Skip to main content
GET
Vend credentials for a bucket

Authorizations

Authorization
string
header
required

The access token received from the authorization server in the OAuth 2.0 flow.

Path Parameters

bucket_name
string
required

The bucket to vend credentials for; unregistered buckets fall back to the tenant default.

Response

Resolved endpoint and credentials for the bucket.

Resolved S3 connection details for one bucket, for runtime credential vending.

A registered bucket returns its own endpoint + credentials (source="bucket"); an unregistered bucket falls back to the tenant default (source="default"). Region and path-style are tenant-wide and come from the service S3 configuration in both cases.

Distinct from S3CredentialResponse (the per-user access-key CRUD model) — this is the infra-facing endpoint+creds vend for the S3A credential provider / Gravitino.

bucket
string
required

The bucket the credentials apply to.

endpoint
string
required

S3 endpoint URL for this bucket.

path_style
boolean
required

Whether path-style access is required for this endpoint.

access_key
string
required

S3 access key.

secret_key
string
required

S3 secret key.

source
string
required

Where the credentials were resolved from: 'bucket' (override) or 'default'.

region
string | null

S3 region, if configured.

session_token
string | null

S3 session token for temporary credentials; null for static keys.