> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.ibee.co.in/docs/infrastructure/object-storage/buckets/bucket-policies/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ibee.co.in/_mcp/server. # Bucket Policies > Control bucket access in IBEE Object Storage — toggle public access, scope API credential permissions to specific buckets, and use bucket-level access controls. Bucket access in IBEE Object Storage is controlled through two mechanisms: * **Public Access** — a bucket-level toggle that exposes objects unauthenticated via a Public Access URL. * **API Credentials** — programmatic access scoped to a permission level and a set of buckets. For browser-based cross-origin access, see [CORS](/docs/infrastructure/object-storage/buckets/cors). For Object Lock retention, see [Objects → Locking](/docs/infrastructure/object-storage/objects/object-locking). ## Public access Enabling **Public Access** allows objects in the bucket to be served unauthenticated via a **Public Access URL**. ### Open General settings Open your bucket → click **Settings** → click the **General** tab. ### Enable Public Access Toggle **Public Access** from Disabled to Enabled. A confirmation toast appears: *"Bucket access changed to public"*. ### Enable the Public Access URL The **Public Access URL** section becomes active but no URL is assigned automatically — it shows *"No Public Access URL is assigned to this bucket."* Click **Enable** in the top-right of the **Public Access URL** card to assign a URL to the bucket. Copy the URL. Objects are then accessible at: ``` https:/// ``` > **Note** > > The Public Access URL is **rate-limited and not recommended for production**. For production traffic, connect a [custom domain](/docs/infrastructure/object-storage/buckets/custom-domains) to the bucket. To turn the URL off, click **Disable** on the **Public Access URL** card. > **Warning** > > Enabling Public Access makes **all objects** in the bucket readable without authentication. Only enable this for buckets intended for public content. > **Info** > > If Public Access is disabled, the Public Access URL section shows: **"Please enable public access in General to use the Public Access URL."** To serve from your own hostname instead of the assigned Public Access URL, see [Custom Domains](/docs/infrastructure/object-storage/buckets/custom-domains) — the bucket must be public to register a custom domain. ## API Credential access For programmatic access via the AWS CLI, rclone, or any S3-compatible tool, use an **S3 credential**, created under **Organization → API Tokens → S3 Credentials**. Each credential belongs to one workspace and provides: * **Access Key ID** + **Secret Access Key** — for S3-compatible tools * **S3 Endpoint** — `https://{workspaceId}.blob.ibeestorage.com` ### Permission levels Each credential is created with one Object Storage permission level: | Permission | What it allows | | ----------------------- | --------------------------------------------------------------------------------------- | | **Admin Read & Write** | Create, list, delete buckets, edit bucket configuration, read, write, and list objects. | | **Admin Read only** | List buckets, view configuration, read and list objects. | | **Object Read & Write** | Read, write, and list objects in specific buckets. | | **Object Read only** | Read and list objects in specific buckets. | ### Bucket scoping **Admin** credentials always apply to every bucket in the credential's workspace. **Object Read & Write** and **Object Read only** credentials can apply to: * **All buckets in the selected workspace** — the simplest option for application-wide access. * **Specific buckets only** — pick one or more buckets the credential can access. This is the bucket-level access boundary: a credential scoped to bucket `A` cannot read or write to bucket `B`. [Create an API credential →](/docs/infrastructure/object-storage/api-tokens) ## Best practices * **Default to private.** Only enable Public Access on buckets that genuinely serve public content (websites, media, downloads). * **Use one credential per application or environment** with the narrowest permission level and bucket scope that works. * **Rotate credentials** by creating a new credential, switching applications to use it, then revoking the old one. The Secret Access Key is shown only once — store it securely. * **Separate buckets** for prod / staging / dev rather than relying on prefix-based separation alone. ## Related * [Buckets](/docs/infrastructure/object-storage/buckets) * [API Credentials](/docs/infrastructure/object-storage/api-tokens) * [CORS](/docs/infrastructure/object-storage/buckets/cors) * [Custom Domains](/docs/infrastructure/object-storage/buckets/custom-domains) * [Objects → Locking](/docs/infrastructure/object-storage/objects/object-locking) > Control bucket access in IBEE Object Storage — toggle public access, scope API credential permissions to specific buckets, and use bucket-level access controls.