Access Grants

An Access Grant is a security envelope that contains a satellite address, a restricted API Key, and a restricted path-based encryption key—everything an application needs to locate an object on the network, access that object, and decrypt it.

Learn more about Access Management and Access Grants or check out the FAQ on Access Grants and Encryption Keys.

The Access Grant screen allows you to create or delete Access Grants, and generate credentials for the Storj DCS S3-compatible Gateway from an Access Grant.

Let's start with creating an Access Grant. Click the Create Access Grant Button.

Give your Access Grant a name:

Set any access restrictions you want encoded into your Access Grant. Through the Satellite Admin Console, you can set basic restrictions on your Access Grant. You can get more sophisticated using the CLI and add further, more granular restrictions, for example, at the path prefix level within a Bucket.

Next, enter an encryption passphrase for your Access Grant. Note that this encryption passphrase is handled by the browser and is not stored by the Satellite.

Do not lose your encryption key. Storj DCS does not manage your encryption keys and if you lose your encryption passphrase and your Access Grant, you will not be able to decrypt your data.,

Copy or download your Access Grant. Do not lose it, you only have one opportunity to do so.

This Access Grant can now be used to configure tools like the Storj DCS CLI, libuplink library, or apps like Rclone, FileZilla or Restic. You can also generate credentials for the Storj DCS S3-compatible Gateway.

Remember, when you generate credentials for the Storj DCS S3-compatible Gateway from an Access Grant, you are opting in to server-side encryption.

When you generate credentials for the Storj DCS S3-compatible Gateway, the Admin Console will register your Access Grant with the Gateway auth service and display the credentials required to configure your client app to work with the Storj DCS S3-compatible Gateway.

To Delete an Access Grant, select an Access Grant and choose Remove Selected:

Then confirm that you want to delete the Access Grant.

Important: If you delete an Access Grant from the Satellite user interface, that Access Grant will immediately cease to function, and all hierarchically derived child Access Grants and Storj DCS gateway access credentials based on that Access Grant will also cease to function. Any data uploaded with that Access Grant will persist on Storj DCS. If you didn't back up the encryption passphrase used with the Access Grant you are deleting, you will not be able to decrypt that data without that encryption passphrase, and it will be effectively unrecoverable.

You don't need to know everything in the whitepaper about our Access Grants, macaroon-based API Keys or our encryption implementation, but if you understand the general principles, you'll find these are some very sophisticated (but easy to use) tools for creating more secure and private applications.

Next we'll cover adding and removing other developers to and from your project.