How it works
A key made for one drawer.
It opens that space and nothing else. Change its permissions, or take it back, whenever you want.
One space
A space is a named place your files live in — a bucket, on normal S3 storage. A key is made for one of them, not carved out of something bigger.
What a key can do
Pick one. Nothing moves on its own, and every state below is written out in full whether or not you press anything.
Read-only. The drawer is shut, and the key in it goes nowhere else.
Taking a key back
One action. It stops working immediately, everywhere, including anything already running. Nothing rebuilds. The old key stays in your records, so you can see when it stopped.
This is the step that gets postponed when you store keys yourself, because there it is a rebuild.
The building
Your real storage credentials live with ScopeFS and are never handed out. Your app holds a key that opens one drawer — only ever the small one.
If you’d rather use S3 directly
Some teams would rather not go through a key at all and would rather talk to storage the ordinary way. You can. The same rules apply — your key still opens one space and can still be taken back — and the tools you already use work unchanged. See the commands.