Skip to main content
GET
Vend the default credentials

Authorizations

Authorization
string
header
required

The access token received from the authorization server in the OAuth 2.0 flow.

Response

The tenant default endpoint and credentials.

Resolved S3 connection details for one bucket, for runtime credential vending.

A registered bucket returns its own endpoint + credentials (source="bucket"); an unregistered bucket falls back to the tenant default (source="default"). Region and path-style are tenant-wide and come from the service S3 configuration in both cases.

Distinct from S3CredentialResponse (the per-user access-key CRUD model) — this is the infra-facing endpoint+creds vend for the S3A credential provider / Gravitino.

bucket
string
required

The bucket the credentials apply to.

endpoint
string
required

S3 endpoint URL for this bucket.

path_style
boolean
required

Whether path-style access is required for this endpoint.

access_key
string
required

S3 access key.

secret_key
string
required

S3 secret key.

source
string
required

Where the credentials were resolved from: 'bucket' (override) or 'default'.

region
string | null

S3 region, if configured.

session_token
string | null

S3 session token for temporary credentials; null for static keys.