Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Object Storage
    • Overview
    • Identity and Access Management
    • Access control list (ACL)
    • Bucket policy
    • Public access
    • Pre-signed URLs
    • Security Token Service
    • Ephemeral keys
  • Pricing policy
  • Terraform reference
  • Monitoring metrics
  • Audit Trails events
  • Bucket logs
  • Release notes
  • FAQ

In this article:

  • Ephemeral key format
  • Key ID
  • Secret key
  • Session token
  1. Access management
  2. Ephemeral keys

Ephemeral access keys compatible with AWS APIs

Written by
Yandex Cloud
Updated at July 23, 2026
View in Markdown
  • Ephemeral key format
    • Key ID
    • Secret key
    • Session token

Ephemeral access keys are temporary credentials for authenticating Yandex accounts, federated accounts, local users, and service accounts.

Note

Creating ephemeral access keys for service accounts may be prohibited by access policies at the folder, cloud, or organization level.

Authentication with ephemeral access keys is only supported in Yandex Object Storage.

You can create an ephemeral key for the current user or for a service account you have access to.

Ephemeral keys are issued based on the current session's IAM token. They may be valid from 15 minutes to 12 hours. If lifetime is not set during creation, it is limited to the IAM token's validity period.

Warning

You cannot revoke an ephemeral key. It automatically expires after its lifetime.

To set up access permissions for the key, you need an access policy in JSON format based on this schema.

Tip

If a service account has roles in Object Storage for a folder, users with temporary keys will get view access to buckets in that folder. We recommend assigning service account roles for specific buckets, rather than a folder.

Ephemeral key formatEphemeral key format

Ephemeral keys consist of three parts:

  • Key ID
  • Secret key
  • Session token

Requests to the AWS-compatible API use all the three parts. The key ID is specified in open format. The secret key is used to sign request parameters, and the session token serves to verify temporary credentials.

Key IDKey ID

Consists of 20 characters. These characters may include:

  • Latin letters
  • Numbers

Here is an example of a key ID: abcdefg1234h********.

Secret keySecret key

A secret key consists of 43 characters and always starts with YC. Other characters may include:

  • Latin letters
  • Numbers
  • Underscores (_) and hyphens (-)

Here is an example of a secret key: YCabcdefg1234hi5678jk9AbCdEfG1234hI********.

Session tokenSession token

The session token has a variable length of approximately 285 characters and is used to verify temporary credentials. Token example: s1.9muilY....

Useful linksUseful links

  • Access management methods in Object Storage: Overview
  • Security Token Service
  • Accessing a bucket using an ephemeral access key

Was the article helpful?

Previous
Security Token Service
Next
Pricing policy
© 2026 Direct Cursus Technology L.L.C.