---
title: "Access keys"
description: "Generate S3 access keys for Edge Network storage, set read-only or read-write permissions, scope keys to specific buckets, and follow rotation best practices."
url: "https://edge.network/docs/storage/access-keys"
section: "Storage"
---

# Access keys

Access keys authenticate your applications with Edge Storage. Each key consists of an Access Key ID and a Secret Access Key.

![Storage access keys with permissions and scoping](/media/docs/control-storage-keys.svg)

## Key components

- **Access Key ID:** a unique identifier for your key. Safe to store in configuration files. Example: `EDGE1234567890ABCDEF`
- **Secret Access Key:** a secret token used to sign requests. Keep this secure. Example: `wJalrXUtnFEMI/K7MDENG...`

## Generate a new key

1. Navigate to [Storage → Access Keys](/console/storage/keys).
2. Click **Generate New Key**.
3. Copy both the Access Key ID and Secret Access Key.
4. Store them securely (for example, in environment variables or a secrets manager).

> [!CAUTION]
> **Save your secret key.** The Secret Access Key is only shown once when the key is created. If you lose it, you'll need to generate a new key.

## Permissions and bucket scoping

When creating a key, you can restrict its permissions and scope it to specific buckets. This follows the principle of least privilege: give each key only the access it needs.

### Permissions

- **Read & Write:** full access to upload, download and delete objects, and to create and delete buckets. Use for applications that manage content.
- **Read Only:** download and list only. Cannot upload, delete or modify objects. Use for analytics, reporting or public-facing read access.

### Bucket scope

By default, keys can access all buckets in the account. You can restrict a key to one or more specific buckets. A scoped key cannot see, access or modify any bucket outside its scope.

- **All buckets:** no scope set. The key works with any bucket. This is the default.
- **Specific buckets:** the key only works with the selected buckets. Requests to other buckets return `AccessDenied`.

> [!NOTE]
> **Backward compatible.** Existing keys continue to work with full account-wide access. Scoping only applies to newly created keys where you explicitly set a bucket scope.

## Security best practices

- **Use environment variables:** never hardcode credentials in your source code. Use environment variables or a secrets manager.
- **Rotate keys regularly:** create new keys periodically and delete old ones. This limits exposure if a key is compromised.
- **One key per application:** use separate keys for different applications or environments. This makes it easy to revoke access if needed.
- **Separate dev and production:** use different keys (and ideally different buckets) for development and production environments.

## Delete a key

To revoke access for a key:

1. Go to [Storage → Access Keys](/console/storage/keys).
2. Find the key you want to delete.
3. Click the delete button and confirm.

The key is revoked immediately. Any applications using this key will no longer be able to authenticate.

## Example: using environment variables

Set the variables in your shell:

```bash
export AWS_ACCESS_KEY_ID="your-access-key-id"
export AWS_SECRET_ACCESS_KEY="your-secret-access-key"
export AWS_ENDPOINT_URL="https://storage.edge.network"
```

Then use them in your code:

```js
import { S3Client } from '@aws-sdk/client-s3'

// SDK automatically picks up environment variables
const client = new S3Client({
  endpoint: process.env.AWS_ENDPOINT_URL,
  region: 'us-east-1',
  forcePathStyle: true
})
```
