- Frames from a video pipeline.
- Screenshots from a browser agent.
- Images a model wrote to S3.
Reference buckets are separate from the secure storage connector, which backs Weights & Biases artifact and run storage. Reference buckets are configured per team and only need read access.
How it works
Reference media rendering works in three steps:- You store a media object in your bucket, for example
s3://[YOUR-BUCKET]/frames/000123.png. - You log that URI as a string value in a span, such as a tool result.
- When you open the conversation, Agent Lens resolves the URI to a short-lived presigned URL and renders it inline. The file extension decides how it renders. Common image formats (such as
.png,.jpg, and.gif) and video formats (such as.mp4,.mov, and.webm) render inline. Other formats render as a download link.
s3:// and gs://.
Prerequisites
- A CoreWeave Forge account and API key.
- A cloud storage bucket you control (S3 or GCS), containing at least one object.
- Organization admin permissions. Adding a reference bucket requires the same permission as creating a team in the organization.
Configure your bucket
Grant CoreWeave Forge read access to the bucket, and allow the browser to fetch objects with CORS. When you view a conversation, Forge presigns a short-lived download URL for each referenced object. Grant the integration principal read access on the bucket so that presigning can succeed. This is read-only access for inline rendering.- AWS S3
- Google Cloud Storage
-
Apply a bucket policy that grants the integration principal
s3:GetObject. Save the following asbucket-policy.json, replacing[YOUR-BUCKET]with your bucket name:Then apply it to your bucket: -
Apply a CORS configuration that allows the Forge app to fetch objects in the browser. Save the following as
cors.json:Then apply it to your bucket:
If an object is encrypted with a customer-managed KMS key, its key policy must also grant
arn:aws:iam::725579432336:role/WandbIntegration kms:Decrypt. The bucket policy alone isn’t sufficient.https://wandb.ai as an allowed origin, add https://forge.coreweave.com. Without it, the browser blocks the request, and referenced media doesn’t render in Agent Lens.
Register the reference bucket
Register the bucket in your team settings so that Agent Lens can presign and display referenced URIs:- In CoreWeave Forge, select Weights & Biases from the product menu.
- In the side menu, under Teams, select your team, and then select the Settings tab. The team settings page is at
https://forge.coreweave.com/wandb/[YOUR-TEAM]/settings. - In the Reference buckets section, select Add bucket.
- Select your cloud provider (AWS or Google Cloud).
- For the bucket name, enter
[YOUR-BUCKET]only, without thes3://orgs://prefix. - For the object key, enter the key of an existing object in the bucket, for example
photos/cat.png. Enter the object key only, not a full URL. Forge reads this one object to confirm that it has read access and that CORS is configured correctly. After the bucket is verified, presigning works for any object in the bucket. - Optionally, select Test connection to validate the configuration without saving.
- Select Add bucket to save.
Log a media reference using agent spans
Return a bucket URI as an agent tool result and CoreWeave Agent Lens renders it inline in the Conversations tab, on the tool call that produced it. The following example opens a conversation, a turn, and a tool span, and sets a bucket URI as the tool’s result. Replace[YOUR-TEAM], [YOUR-PROJECT], and [YOUR-BUCKET] with your own values.
- Python
- TypeScript
This example uses Agent Lens agent spans. For the full multi-turn setup, including LLM calls and a complete agent loop, see the custom agents quickstart.