Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Identity and Access Management
    • Overview
      • How to choose the correct authentication method
      • IAM token
      • API key
      • Static access key
      • Security Token Service
      • Ephemeral keys
      • Authorized key
      • OAuth token
      • ID token
      • Cookie
      • Refresh token
    • Service access to user resources
    • Identity federations
    • Workload identity federations
    • Quotas and limits
  • Secure use of Yandex Cloud
  • Access management
  • Pricing policy
  • Role reference
  • Terraform reference
  • Monitoring metrics
  • Audit Trails events
  • Release notes

In this article:

  • Static key format
  • Key ID
  • Secret key
  • Services that support this authentication method
  • Use cases
  1. Concepts
  2. Authentication
  3. Static access key

Static access keys compatible with the AWS API

Written by
Yandex Cloud
Updated at July 8, 2026
View in Markdown
  • Static key format
    • Key ID
    • Secret key
  • Services that support this authentication method
  • Use cases

Note

Creating static access keys for service accounts may be prohibited by access policies at the folder, cloud, or organization level.

A static access key is required to authenticate a service account in AWS-compatible APIs.

It consists of two parts:

  • Key ID
  • Secret key

Both parts are used in requests to the AWS-compatible API. A key ID is specified in open format. A secret key is used to sign request parameters and is not specified in the request.

It is the client's responsibility to store the secret key. Yandex Cloud gives access to it only when creating a static key.

A static key has no expiration date.

Alert

Make sure no third party has access to your secret key. Keep your key in a secure location. If your key has become known to a third party, reissue it.

To ensure security and control over access to resources, monitor cases of unauthorized use of keys, and delete unused keys without the risk of disrupting Yandex Cloud services, you can track the dates of last use of service account access keys. You can find this info on the service account page in the management console or in the last_used_at field when using the API to invoke access key management methods.

In addition to static access keys, you can use Security Token Service temporary keys, also compatible with the AWS API, to work with Yandex Object Storage.

Static key formatStatic key format

Key IDKey ID

A key ID consists of 25 characters and always starts with YC. Other characters may include:

  • Latin letters.
  • Numbers.
  • Underscores (_) and hyphens (-).

Here is an example of a key ID: YCchbYEDdcsYFBnxSWbcjDJDn.

Secret keySecret key

A secret key consists of 40 characters and always starts with YC. Other characters may include:

  • Latin letters.
  • Numbers.
  • Underscores (_) and hyphens (-).

Here is an example of a secret key: YCVdheub7w9bImcGAnd3dZnf08FRbvjeUFvehGvc.

For an example of using a secret key and its ID in an AWS-compatible API, see the AWS Command Line Interface section.

Services that support this authentication methodServices that support this authentication method

The following services support authentication based on static access keys:

  • Object Storage
  • Message Queue
  • Managed Service for YDB
  • Yandex Data Streams
  • Yandex Cloud Postbox

Use casesUse cases

  • Using a Yandex Lockbox secret to store a static access key

Useful linksUseful links

  • Creating a static access key
  • How to choose a suitable authentication method in Yandex Cloud
  • Security Token Service
  • Using a Yandex Lockbox secret to store a static access key

Was the article helpful?

Previous
API key
Next
Security Token Service
© 2026 Direct Cursus Technology L.L.C.