Create temporary credentials
Create an access key, secret and session token that stop working on their own, limited to a bucket, a key prefix and read-only or read-write.
In the dashboard
Temporary credentials are an access key ID, a secret access key and a session token that stop working on their own, from 15 minutes to 12 hours after you create them. Use them to give an app, a build job or a person access to one bucket, or to one folder in it, for as long as the work takes, without handing out a long-lived access key.
You create them on the service's Access keys tab or through the API. They work with any S3 client that can send a session token, such as the AWS CLI and the AWS SDKs.
Before you begin
Section titled Before you begin- Sign in to the dashboard and open the service.
- The service must be
active. - To limit the credentials to one bucket, create the bucket first (Create a bucket).
- Check that the Temporary credentials… button is on the Access keys tab. It is there only when we have turned the feature on. If it is missing, create an access key instead.
What temporary credentials can do
Section titled What temporary credentials can doYou choose three limits when you create them: the buckets, a key prefix and the permissions.
- Scope
- All buckets on this account covers every bucket whose name starts with your prefix, such as
u7-, including buckets you create later. One bucket covers that bucket only, and every other bucket refuses the credentials. - Key prefix
- Optional. The credentials reach only keys that start with it. With
photos/2026/they readphotos/2026/jan/a.jpgand refusephotos/2025/a.jpg. End a folder's prefix with a slash. Without the slash,photos/2026also matchesphotos/2026-old/a.jpg. When a request reads or writes an object, upper and lower case are not told apart:photos/also reachesPhotos/a.jpg. A listing does tell them apart. Do not use a prefix to separate keys whose names differ only in case. - Permissions
- Read only lists and downloads objects, and lists their versions and tags. Read and write also uploads, copies and deletes objects, including multipart uploads and old versions that Object Lock does not protect, and adds and removes object tags.
They cannot do more than an access key of the same permissions. Temporary credentials never:
- create or delete a bucket,
- read or change a bucket's settings, such as its versioning, CORS rules, lifecycle rules or policy,
- read or change an object's ACL, retention or legal hold, or
- ask for more credentials.
A request that tries any of these answers 403 AccessDenied. An access key can read a bucket's settings; temporary credentials cannot.
- Lifetime
- From 900 seconds (15 minutes) to 43200 seconds (12 hours). The dashboard offers 15 minutes, 1 hour and 12 hours. The API takes any number between.
Temporary credentials work at once, with no wait for them to reach storage. They stop working at the Expires time, and nothing can end them sooner, so pick the shortest time the work needs.
Requests made with them are counted and billed to the service like requests made with an access key (Usage and billing).
Create temporary credentials
Section titled Create temporary credentials- Open the service and select the Access keys tab.
- Select Temporary credentials….
- Under Scope, keep All buckets on this account or choose one bucket.
- In Key prefix (optional), type a prefix such as
photos/2026/, or leave it empty to cover every key. A prefix has at most 256 bytes. It cannot contain*,?,$or a backslash, and it cannot start with a slash. - Under Permissions, choose Read only or Read and write. Read only is selected first.
- Under How long, choose 15 minutes, 1 hour or 12 hours. 1 hour is selected first.
- Select Create credentials.
Save the credentials
Section titled Save the credentialsThe dialog now shows the credentials, under Save these credentials now. This is the only time the dashboard or the API shows the secret access key and the session token. We do not keep either.
- Access key ID
- Starts with
ASIA. - Secret access key and Session token
- Hidden at first. Select the eye icon beside one to show it, or copy it without showing it.
- Expires
- When the credentials stop working, in your time zone, with how long is left.
- Endpoint and Region
- Where to send requests. For a bucket in another region, use that region's endpoint.
- Scope, Key prefix and Permissions
- What you chose.
To copy the values:
- Copy all copies every field, the secret and the token included, as lines of text.
- The copy button beside a field copies that value.
- Environment variables holds the four
exportlines the AWS CLI and the AWS SDKs read. AWS CLI holds a command that lists what the credentials cover.
Select I have saved them when you have stored the values where your app can read them.
Use the credentials
Section titled Use the credentialsEvery request carries the session token as well as the key ID and the secret. Send requests to the endpoint with path-style addressing, as for an access key (Connect an S3 client).
AWS CLI
Section titled AWS CLIPaste the Environment variables block into your shell, then run a command with the endpoint:
export AWS_ACCESS_KEY_ID=ASIAEXAMPLE0000000000
export AWS_SECRET_ACCESS_KEY=ExampleSecretAccessKey000000000000000000
export AWS_SESSION_TOKEN=ExampleSessionToken
export AWS_DEFAULT_REGION=fra
aws s3 ls s3://u7-assets/photos/2026/ --endpoint-url https://s3.fra.coritan.com:7337
aws s3 cp ./report.pdf s3://u7-assets/photos/2026/report.pdf --endpoint-url https://s3.fra.coritan.com:7337
Python
Section titled Pythonimport boto3
from botocore.config import Config
s3 = boto3.client(
"s3",
endpoint_url="https://s3.fra.coritan.com:7337",
region_name="fra",
aws_access_key_id="ASIAEXAMPLE0000000000",
aws_secret_access_key="ExampleSecretAccessKey000000000000000000",
aws_session_token="ExampleSessionToken",
config=Config(s3={"addressing_style": "path"}),
)
print(s3.list_objects_v2(Bucket="u7-assets", Prefix="photos/2026/")["KeyCount"])
Listing with a prefix
Section titled Listing with a prefixCredentials limited to a prefix can list only that prefix. Name it in every listing, or a longer prefix under it:
aws s3 ls s3://u7-assets/photos/2026/works.aws s3 ls s3://u7-assets/is refused, because it would show keys outside the prefix.aws s3 lswith no bucket lists the buckets the credentials cover, and shows none when they have a prefix.- A tool that checks a bucket exists before it uses it, with a
HEADrequest on the bucket, is refused. Turn that check off, asno_check_bucket = truedoes in rclone.
