Object Storage Admin IAM role or the cwobject:CreateAccessKey action granted through an organization access policy.
For production workloads, use Workload Identity Federation instead of Cloud Console keys. WIF issues short-lived keys from your identity provider, so credentials never need to be stored or rotated.
For full setup steps, see Create access keys.
Administrator Authentication & Access