---
title: S3 API
description: Use S3 tools with an API key: the endpoint, the signing region, path-style addressing, and the S3 operations that storage supports.
doc_version: 0.1.0-preview
last_updated: 2026-09-14
---

# S3 API

Use S3 tools with an API key: the endpoint, the signing region, path-style addressing, and the S3 operations that storage supports.

## Connection

- Endpoint: https://g4.beta.graphon.ai
- Region: us-east-1 (a signing region only; data stays in the bucket's location)
- Addressing: path style, /{bucket}/{key}
- Access key ID: the part of the API key between the `_` and the `.`
- Secret access key: the whole API key
- `graphon s3-credentials` prints these values for the AWS tools.

## Operations

Role is the lowest role whose key can send the request. An unsupported
operation returns 501 NotImplemented.

| Operation | Request | Role | Supported | Notes | Example |
| --- | --- | --- | --- | --- | --- |
| ListBuckets | `GET /` | Viewer | supported | Lists the buckets in the key's workspace, in name order. | `aws s3 ls` |
| CreateBucket | `PUT /{bucket}` | Editor | supported | Send LocationConstraint as provider:location, for example gcp:us-central1. A new bucket is private and standard class. | `aws s3api create-bucket --bucket support-tickets --create-bucket-configuration LocationConstraint=gcp:us-central1` |
| HeadBucket | `HEAD /{bucket}` | Viewer | supported | Finds an active or offline bucket, and returns the signing region. | `aws s3api head-bucket --bucket support-tickets` |
| DeleteBucket | `DELETE /{bucket}` | Editor | supported | The bucket must be empty. It stays restorable for seven days. | `aws s3 rb s3://support-tickets` |
| GetBucketLocation | `GET /{bucket}?location` | Viewer | supported | Returns us-east-1, the signing region. The JSON API reports the real location. | `aws s3api get-bucket-location --bucket support-tickets` |
| GetBucketVersioning | `GET /{bucket}?versioning` | Viewer | supported | Returns empty, Enabled, or Suspended. | `aws s3api get-bucket-versioning --bucket support-tickets` |
| PutBucketVersioning | `PUT /{bucket}?versioning` | Editor | partial | Enabled or Suspended. MFA delete is rejected. | `aws s3api put-bucket-versioning --bucket support-tickets --versioning-configuration Status=Enabled` |
| ListMultipartUploads | `GET /{bucket}?uploads` | Viewer | supported | Lists uploads that are not complete yet. | `aws s3api list-multipart-uploads --bucket support-tickets` |
| GetObjectLockConfiguration | `GET /{bucket}?object-lock` | Viewer | supported | Returns the default retention for new versions. | `aws s3api get-object-lock-configuration --bucket support-tickets` |
| PutObjectLockConfiguration | `PUT /{bucket}?object-lock` | Editor | partial | COMPLIANCE mode with a default in days. Years, GOVERNANCE, and legal hold return 501. | `aws s3api put-object-lock-configuration --bucket support-tickets --object-lock-configuration '{"ObjectLockEnabled":"Enabled","Rule":{"DefaultRetention":{"Mode":"COMPLIANCE","Days":30}}}'` |
| DeleteObjects | `POST /{bucket}?delete` | Editor | supported | Up to 1,000 keys. Each key gets its own result. Quiet mode works. | `aws s3api delete-objects --bucket support-tickets --delete '{"Objects":[{"Key":"a.json"},{"Key":"b.json"}]}'` |
| ListObjectVersions | `GET /{bucket}?versions` | Viewer | supported | Lists live versions and delete markers, with key and version markers. | `aws s3api list-object-versions --bucket support-tickets` |
| ListObjectsV2 | `GET /{bucket}?list-type=2` | Viewer | supported | prefix, delimiter, continuation-token, start-after, max-keys, and encoding-type. | `aws s3 ls s3://support-tickets/incidents/` |
| ListObjects | `GET /{bucket}` | Viewer | supported | The legacy listing, with marker pagination. | `aws s3api list-objects --bucket support-tickets` |
