> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.ibee.co.in/docs/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ibee.co.in/docs/_mcp/server.

# Bucket Policies

> Control bucket access in IBEE Object Storage — toggle public access, scope API credential permissions to specific buckets, and use bucket-level access controls.

Bucket access in IBEE Object Storage is controlled through two mechanisms:

* **Public Access** — a bucket-level toggle that exposes objects unauthenticated via a Public Access URL.
* **API Credentials** — programmatic access scoped to a permission level and a set of buckets.

For browser-based cross-origin access, see [CORS](/docs/infrastructure/object-storage/buckets/cors). For Object Lock retention, see [Objects → Locking](/docs/infrastructure/object-storage/objects/object-locking).

## Public access

Enabling **Public Access** allows objects in the bucket to be served unauthenticated via a **Public Access URL**.

### Open General settings

Open your bucket → click **Settings** → click the **General** tab.

### Enable Public Access

Toggle **Public Access** from Disabled to Enabled. A confirmation toast appears: *"Bucket access changed to public"*.

### Enable the Public Access URL

The **Public Access URL** section becomes active but no URL is assigned automatically — it shows *"No Public Access URL is assigned to this bucket."*

Click **Enable** in the top-right of the **Public Access URL** card to assign a URL to the bucket.

Copy the URL. Objects are then accessible at:

```
https://<public-access-url>/<object-key>
```

> **Note**
>
> The Public Access URL is **rate-limited and not recommended for production**. For production traffic, connect a [custom domain](/docs/infrastructure/object-storage/buckets/custom-domains) to the bucket. To turn the URL off, click **Disable** on the **Public Access URL** card.

> **Warning**
>
> Enabling Public Access makes **all objects** in the bucket readable without authentication. Only enable this for buckets intended for public content.

> **Info**
>
> If Public Access is disabled, the Public Access URL section shows: **"Please enable public access in General to use the Public Access URL."**

To serve from your own hostname instead of the assigned Public Access URL, see [Custom Domains](/docs/infrastructure/object-storage/buckets/custom-domains) — the bucket must be public to register a custom domain.

## API Credential access

For programmatic access via the AWS CLI, rclone, or any S3-compatible tool, use an **S3 credential**, created under **Organization → API Tokens → S3 Credentials**. Each credential belongs to one workspace and provides:

* **Access Key ID** + **Secret Access Key** — for S3-compatible tools
* **S3 Endpoint** — `https://{workspaceId}.blob.ibeestorage.com`

### Permission levels

Each credential is created with one Object Storage permission level:

| Permission              | What it allows                                                                          |
| ----------------------- | --------------------------------------------------------------------------------------- |
| **Admin Read & Write**  | Create, list, delete buckets, edit bucket configuration, read, write, and list objects. |
| **Admin Read only**     | List buckets, view configuration, read and list objects.                                |
| **Object Read & Write** | Read, write, and list objects in specific buckets.                                      |
| **Object Read only**    | Read and list objects in specific buckets.                                              |

### Bucket scoping

**Admin** credentials always apply to every bucket in the credential's workspace. **Object Read & Write** and **Object Read only** credentials can apply to:

* **All buckets in the selected workspace** — the simplest option for application-wide access.
* **Specific buckets only** — pick one or more buckets the credential can access.

This is the bucket-level access boundary: a credential scoped to bucket `A` cannot read or write to bucket `B`.

[Create an API credential →](/docs/infrastructure/object-storage/api-tokens)

## Best practices

* **Default to private.** Only enable Public Access on buckets that genuinely serve public content (websites, media, downloads).
* **Use one credential per application or environment** with the narrowest permission level and bucket scope that works.
* **Rotate credentials** by creating a new credential, switching applications to use it, then revoking the old one. The Secret Access Key is shown only once — store it securely.
* **Separate buckets** for prod / staging / dev rather than relying on prefix-based separation alone.

## Related

* [Buckets](/docs/infrastructure/object-storage/buckets)
* [API Credentials](/docs/infrastructure/object-storage/api-tokens)
* [CORS](/docs/infrastructure/object-storage/buckets/cors)
* [Custom Domains](/docs/infrastructure/object-storage/buckets/custom-domains)
* [Objects → Locking](/docs/infrastructure/object-storage/objects/object-locking)