> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.ibee.co.in/docs/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ibee.co.in/docs/_mcp/server.

# Core Concepts

> Core building blocks of IBEE Object Storage — buckets, objects, regions, endpoints, and access.

Before working with Object Storage it helps to understand the building blocks: **buckets**, **objects**, **regions**, **endpoints**, and **access** via API Credentials.

## Buckets

A **bucket** is a container for objects. Every object you upload lives in exactly one bucket.

* Bucket names are **globally unique** within IBEE Object Storage.
* A bucket's **location** is fixed at creation and cannot be changed — to use a different location, create a new bucket and migrate your objects.
* Use multiple buckets to separate environments, projects, or access boundaries.

Bucket names must be **3 to 63 characters**, lowercase, and contain only letters, numbers, and hyphens. They must start and end with a letter or number. See [Buckets](/docs/infrastructure/object-storage/buckets) for the full naming rules and the create flow.

## Objects

An **object** is a single file plus its metadata. Each object has:

* A **key** — the path-like name within the bucket (`reports/2026-05.pdf`).
* The object **data** — up to 5 TiB per object.
* A **type** (MIME type, e.g. `image/jpeg`) and **storage class** (`Standard`).
* System metadata — size, last-modified, ETag.

There's no real folder hierarchy — only keys with `/` separators. The portal renders prefixes as folders. See [Objects](/docs/infrastructure/object-storage/objects) for upload, download, and management.

## Regions

A **region** is a physical data center where buckets live. Pick the region closest to your users or your compute.

| Region           | Code  | Status    |
| ---------------- | ----- | --------- |
| Amaravati, India | `VGA` | Available |
| Hyderabad, India | `HYD` | Preorder  |
| Ashburn, USA     | `IAD` | Preorder  |

When creating a bucket, keep **Automatic location** to let the platform pick the best available region, or click **Need a specific location? click here** to choose a site yourself. Pre-order sites show **Talk to Sales** instead of a create button. Jurisdiction-based placement (**Specify jurisdiction**) is coming soon — talk to sales if you need it today. See [Buckets → Create a bucket](/docs/infrastructure/object-storage/buckets#create-a-bucket) and [Regions & Locations](/docs/getting-started/overview/regions-and-locations).

## Endpoints

The **endpoint** is the HTTPS URL S3-compatible clients connect to. Each workspace has its own S3 endpoint:

```text
https://{workspaceId}.blob.ibeestorage.com
```

Use this with the AWS CLI, AWS SDKs, `s3cmd`, `rclone`, or any S3-compatible tool — paired with the Access Key ID and Secret Access Key from an [API Credentials](/docs/infrastructure/object-storage/api-tokens).

For browser delivery from a public bucket, use the bucket's **Public Access URL** or a **Custom Domain** instead. See [Buckets → Policies](/docs/infrastructure/object-storage/buckets/bucket-policies) and [Buckets → Custom Domains](/docs/infrastructure/object-storage/buckets/custom-domains).

## Access

To reach buckets from S3-compatible tools you create an **S3 credential** under **Organization → API Tokens → S3 Credentials**. Each credential belongs to one workspace and gives you:

| Credential        | Use                                                             |
| ----------------- | --------------------------------------------------------------- |
| Access Key ID     | S3-compatible tools (AWS CLI, SDKs, rclone)                     |
| Secret Access Key | S3-compatible tools — shown once only                           |
| S3 Endpoint       | `https://{workspaceId}.blob.ibeestorage.com` for that workspace |

Permission levels range from `Object Read only` to `Admin Read & Write`. Object-level credentials can be limited to specific buckets; Admin credentials always apply to every bucket in the workspace. See [API Credentials](/docs/infrastructure/object-storage/api-tokens) for the full flow.

## Public access and Object Lock

These bucket-level settings control how objects can be read, written, and kept:

* **Public Access** — when enabled, objects can be served unauthenticated via the bucket's Public Access URL. Toggled from **Settings → General**.
* **Versioning** — keeps previous versions of overwritten or deleted objects. Turned on at bucket creation under **Versioning and object lock**.
* **Object Lock** — prevents objects from being deleted or overwritten while a retention period is in effect. **Permanent setting** that must be enabled at bucket creation under **Versioning and object lock** (it also turns on versioning). See [Objects → Locking](/docs/infrastructure/object-storage/objects/object-locking).

## Related

* [Getting started](/docs/infrastructure/object-storage/upload-your-first-object)
* [Buckets](/docs/infrastructure/object-storage/buckets)
* [Objects](/docs/infrastructure/object-storage/objects)
* [Limits](/docs/infrastructure/object-storage/limits)