> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.ibee.ai/docs/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ibee.ai/docs/_mcp/server.

# Core Concepts

> Core building blocks of IBEE Object Storage — buckets, objects, regions, endpoints, and access.

Before working with Object Storage it helps to understand the building blocks: **buckets**, **objects**, **regions**, **endpoints**, and **access** via API Credentials.

## Buckets

A **bucket** is a container for objects. Every object you upload lives in exactly one bucket.

* Bucket names are **globally unique** within IBEE Object Storage.
* A bucket's **location** is fixed at creation and cannot be changed — to use a different location, create a new bucket and migrate your objects.
* Use multiple buckets to separate environments, projects, or access boundaries.

Bucket names must be **3 to 63 characters**, lowercase, and contain only letters, numbers, and hyphens. They must start and end with a letter or number. See [Buckets](/docs/infrastructure/object-storage/buckets) for the full naming rules and the create flow.

## Objects

An **object** is a single file plus its metadata. Each object has:

* A **key** — the path-like name within the bucket (`reports/2026-05.pdf`).
* The object **data** — up to 5 TiB per object.
* A **type** (MIME type, e.g. `image/jpeg`) and **storage class** (`Standard`).
* System metadata — size, last-modified, ETag.

There's no real folder hierarchy — only keys with `/` separators. The portal renders prefixes as folders. See [Objects](/docs/infrastructure/object-storage/objects) for upload, download, and management.

## Regions

A **region** is a physical data center where buckets live. Pick the region closest to your users or your compute.

| Region           | Code  | Status    |
| ---------------- | ----- | --------- |
| Amaravati, India | `VGA` | Available |
| Hyderabad, India | `HYD` | Preorder  |
| Ashburn, USA     | `IAD` | Preorder  |

When creating a bucket, choose **Automatic** (Asia Pacific) for the closest available region or **Specify jurisdiction** to pin the bucket to a specific country. See [Regions & Locations](/docs/getting-started/overview/regions-and-locations).

## Endpoints

The **endpoint** is the HTTPS URL S3-compatible clients connect to. Each organization has an organization-scoped S3 endpoint:

```text
https://{workspaceId}.blob.ibeestorage.com
```

Use this with the AWS CLI, AWS SDKs, `s3cmd`, `rclone`, or any S3-compatible tool — paired with the Access Key ID and Secret Access Key from an [API Credentials](/docs/infrastructure/object-storage/api-tokens).

For browser delivery from a public bucket, use the bucket's **Public Access URL** or a **Custom Domain** instead. See [Buckets → Policies](/docs/infrastructure/object-storage/buckets/bucket-policies) and [Buckets → Custom Domains](/docs/infrastructure/object-storage/buckets/custom-domains).

## Access

To call the API programmatically you create an **API token** scoped to Object Storage. A token gives you three credentials:

| Credential        | Use                                         |
| ----------------- | ------------------------------------------- |
| Bearer Token      | The IBEE REST API                           |
| Access Key ID     | S3-compatible tools (AWS CLI, SDKs, rclone) |
| Secret Access Key | S3-compatible tools — shown once only       |

Tokens can be scoped to **all buckets** in the organization or **specific buckets only**, with permission levels ranging from `Object Read only` to `Admin Read & Write`. See [API Credentials](/docs/infrastructure/object-storage/api-tokens) for the full flow.

## Public access and Object Lock

Two bucket-level access settings control how objects can be read and written:

* **Public Access** — when enabled, objects can be served unauthenticated via the bucket's Public Access URL. Toggled from **Settings → General**.
* **Object Lock** — prevents objects from being deleted or overwritten while a retention period is in effect. **Permanent setting** that must be enabled at bucket creation under **Advanced options**. See [Objects → Locking](/docs/infrastructure/object-storage/objects/object-locking).

## Related

* [Getting started](/docs/infrastructure/object-storage/upload-your-first-object)
* [Buckets](/docs/infrastructure/object-storage/buckets)
* [Objects](/docs/infrastructure/object-storage/objects)
* [Limits](/docs/infrastructure/object-storage/limits)