Generates a new Object Storage access key and an associated secret key, for use with customer key-based encryption (SSE-C). The secret key is only displayed when the access key is generated and can't be viewed again. A successful request triggers an obj_access_key_create event.
Between October 6, 2026 and November 16, 2026, server-side encryption with Akamai-managed keys (also referred to as "SSE-S3") will be enabled by default for all E2 and E3 endpoints. If your workflow requires it, you can still manually create and apply SSE-C keys. These keys will take precedence over the default-created SSE-S3 keys. Existing SSE-C keys you've set up for your endpoints will still be valid. See Default encryption at rest (SSE-S3) for complete details.
If your account has a negative balance, you can't access this operation.
This operation has specific rate limits.
Unlimited vs. limited access keys
An unlimited access key grants full access to all of your buckets in each region you name, using the regions array. A limited access key lets you name specific buckets where you need to manage content, using the bucket_access array.
There's a tutorialWe offer workflows for both an unlimited access key and a limited access key.
Permissions and scopes
To call this operation, you need the following:
-
OAuth scopes. Your user needs these scopes assigned. Learn more.
- Scopes:
object_storage:read_write
- Scopes:
CLI
linode-cli object-storage keys-create \
--label "my-object-storage-key" \
--bucket_access '[{"region": "ap-south", "bucket_name": "bucket-example-1", "permissions": "read_write" }]'