID
    2. secretAccessKey
    3. SessionToken
Image

Creating a Cloud Storage Connection in ArcGIS Pro

  1. Open a new project in ArcGIS Pro.
  2. Navigate to the “Insert” tab.
  3. Select “Connections,” then “Cloud Store,” and then “New Cloud Storage Connection.”
  4. A “Create Cloud Storage Connection” window will pop up. Populate it with the temporary credentials and relevant information from the previous step:
    1. Enter your desired “Connection File Name”
    2. Service Provider: AMAZON
    3. accessKeyID
    4. secretAccessKey
    5. Bucket (Container) Name: lp-prod-protected
    6. Folder (Optional): HLSL30.020
    7. Region (Environment): US West (Oregon)
    8. sessionToken
Image
Image
  1. Verify connection information and hit “OK” to establish a connection. The following screenshot below shows how the Cloud Storage Connection should appear in the Catalog Pane.
Image

HLS is funded by NASA and is a deliverable of the Satellite Needs Working Group (SNWG), an interagency effort of the U.S. Government dedicated to identifying and addressing Earth observation needs across U.S. civilian federal agencies.

Details

Last Updated

Sept. 23, 2026

Published

Sept. 23, 2026