> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.instabase.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.instabase.com/_mcp/server.

# Connecting Amazon S3

> Add Amazon S3 as a data connection.

Users with workspace manager permissions or higher can connect Amazon S3 buckets to AI Hub.

## About this connection

Review the following functionality, limitations, and other considerations when connecting an Amazon S3 bucket.

* **Functionality** -- Connected Amazon S3 buckets are supported for use as a source of input files, a destination for file output, and as an upstream or downstream integration in deployments. Amazon S3 buckets can also be used as [default drives](/admin/data-sources/default-drives/).

* **Authentication** -- AI Hub supports two authentication methods for Amazon S3 buckets: AWS IAM access keys or AWS IAM roles.

* **Supported content** -- Any [supported file types](/overview/limitations/). You can specify a specific folder path as the mount point, otherwise the bucket's root directory (`/`) is mounted and all contents are accessible.

## Connecting an Amazon S3 bucket

You can connect your Amazon S3 bucket using the following authentication methods:

* [AWS IAM access key](#authenticating-with-an-aws-iam-access-key)

* [AWS IAM role](#authenticating-with-an-aws-iam-role)

### Authenticating with an AWS IAM access key

> **Before you begin**
>
> Ensure you've set up AWS IAM access key with the required permissions. For a list of permissions, see [Access key permissions requirements](#access-key-permissions-requirements).

1. In Workspaces, select a workspace to connect the drive to, then select the **Data** tab.

2. Click **Add data source**, then select **Amazon S3**.

3. Select an audience.

   * **Workspace members** (Recommended) -- Connect the drive to the selected workspace. Only members of the selected workspace have access.

   * **Organization members** -- Connect the drive at the organization level, making it available to all workspaces.

4. Enter a display name for the drive. This name can't be changed later.

5. Select **Access key** as your authentication method.

6. On the configuration screen, fill in your authentication and bucket details, then click **Next**.

   | Setting                           | Required                                                                         | Description                                                                                                                                                                                                                                                           |
   | --------------------------------- | -------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   | Access key ID                     | Required                                                                         | Your AWS IAM access key ID.                                                                                                                                                                                                                                           |
   | Secret access key                 | Required                                                                         | Your AWS IAM secret access key. Review the [permissions requirements](#access-key-permissions-requirements).                                                                                                                                                          |
   | Bucket name                       | Required                                                                         | The name of the S3 bucket to use for file storage. Provide the name, not the Amazon Resource Name (ARN).                                                                                                                                                              |
   | Region                            | Required                                                                         | The region code for your AWS account, such as `us-east-1`. For a full list of region codes, see the AWS [Regions and zones](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-regions-availability-zones.html) documentation.                                 |
   | Path to drive                     | Optional                                                                         | A file path to a folder in the S3 bucket where the desired input files are found. Leave empty to accept default (root).                                                                                                                                               |
   | Server-side encryption type       | Optional                                                                         | Select the server-side encryption (SSE) type.  • **None** -- (Default) No server-side encryption.  • **SSE-S3** -- Use Amazon-managed server-side encryption of files.  • **SSE-KMS** -- Use Amazon Key Management Service (KMS) for server-side encryption of files. |
   | Server-side encryption KMS key ID | Visible and required when **Server-side encryption type** is set to **SSE-KMS**. | The Amazon resource name (ARN) for the KMS key. See the AWS [Finding the key ID and key ARN](https://docs.aws.amazon.com/kms/latest/developerguide/find-cmk-id-arn.html) documentation for more information.                                                          |

7. Select whether to set the drive as a default drive. Not usually recommended, see [Managing default drives](/admin/data-sources/default-drives/) for details.

8. Click **Done**

#### Access key permissions requirements

The AWS IAM access key must have the following permissions:

```bash
s3:DeleteObject
s3:DeleteObjectVersion
s3:GetObject
s3:GetObjectAcl
s3:GetObjectVersion
s3:PutObject
s3:PutObjectAcl
s3:PutObjectVersion
s3:ListBucket
s3:ListBucketMultipartUploads
s3:ListMultipartUploadParts
s3:AbortMultipartUpload
```

### Authenticating with an AWS IAM role

1. In Workspaces, select a workspace to connect the drive to, then select the **Data** tab.

2. Click **Add data source**, then select **Amazon S3**.

3. Select an audience.

   * **Workspace members** (Recommended) -- Connect the drive to the selected workspace. Only members of the selected workspace have access.

   * **Organization members** -- Connect the drive at the organization level, making it available to all workspaces.

4. Enter a display name for the drive. This name can't be changed later.

5. Select **IAM role** as your authentication method, then click **Next**.

6. Connect a new role or select a previously connected role, then click **Next**.

   #### Connecting a new IAM role

   1. If previously added IAM roles are shown, click the **+** icon next to the role selection dropdown. Otherwise, you're brought to the **Add custom trust policy** screen.

   2. Copy the custom trust policy provided. Using the IAM console in the AWS Management Console, configure an IAM role using the custom trust policy. You don't need to set a permissions boundary.

