Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • Yandex SIEM
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Object Storage
    • All guides
      • Creating a bucket
      • Deleting a bucket
      • Limiting the maximum size of a bucket
      • Encrypting a bucket
      • Managing object lifecycles
      • Managing CORS configurations
      • Configuring access permissions using IAM
      • Editing a bucket's ACL
      • Managing access policies
      • Configuring public access to a bucket
      • Disabling access with static keys
      • Accessing a bucket using Security Token Service
      • Accessing a bucket with an ephemeral access key
      • Accessing a bucket using a service connection from VPC
      • Searching for sensitive data in a bucket
      • Managing bucket versioning
      • Enabling logging
      • Managing object locks
      • Managing object metadata export
      • Managing bucket labels
      • Getting a list of buckets
      • Getting bucket information and statistics
      • Viewing bucket metrics
  • Pricing policy
  • Terraform reference
  • Monitoring metrics
  • Audit Trails events
  • Bucket logs
  • Release notes
  • FAQ
  1. Step-by-step guides
  2. Buckets
  3. Accessing a bucket using Security Token Service

Accessing a bucket using Security Token Service

Written by
Yandex Cloud
Updated at September 23, 2026
View in Markdown

With Security Token Service restricted, you can get temporary keys for access to Yandex Object Storage buckets.

Authentication with temporary access keys is only supported in Object Storage.

You must have at least the following roles:

  • iam.serviceAccounts.admin for a folder to create a service account and get access keys for it. If you want to use an existing service account, the iam.serviceAccounts.admin role for that service account will be enough.

  • storage.admin for a bucket or folder to assign the required role to the service account. Alternatively, you can use the FULL_CONTROL permission in the bucket's ACL.

If you have a primitive admin role for a folder, you do not need to assign any additional roles.

To get a temporary access key:

  1. Create a service account. You can also use an existing service account.

  2. Assign it the required role, e.g., storage.viewer, for the bucket or folder you want to access with a temporary key.

    Note

    Assign a role for a folder if you want to have access to all buckets in the folder using the service account.

    The selected role must include all the permissions you want to grant using temporary keys.

    Tip

    If a service account has roles in Object Storage for a folder, users with temporary keys will get view access to buckets in that folder. We recommend assigning service account roles for specific buckets, rather than the folder.

    Alternatively, you can use ACL permissions for the bucket.

  3. Create a static access key for the service account.

  4. Install and configure the AWS Command Line Interface (AWS CLI).

  5. Describe the bucket policy configuration as a data schema in JSON format.

    Warning

    One Security Token Service access policy is set only for a specific bucket. You cannot use a single temporary key for multiple buckets.

    Temporary Security Token Service keys inherit the access permissions of the service account but are limited by the bucket-level access policy. If you set up a temporary key’s access policy to allow operations the service account has no permissions for, such operations will not be performed.

    Policy example

    This policy allows a temporary key user to get objects from the specified bucket prefix:

    {
      "Version": "2012-10-17",
      "Statement": {
        "Sid": "all",
        "Effect": "Allow",
        "Principal": "*",
        "Action": "s3:GetObject",
        "Resource": "arn:aws:s3:::<bucket_name>/<prefix>"
      }
    }
    

    Where:

    • Version: Version of the bucket policy description, e.g., 2012-10-17. This is an optional property.

    • Statement: Bucket policy rules:

      • Sid: Custom rule ID, e.g., all. Statement Allow, or Statement Deny. This is an optional property.

      • Effect: Denies or allows the requested action. The possible values are Allow and Deny.

      • Principal: Valid value is *. This setting is required for compatibility with the AWS S3 API.

      • Action: Action to perform when the policy triggers, e.g., s3:GetObject, s3:PutObject, or *.

      • Resource: Resource to perform the action with. The valid values are:

        • arn:aws:s3:::<bucket_name>: Bucket.
        • arn:aws:s3:::<bucket_name>/<object_key>: Bucket object.
        • arn:aws:s3:::<bucket_name>/<prefix>*: All objects in the bucket whose keys start with a prefix, e.g., arn:aws:s3:::samplebucket/some/path/*. A prefix can be empty, e.g., arn:aws:s3:::samplebucket/*, in which case the rule will apply to all bucket objects.

        A bucket resource does not include resources of all its objects. To make sure a bucket policy rule applies to the bucket and all its objects, specify them as separate resources, e.g., arn:aws:s3:::samplebucket and arn:aws:s3:::samplebucket/*.

      If you apply a bucket policy without rules when creating temporary access keys, access with a temporary key will be denied.

    Save the final configuration to a file named policy.json.

    Warning

    The access is checked against the object ACL after the Security Token Service policy check. Therefore, if the service account you are using to obtain temporary access keys has ACL permissions configured for objects in the bucket, those objects will become available for temporary access key requests, regardless of the specified policy. For more information, see the Object Storage access management mechanisms diagram.

  6. Get a temporary access key:

    AWS CLI

    Run this command:

    aws --endpoint https://sts.yandexcloud.net/ sts assume-role \
      --role-arn <description> \
      --role-session-name <key_name> \
      --duration-seconds <key_lifetime> \
      --policy file://policy.json
    

    Where:

    • --endpoint: Security Token Service endpoint.
    • --role-arn: Custom description of at least 20 characters. You can use Latin letters, numbers, _ and -.
    • --role-session-name: Unique key name. You can use Latin letters, numbers, _ and -.
    • --duration-seconds: Key lifetime in seconds, which cannot exceed 43200.
    • --policy file://: Path to the bucket policy file.

    For more information about the aws sts assume-role command, see this AWS guide.

    Result:

    {
        "Credentials": {
            "AccessKeyId": "YCAJEkNuezZyt4b**********",
            "SecretAccessKey": "YCMUWwxFAnZ**********...",
            "SessionToken": "s1.9euelZqPjcj**********...",
            "Expiration": "2024-02-29T23:30:53+00:00"
        },
        "AssumedRoleUser": {
            "Arn": "a1234567891234567890/test-2"
        },
        "PackedPolicySize": 0,
        "SourceIdentity": ""
    }
    

    Where:

    • AccessKeyId: Key ID (same as the static key ID).
    • SecretAccessKey: Secret key.
    • SessionToken: Session token.

    Save these parameters.

  7. Set the temporary access key parameters as environment variables for the user you want to grant bucket access permissions:

    export AWS_ACCESS_KEY_ID=<key_ID>
    export AWS_SECRET_ACCESS_KEY=<secret_key>
    export AWS_SESSION_TOKEN=<session_token>
    
  8. To test access to the bucket, save an object from the bucket prefix you granted access to on the client device:

    AWS CLI
    aws --endpoint https://storage.yandexcloud.net s3 cp \
      s3://<bucket_name>/<prefix><object_name> ./
    

    Result:

    download: s3://<bucket_name>/<prefix><object_name> to ./<object_name>
    

Useful linksUseful links

  • Access management methods in Object Storage: Overview
  • Accessing a bucket using an ephemeral access key

Was the article helpful?

Previous
Disabling access with static keys
Next
Accessing a bucket with an ephemeral access key
© 2026 Direct Cursus Technology L.L.C.