Result
Section titled ResultThe credentials list, read and write what you chose, at the endpoint, until the Expires time. After it, every request is refused with InvalidAccessKeyId, and you create new credentials.
Troubleshooting
Section titled TroubleshootingInvalidAccessKeyId- The credentials have expired, or the request left out the session token or sent a wrong one. Check that your client sends the token with the key ID and the secret, and create new credentials if the time has passed.
AccessDenied- The request is outside what you chose: another bucket, a key outside the prefix, a write with Read only credentials, or a call such as creating a bucket or reading a bucket's settings. A listing that does not name the prefix is refused too.
- The Temporary credentials… button is missing
- The service is not
active, or we have not turned the feature on. Create an access key instead. Temporary credentials are not available yet. Create an access key instead.- We have not turned the feature on. Use an access key.
Temporary credentials are not ready in this region yet. Try again in a few minutes.- We turned the feature on and the region's storage servers have not picked it up yet. Try again in a few minutes.
A prefix cannot contain *, ?, $ or a backslash- Remove the character. A prefix is plain text, and these characters have a meaning in the permissions the credentials carry, so a key that holds one cannot be named by a prefix.
Too many requests for this action. Try again later.- One account may create 120 sets of temporary credentials an hour. Wait, or reuse a set that has not expired.
- An AWS tool's
assume-rolecall is refused - The credentials come from this page and the API below. Calls such as
aws sts assume-roleagainst the endpoint answerAccessDenied.
Related
Section titled Related- Create and revoke access keys
- Connect an S3 client
- Object Storage limits
- Troubleshoot Object Storage
With the API
Section titled With the APIEach request takes the service ID. A service that is not Object Storage on your account answers 404 with Object storage service not found.
Check that they are available
Section titled Check that they are availableGET /api/v1/client/object-storage/{service_id}/credentials says whether you can create temporary credentials and which limits apply:
curl https://api.coritan.com/api/v1/client/object-storage/1207/credentials \
-H "Authorization: Bearer $CORITAN_TOKEN"
{
"enabled": true,
"modes": ["read", "read_write"],
"min_expires_in": 900,
"max_expires_in": 43200,
"default_expires_in": 3600,
"max_prefix_bytes": 256
}
enabled is false until we turn the feature on. The dashboard shows Temporary credentials… only when it is true.
Create credentials
Section titled Create credentialsPOST /api/v1/client/object-storage/{service_id}/credentials takes:
mode- Required.
readorread_write. bucket_id- Optional. The
idof one of the service's buckets. Without it, the credentials cover every bucket on your account. prefix- Optional. Keys must start with it. At most 256 bytes. Without it, the credentials cover every key.
expires_in- Optional. Seconds until they expire, from 900 to 43200. The default is 3600.
curl -X POST https://api.coritan.com/api/v1/client/object-storage/1207/credentials \
-H "Authorization: Bearer $CORITAN_TOKEN" \
-H "Content-Type: application/json" \
-d '{"mode": "read", "bucket_id": 31, "prefix": "photos/2026/", "expires_in": 1800}'
It answers 201:
{
"access_key_id": "ASIAEXAMPLE0000000000",
"secret_access_key": "ExampleSecretAccessKey000000000000000000",
"session_token": "ExampleSessionToken",
"expiration": "2026-10-09T10:30:00Z",
"endpoint": "https://s3.fra.coritan.com:7337",
"region": "fra",
"bucket": "u7-assets",
"prefix": "photos/2026/",
"mode": "read"
}
secret_access_key and session_token appear in this response and never again. expiration is in UTC. bucket is null for credentials that cover every bucket. endpoint and region are those of the bucket, or of the service's home region when the credentials cover every bucket.
| Status | detail |
Cause |
|---|---|---|
404 |
Bucket not found |
bucket_id is not one of the service's buckets. |
409 |
This service is suspended; it can be changed once it is active |
The service is not active. The message names its status. |
409 |
Create a bucket first. A service gets its region from its first bucket. |
The service has no region and no bucket yet. |
422 |
A prefix cannot contain *, ?, $ or a backslash |
The prefix holds one of those characters. |
422 |
A prefix does not start with a slash |
The prefix starts with /. |
422 |
A prefix is at most 256 bytes |
The prefix is longer. |
422 |
a list of fields | mode is not read or read_write, or expires_in is outside 900 to 43200. |
429 |
detail.message is Too many requests for this action. Try again later. |
The account asked for more than 120 sets in an hour. The Retry-After header says how many seconds to wait. |
503 |
Temporary credentials are not available yet. Create an access key instead. |
We have not turned the feature on. |
503 |
Temporary credentials are not ready in this region yet. Try again in a few minutes. |
The region's storage servers have not picked up the feature. |
502 |
Storage would not issue temporary credentials. Try again in a minute. |
The region's storage servers refused the request. Try again. |
502 |
Storage did not answer. Try again in a minute. |
The region's storage servers did not answer in time. Try again. |
API operations on this page
| Method | Path | What it does |
|---|---|---|
GET | /api/v1/client/object-storage/{service_id}/credentials | Whether temporary credentials can be created for this service, and the limits they follow |
POST | /api/v1/client/object-storage/{service_id}/credentials | Create temporary credentials |