Skip to main content
Before you start using CoreWeave AI Object Storage, you must set up access tokens, access keys, and organization access policies. Organization access policies authorize principals in your organization. Add a bucket access policy when you need to control a specific resource, including access from other organizations. For more information, see Policy evaluation. The Object Storage API lets you manage access keys and policies programmatically, while the Object Storage S3 endpoint lets you create and manage buckets and objects. For production workloads, CoreWeave recommends Workload Identity Federation (WIF) to obtain Access Keys. It exchanges short-lived OpenID Connect (OIDC) tokens for temporary credentials, which eliminates the need to store or rotate long-lived static keys. If a principal already authenticates with a CoreWeave API access token, CoreWeave recommends exchanging that token directly for temporary credentials instead of creating a separate static Access Key. This method also carries the principal’s SCIM group memberships, which you can use for group-based and attribute-based access control. See Direct access token exchange. The following diagram outlines how to choose an authentication and management approach for Object Storage: Use OIDC WIF by default for production workloads. If your organization must use SAML for workload authentication, contact your CoreWeave account team.

Authentication summary table

This table summarizes the authentication required to use each Object Storage API and interface:
Last modified on October 8, 2026