Skip to main content
Blob Storage has an S3-compatible gateway that works with any S3 client. The SDK gives you its credentials, or a ready S3Client from the AWS SDK. Examples use the blob client from Creating the client.
Both methods need an API key. A client created with an upload token gets 403 UPLOAD_TOKEN_NOT_ALLOWED, and a key in an old format gets LEGACY_API_KEY.

s3()

s3() returns an S3Client from @aws-sdk/client-s3, already configured with the gateway’s endpoint, region and credentials, and with forcePathStyle: true. @aws-sdk/client-s3 is an optional peer dependency: install it only if you use s3(). It is loaded lazily, so the SDK itself stays dependency-free.

Buckets

See Buckets and Keys for how S3 keys map to objects, and Supported operations for what the gateway accepts.

s3Credentials()

For other S3 clients (aws-cli, rclone, boto3, …), s3Credentials() returns the raw key pair:
Use path-style addressing with any other client.
secret_access_key gives the same access as the API key. Keep it on the server and store it like the key itself. Revoking or rotating the API key also kills the pair.

Caching

The pair is deterministic per API key, so the SDK caches it per client instance: s3Credentials() and s3() call the API once, and later calls reuse the result. A failed call is not cached, so the next call tries again.
The credentials route accepts only 10 requests per hour. Create one SquareCloudBlob client and reuse it instead of creating one per request.
API reference: S3 Credentials.

Next steps

Errors

Error codes and the retry policy.

S3 compatibility

What the S3 gateway supports.