      > **Note**
      >
      > See the following AWS documentation for guidance:
      >
      > * [Creating an IAM role using a custom trust policy (console)](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_create_for-custom.html)
      >
      > * [Updating a role trust policy (console)](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_update-role-trust-policy.html)

   3. Confirm the custom trust policy is added, then click **Next**.

7. On the configuration screen, fill in your authentication and bucket details, then click **Next**.

   | Setting                           | Required                                                                         | Description                                                                                                                                                                                                                                                                                                                                                      |
   | --------------------------------- | -------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   | IAM role ARN                      | Required                                                                         | The Amazon Resource Name (ARN) for the IAM role being used for authentication. See the AWS [IAM identifiers](https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_identifiers.html#identifiers-arns) and [Find Amazon Resource Names (ARNs) in AMS](https://docs.aws.amazon.com/managedservices/latest/userguide/find-arn.html) documentation for details. |
   | Bucket name                       | Required                                                                         | The name of the S3 bucket to use for file storage. Provide the name, not the ARN.                                                                                                                                                                                                                                                                                |
   | AWS region                        | Required                                                                         | The region code for your AWS account, such as `us-east-1`. For a full list of region codes, see the AWS [Regions and zones](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-regions-availability-zones.html) documentation.                                                                                                                            |
   | Path to drive                     | Optional                                                                         | A file path to a folder in the S3 bucket where the desired input files are found. Leave empty to accept default (root).                                                                                                                                                                                                                                          |
   | Server-side encryption type       | Optional                                                                         | Select the server-side encryption type.  • **None** -- (Default) No server-side encryption.  • **SSE-S3** -- Use Amazon-managed server-side encryption of files.  • **SSE-KMS** -- Use Amazon Key Management Service (KMS) for server-side encryption of files.                                                                                                  |
   | Server-side encryption KMS key ID | Visible and required when **Server-side encryption type** is set to **SSE-KMS**. | The Amazon resource name (ARN) for the KMS key. See the AWS [Finding the key ID and key ARN](https://docs.aws.amazon.com/kms/latest/developerguide/find-cmk-id-arn.html) documentation for more information.                                                                                                                                                     |

8. Copy the IAM role policy provided. Using the IAM console in the AWS Management Console, embed the policy as an inline policy for the IAM role used for authentication.

   > **Note**
   >
   > See the AWS [Adding and removing IAM identity permissions](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_manage-attach-detach.html#add-policies-console) documentation for guidance. Follow the instructions for embedding an inline policy for a user or role in the IAM console.

9. Copy the bucket policy provided. Using the Amazon S3 console in the AWS Management Console, add the bucket policy to the S3 bucket being used for storage.

   > **Note**
   >
   > See the AWS [Adding a bucket policy by using the Amazon S3 console](https://docs.aws.amazon.com/AmazonS3/latest/userguide/add-bucket-policy.html) for guidance on editing bucket policies.

10. Confirm the IAM role policy is embedded and the bucket policy is added, then click **Next**.

11. Select whether to set the drive as a default drive. Not usually recommended, see [Managing default drives](/admin/data-sources/default-drives/) for details.

12. Click **Done**

#### Managing IAM roles

After adding an IAM role, it can be reused when adding other S3 buckets. Roles added when connecting a workspace drive are reusable within the same workspace only. Roles added when connecting an organization drive are reusable across all workspaces. While other organization or workspace members can select a listed IAM role, they must have access to your AWS Management Console to complete all steps in the connection process.

**Reusing roles**

Previously connected IAM roles display in a role selection dropdown when connecting S3 buckets. When reusing a role, you don't need to add a new custom trust policy as the trust relationship is already established.

**Updating roles**

AI Hub doesn't support updating or changing the IAM role used for authentication. You can [remove](#removing-a-connection) then reconnect the bucket with a new role.

**Deleting roles**

When you delete a role, it can no longer be used for authentication. You can't delete an IAM role that's in use with a connected drive. To continue using the connection with a different role, [remove](#removing-a-connection) then reconnect the bucket with a new role.

1. In Workspaces, select a workspace, then select the **Data** tab.

2. Click **Add data source**, then select **Amazon S3**.

3. Select an audience.

4. Enter a display name for the drive.

5. Select **IAM role** as your authentication method, then click **Next**.

6. Select the role to delete, then click the delete icon ![Icon of a trash can.](/_fern-img/fde5c4ebfaee103ef10fc55c5b5119885924befbf5e79ea1da8cbf46d20448a8.webp).

7. Click **Delete** to confirm.

## Updating a connection

Select configuration changes are supported.

* **Authenticated with AWS IAM access key** -- You can update the drive’s security credentials. You must remove and reconnect the drive to change the authentication method.

* **Authenticated with AWS IAM role** -- No changes supported. You must remove and reconnect the drive to change the authentication method or change the IAM role.

1. In Workspaces, select *All workspaces*, then select the **Data** tab.

2. Click the overflow icon ![Icon with three stacked vertical dots.](/_fern-img/a83e2b40897c8c3871ed84b69fd99d990dbe0eb9bc3936ad84addb6d2ce31f95.webp) of the drive to update, then select **Modify configuration**.

3. Make any changes, then click **Update** to confirm.

## Removing a connection

You can remove a connected drive to disconnect it and revoke AI Hub's access to its contents.

> **Before you begin**
>
> Review the following limitations:
>
> * Removing a drive completely disconnects the drive from AI Hub. Any processed AI Hub files stored on the drive aren't deleted, but AI Hub loses the ability to reference those files in the future. While you can later reconnect the drive, doing so doesn't restore the ability to reference files previously saved to the drive. To reference such files, you must re-upload them.
>
> * Default drives can't be removed. For guidance on changing default drives, see [Managing default drives](/admin/data-sources/default-drives/)

1. In Workspaces, select *All workspaces*, then select the **Data** tab.

2. Click the overflow icon ![Icon with three stacked vertical dots.](/_fern-img/a83e2b40897c8c3871ed84b69fd99d990dbe0eb9bc3936ad84addb6d2ce31f95.webp) of the drive to remove, then select **Remove**.

3. Type the confirmation text, then click **Remove**.