> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.ibee.co.in/docs/infrastructure/object-storage/core-concepts/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ibee.co.in/_mcp/server. # Core Concepts > Core building blocks of IBEE Object Storage — buckets, objects, regions, endpoints, and access. Before working with Object Storage it helps to understand the building blocks: **buckets**, **objects**, **regions**, **endpoints**, and **access** via API Credentials. ## Buckets A **bucket** is a container for objects. Every object you upload lives in exactly one bucket. * Bucket names are **globally unique** within IBEE Object Storage. * A bucket's **location** is fixed at creation and cannot be changed — to use a different location, create a new bucket and migrate your objects. * Use multiple buckets to separate environments, projects, or access boundaries. Bucket names must be **3 to 63 characters**, lowercase, and contain only letters, numbers, and hyphens. They must start and end with a letter or number. See [Buckets](/docs/infrastructure/object-storage/buckets) for the full naming rules and the create flow. ## Objects An **object** is a single file plus its metadata. Each object has: * A **key** — the path-like name within the bucket (`reports/2026-05.pdf`). * The object **data** — up to 5 TiB per object. * A **type** (MIME type, e.g. `image/jpeg`) and **storage class** (`Standard`). * System metadata — size, last-modified, ETag. There's no real folder hierarchy — only keys with `/` separators. The portal renders prefixes as folders. See [Objects](/docs/infrastructure/object-storage/objects) for upload, download, and management. ## Regions A **region** is a physical data center where buckets live. Pick the region closest to your users or your compute. | Region | Code | Status | | ---------------- | ----- | --------- | | Amaravati, India | `VGA` | Available | | Hyderabad, India | `HYD` | Preorder | | Ashburn, USA | `IAD` | Preorder | When creating a bucket, keep **Automatic location** to let the platform pick the best available region, or click **Need a specific location? click here** to choose a site yourself. Pre-order sites show **Talk to Sales** instead of a create button. Jurisdiction-based placement (**Specify jurisdiction**) is coming soon — talk to sales if you need it today. See [Buckets → Create a bucket](/docs/infrastructure/object-storage/buckets#create-a-bucket) and [Regions & Locations](/docs/getting-started/overview/regions-and-locations). ## Endpoints The **endpoint** is the HTTPS URL S3-compatible clients connect to. Each workspace has its own S3 endpoint: ```text https://{workspaceId}.blob.ibeestorage.com ``` Use this with the AWS CLI, AWS SDKs, `s3cmd`, `rclone`, or any S3-compatible tool — paired with the Access Key ID and Secret Access Key from an [API Credentials](/docs/infrastructure/object-storage/api-tokens). For browser delivery from a public bucket, use the bucket's **Public Access URL** or a **Custom Domain** instead. See [Buckets → Policies](/docs/infrastructure/object-storage/buckets/bucket-policies) and [Buckets → Custom Domains](/docs/infrastructure/object-storage/buckets/custom-domains). ## Access To reach buckets from S3-compatible tools you create an **S3 credential** under **Organization → API Tokens → S3 Credentials**. Each credential belongs to one workspace and gives you: | Credential | Use | | ----------------- | --------------------------------------------------------------- | | Access Key ID | S3-compatible tools (AWS CLI, SDKs, rclone) | | Secret Access Key | S3-compatible tools — shown once only | | S3 Endpoint | `https://{workspaceId}.blob.ibeestorage.com` for that workspace | Permission levels range from `Object Read only` to `Admin Read & Write`. Object-level credentials can be limited to specific buckets; Admin credentials always apply to every bucket in the workspace. See [API Credentials](/docs/infrastructure/object-storage/api-tokens) for the full flow. ## Public access and Object Lock These bucket-level settings control how objects can be read, written, and kept: * **Public Access** — when enabled, objects can be served unauthenticated via the bucket's Public Access URL. Toggled from **Settings → General**. * **Versioning** — keeps previous versions of overwritten or deleted objects. Turned on at bucket creation under **Versioning and object lock**. * **Object Lock** — prevents objects from being deleted or overwritten while a retention period is in effect. **Permanent setting** that must be enabled at bucket creation under **Versioning and object lock** (it also turns on versioning). See [Objects → Locking](/docs/infrastructure/object-storage/objects/object-locking). ## Related * [Getting started](/docs/infrastructure/object-storage/upload-your-first-object) * [Buckets](/docs/infrastructure/object-storage/buckets) * [Objects](/docs/infrastructure/object-storage/objects) * [Limits](/docs/infrastructure/object-storage/limits) > Core building blocks of IBEE Object Storage — buckets, objects, regions, endpoints, and access.