| GetObjectRetention | `GET /{bucket}/{key}?retention` | Viewer | supported | Returns the retention of the selected version. | `aws s3api get-object-retention --bucket support-tickets --key a.json` |
| PutObjectRetention | `PUT /{bucket}/{key}?retention` | Editor | partial | COMPLIANCE only. Retention can be added or extended, never shortened. | `aws s3api put-object-retention --bucket support-tickets --key a.json --retention Mode=COMPLIANCE,RetainUntilDate=2027-01-01T00:00:00Z` |
| GetObjectTagging | `GET /{bucket}/{key}?tagging` | Viewer | supported | Returns the tags of the live version. | `aws s3api get-object-tagging --bucket support-tickets --key a.json` |
| PutObjectTagging | `PUT /{bucket}/{key}?tagging` | Editor | supported | Replaces the whole tag set. | `aws s3api put-object-tagging --bucket support-tickets --key a.json --tagging 'TagSet=[{Key=team,Value=support}]'` |
| DeleteObjectTagging | `DELETE /{bucket}/{key}?tagging` | Editor | supported | Empties the tag set. | `aws s3api delete-object-tagging --bucket support-tickets --key a.json` |
| CreateMultipartUpload | `POST /{bucket}/{key}?uploads` | Editor | supported | Starts an upload. aws s3 cp uses multipart for large files. | `aws s3 cp ./big.bin s3://support-tickets/big.bin` |
| UploadPartCopy | `PUT /{bucket}/{key}?partNumber&uploadId with x-amz-copy-source` | Editor | partial | The source needs the Viewer role and must be in the same workspace. One byte range per part. |  |
| UploadPart | `PUT /{bucket}/{key}?partNumber&uploadId` | Editor | supported | Returns the part ETag. Every part except the last must be the same size. |  |
| ListParts | `GET /{bucket}/{key}?uploadId` | Viewer | supported | Lists the parts of one upload, in part order. |  |
| CompleteMultipartUpload | `POST /{bucket}/{key}?uploadId` | Editor | supported | Send the parts in ascending order with their exact ETags. |  |
| AbortMultipartUpload | `DELETE /{bucket}/{key}?uploadId` | Editor | supported | Safe to send twice. |  |
| CopyObject | `PUT /{bucket}/{key} with x-amz-copy-source` | Editor | partial | The source needs the Viewer role and must be in the same workspace. A copy across storage providers returns 501. | `aws s3 cp s3://support-tickets/a.json s3://support-tickets/b.json` |
| PutObject | `PUT /{bucket}/{key}` | Editor | supported | One request can carry at most 200 MiB. Send x-amz-checksum-sha256 to have G4 check the bytes. If-None-Match: * creates only. | `aws s3 cp ./a.json s3://support-tickets/a.json` |
| HeadObject | `HEAD /{bucket}/{key}` | Viewer | supported | The same headers as GetObject, with no body. A public-read bucket needs no signature. | `aws s3api head-object --bucket support-tickets --key a.json` |
| GetObject | `GET /{bucket}/{key}` | Viewer | partial | Supports versionId, conditions, and one byte range. Multiple ranges return 501. A public-read bucket needs no signature. | `aws s3 cp s3://support-tickets/a.json ./a.json` |
| DeleteObject | `DELETE /{bucket}/{key}` | Editor | supported | With versionId, removes that version. In a versioned bucket, adds a delete marker. | `aws s3 rm s3://support-tickets/a.json` |
| Options | `OPTIONS /{bucket}/{key}` | — | supported | CORS preflight only. It reads and changes nothing. |  |
| BucketWebsiteCorsLifecycle | `GET /{bucket}?website` | — | unsupported | Website, CORS, and lifecycle configuration return 501. |  |
| ObjectAcl | `GET /{bucket}/{key}?acl` | — | unsupported | Object ACLs return 501. Use the bucket permission in the JSON API. |  |
| ObjectLegalHold | `GET /{bucket}/{key}?legal-hold` | — | unsupported | Legal hold returns 501. |  |
| SelectObjectContent | `POST /{bucket}/{key}?select` | — | unsupported | S3 Select returns 501. |  |
| ServerSideEncryptionWithCustomerKeys | `PUT /{bucket}/{key} with x-amz-server-side-encryption-customer-algorithm` | — | unsupported | SSE-C returns 501. Providers encrypt every object at rest. |  |

## Sitemap

See the full [sitemap](/sitemap.md) for all pages.
