Skip to main content
Weights & Biases uses pre-signed URLs to simplify access to blob storage from your AI workloads or user browsers. This page explains how pre-signed URLs work in Weights & Biases. It also outlines the access controls, network restrictions, and audit logging that administrators should configure to secure blob storage access. For background on pre-signed URLs, refer to the cloud provider’s documentation: Pre-signed URLs work as follows:
  1. When needed, AI workloads or user browser clients within your network request pre-signed URLs from Weights & Biases.
  2. Weights & Biases responds to the request by accessing the blob storage to generate the pre-signed URL with the required permissions.
  3. Weights & Biases returns the pre-signed URL to the client.
  4. The client uses the pre-signed URL to read from or write to the blob storage.
A pre-signed URL expires after the following durations:
  • Read operations: 1 hour.
  • Write operations: 24 hours, to allow more time to upload large objects in chunks.

Team-level access control

Each pre-signed URL is restricted to specific buckets based on team-level access control in the Weights & Biases platform. Consider a user who belongs to only one team, and that team is mapped to a storage bucket using the secure storage connector. In this case, the pre-signed URLs generated for their requests can’t access storage buckets mapped to other teams.
Weights & Biases recommends adding users only to the teams they need to belong to.

Network restriction

Weights & Biases recommends using IAM policies to restrict the networks that can use pre-signed URLs to access external storage. This helps ensure that only networks running your AI workloads, or gateway IP addresses that map to your user machines, can access your Weights & Biases-specific buckets. Consult your cloud provider’s documentation for guidance on configuring these IAM policies:

Audit logs

Weights & Biases recommends using Weights & Biases audit logs together with blob-storage-specific audit logs. For blob storage audit logs, refer to the documentation for each cloud provider: Admin and security teams can use audit logs to track what each user does in Weights & Biases and take action if they need to limit certain operations for specific users.
Pre-signed URLs are the only supported blob storage access mechanism in Weights & Biases. Weights & Biases recommends configuring some or all of the preceding security controls to fit your organization’s needs.

Determine the user that requested a pre-signed URL

To correlate pre-signed URL activity with specific Weights & Biases users when reviewing audit logs, inspect the provider-specific query parameter that Weights & Biases appends to each URL:

Correlate Azure Blob Storage activity with a user

Azure requires scid to be a GUID, so Weights & Biases derives a stable UUID from the username instead of including the username directly. The UUID doesn’t contain the username and you can’t decode it. To correlate Azure storage activity with a user, compute or maintain a mapping between usernames and their corresponding scid values. Azure includes scid only on user-delegation SAS URLs, which Weights & Biases generates when the storage bucket is configured with a managed identity. Shared-key SAS URLs don’t include scid.
Weights & Biases appends attribution parameters to pre-signed URLs by default. To turn off attribution for all storage providers, set the GORILLA_BUCKET_ATTRIBUTION_DISABLED environment variable to true. When attribution is off, Weights & Biases omits scid and X-User, and you can’t correlate pre-signed URL activity with individual users.
Last modified on September 30, 2026