v4

OpenAPI 3.1.02026-08-01166346466.7 KB
buckets

Rotate bucket credentials

Replace a bucket's stored credentials.

Only available for access_key buckets — assume_role buckets store no credentials (manage access via the role's trust policy instead). The new credentials are re-validated against the bucket's existing (immutable) identity before they are persisted. The credentials version is bumped so cached storage clients rebuild.

Args: bucket_id: The ID of the bucket to rotate credentials for. params: The new bucket access credentials.

Returns: Bucket: The updated bucket. Credentials are never returned.

post/v1/buckets/{bucket_id}/credentials

Path parameters

bucket_idstring uuid required

The ID of the bucket to rotate credentials for

The ID of the bucket to rotate credentials for

Request body

Response

The bucket with rotated credentials

idstring required

The ID of the bucket

created_atstring date-time required

Creation time

updated_atstring date-time required

Last update time

namestring required

Display name

provider'aws_s3' required

Object-storage provider backing a bring-your-own bucket.

bucketstring required

The bucket name

regionstring nullable required

The bucket region

endpoint_urlstring nullable required

Custom S3-compatible endpoint

prefixstring required

Key prefix within the bucket

sse_kms_key_idstring nullable required

KMS key id/ARN used to encrypt writes (SSE-KMS)

auth_type'assume_role' | 'access_key' required

How omni authenticates against a customer bucket.

ASSUME_ROLE is the recommended default for AWS: nothing secret is stored, every service assumes the customer's IAM role via STS on use. ACCESS_KEY remains for S3-compatible providers that have no STS.

role_arnstring nullable required

IAM role Mixedbread assumes (auth_type=assume_role); not a secret

external_idstring nullable required

sts:ExternalId the role's trust policy must require (auth_type=assume_role); not a secret

status'pending' | 'active' | 'error' required

Validation lifecycle of a customer bucket.

last_validated_atstring date-time nullable required

When the bucket was last validated

has_credentialsboolean required

Whether secret credentials are stored (always false for assume-role buckets)

credentials_versioninteger required

Increments on every credential rotation

object'bucket'

The type of the object