REST API - Storage#

S3-compatible object storage.

Buckets#

EndpointMethodDescription
/projects/{id}/storage/bucketsGETList buckets
/projects/{id}/storage/bucketsPOSTCreate a bucket
/projects/{id}/storage/buckets/{bucketID}GETGet one bucket
/projects/{id}/storage/buckets/{bucketID}DELETEDelete a bucket

Create:

{
  "name": "Avatars",
  "slug": "avatars",
  "is_public": true,
  "file_size_limit": 5000000,
  "allowed_mime_types": ["image/png", "image/jpeg"]
}
JSON

Objects#

EndpointMethodDescription
/projects/{id}/storage/buckets/{bucketID}/objectsGETList objects
/projects/{id}/storage/buckets/{bucketID}/foldersPOSTCreate a folder
/projects/{id}/storage/objects/{objectID}DELETEDelete an object

Signed URLs#

EndpointMethodDescription
/projects/{id}/storage/signed-upload-urlPOSTPresigned PUT URL (5 min)
/projects/{id}/storage/signed-download-urlPOSTPresigned GET URL (1 hour)
/projects/{id}/storage/public/{bucketID}/{objectID}GETPublic download (no auth)

Signed upload:

{
  "bucket_id": "uuid",
  "object_name": "user-1.png",
  "content_length": 20480
}
JSON
{
  "url": "http://localhost:8333/afb-5c73dab0/avatars/user-1.png?X-Amz-..."
}
JSON

Then PUT the file bytes to the returned URL.

Security#

  • Storage accepts the project API key (or a project-user session)
  • Scoped keys: storage:read, storage:write
  • API keys are authorized only to their own project