Skip to content

Create an S3 access key (the secret is returned exactly once)

  • Method: POST
  • Path: /v1/orgs/{org}/s3/access-keys
  • Operation ID: createAccessKey
  • Tag: Object storage

Send Authorization: Bearer <credential>. The credential is either an API key (vsk_…) created for an organization, or an OIDC access token obtained by signing in to VirtScale.

Name Type Required Description
org string (uuid) Yes The organization’s id.
Name Type Required Description
Idempotency-Key string, nullable No
Field Type Required Enum Description
access_key AccessKeyOut Yes
access_key.created_at string (date-time) Yes
access_key.id string (uuid) Yes
access_key.last_rotated_at string (date-time), nullable No
access_key.openbao_path string, nullable No
access_key.operation_id string (uuid), nullable No
access_key.rgw_access_key_id string, nullable No The public half of the credential. null while it is still being issued.
access_key.state string Yes
access_key.updated_at string (date-time) Yes
operation OperationRef Yes
operation.attempt integer Yes
operation.created_at string (date-time) Yes
operation.error_class string, nullable No
operation.error_detail string, nullable No
operation.finished_at string (date-time), nullable No When the operation reached a terminal state. Guaranteed non-null whenever state is succeeded, failed or cancelled – including operations that complete synchronously and are returned already succeeded. null means the operation is still in flight.
operation.id string (uuid) Yes
operation.max_attempts integer Yes
operation.resource_id string Yes
operation.resource_type string Yes
operation.state string Yes
operation.type string Yes
secret_access_key string, nullable No The plaintext secret. Shown once and never retrievable again – nothing stores it. Save it now. null on an idempotent replay.

Every error response is application/problem+json (schema Problem).

Status Meaning
401 The credential is missing or invalid.
403 The credential does not have permission to perform this operation.
404 The resource does not exist.
default Any other status is possible; the code field identifies the error.
curl -X POST "https://api.virtscale.nl/v1/orgs/$ORG_ID/s3/access-keys" \
  -H "Authorization: Bearer $VIRTSCALE_API_KEY"