Free plan available

Somewhere to put your files, reached with any S3 client

Make a bucket in the console, copy its address and its key, and point the aws CLI, your application's SDK or a tool like rclone at it. It speaks S3, so whatever you already use to talk to object storage works here.

Sample data, drawn with the console's own components.

One key

Per bucket, and you can rotate it

Any S3 client

Path-style addressing

One region

The one you choose

What a client needs

S3 compatiblePath-style addressingSignature v4aws CLIboto3AWS SDK for JavaScriptrclone

One thing has to be set, whichever client you use: path-style addressing, so that the bucket is a path under the address rather than a name in front of it. It is one option, and the console shows it beside the address.

A key for each bucket

Every bucket has one credential of its own, shown to you once when it is made. It reaches that bucket and no other, and rotating it mints a new key and revokes the old one.

Nothing is readable without it

The address is on the internet so that your application can reach it, and every request to it is signed. There is no anonymous read and no setting that would grant one.

Uploads go straight to the store

When you drop a file into the console it travels from your browser to the store itself. No byte of it passes through our API, so a large file is not waiting on us.

aws configure set default.s3.addressing_style path

aws s3 cp ./logo.png s3://product-images/uploads/logo.png \
  --endpoint-url "$HIVEOPS_S3_ENDPOINT" --region "$HIVEOPS_S3_REGION"

aws s3 ls s3://product-images/uploads/ \
  --endpoint-url "$HIVEOPS_S3_ENDPOINT" --region "$HIVEOPS_S3_REGION"

What it is not, said plainly

Buckets are private, and there is no way to make one public or to hand somebody a link to a file in it. A bucket lives in one region and is not copied to another, so it is where your application keeps things rather than a second copy of them: keep your own copy of anything you cannot afford to lose.

Browse it without leaving the console

The console lists what is in a bucket, uploads a file into it and takes one back out, so you can check what your application wrote without installing anything. Deleting a bucket destroys every object in it, and nothing brings them back.