Storage

Azure Blob Storage

Store watermarked files in your own Azure Blob Storage container. Create a scoped SAS token, connect and verify it, and renew access before it expires.

Connect an Azure Blob container with a container-scoped SAS token. A SAS (shared access signature) token is a signed string that grants limited access to one container. Etchv delivers verified files without changing their format or your container’s access policy.

Create a container SAS

Use a dedicated container in a standard Azure public-cloud account.

SettingRequired value
ResourceContainer: sr=c
PermissionsRead, create, write: sp=rcw
ProtocolHTTPS only: spr=https
ExpiryA date within your rotation policy
Resource
Required value
Container: sr=c
Permissions
Required value
Read, create, write: sp=rcw
Protocol
Required value
HTTPS only: spr=https
Expiry
Required value
A date within your rotation policy

Use a user-delegation SAS when you can. It is valid only as long as its delegation key, and never longer than seven days. Etchv does not support account keys, connection strings, account-wide SAS, URLs or private endpoints. See Microsoft’s SAS overview.

Connect and verify

Choose Azure Blob Storage in Dashboard storage, or send this to POST /storage/destinations with a storage:write owner/admin key:

JSON
{
  "name": "Production Azure",
  "provider": "azure",
  "account": "YOUR_STORAGE_ACCOUNT",
  "bucket": "watermarked-assets",
  "prefix": "etchv",
  "visibility": "private",
  "credentials": "sv=...&sr=c&sp=rcw&spr=https&se=...&sig=..."
}

Send only the SAS query string. It may start with ?. Click Test connection, or call POST /storage/destinations/{id}/verify. Etchv checks write and read access. Tokens are encrypted and never returned in responses or URLs.

Store and retrieve

Pass the destination ID in an embedding request. Etchv writes a block blob (Azure’s standard file type). It never overwrites a file that holds different bytes.

VisibilityReturned location
Privateazure://account/container/key; download with Azure credentials or Etchv’s authenticated proxy
Already publicAlso includes https://account.blob.core.windows.net/container/key, without a SAS
Private
Returned location
azure://account/container/key; download with Azure credentials or Etchv’s authenticated proxy
Already public
Returned location
Also includes https://account.blob.core.windows.net/container/key, without a SAS

Etchv does not change anonymous access settings. It never sends the token that can write to your container to a browser. Your container controls how long files are kept.

Renew access before expiry

  1. Check credential_expires_at in the API or dashboard. It shows whichever expires first: the SAS or the delegation key.
  2. Replace credentials with PATCH /storage/destinations/{id}, or Storage → Details → Replace credentials.
  3. Test the connection again. Within 30 days, retry any deliveries that ran out of attempts.

You can't save a token that has expired or is not valid yet. An expired destination cannot receive new jobs. Downloads through Etchv also need valid credentials, even when the file still exists in Azure.

Generate a user-delegation SAS with Azure CLI

After signing in with an authorized identity:

Shell
az storage container generate-sas \
  --account-name YOUR_STORAGE_ACCOUNT \
  --name watermarked-assets \
  --auth-mode login --as-user \
  --permissions rcw --https-only \
  --expiry YOUR_UTC_EXPIRY --output tsv

Grant blob read/write access on the container and delegation-key access on the storage account. A custom role scoped to the container, plus Storage Blob Delegator, avoids granting general storage admin rights. Keep tokens out of logs and source control. See Microsoft’s user-delegation guide.

Account-key authentication can stay disabled. Your pipeline can use GitHub OIDC to create new tokens. The Etchv connection still uses the SAS you supply. Direct Azure workload identity is not supported.

View source on GitHub

Your privacy, your choice

We use essential cookies to keep Etchv working. Optional analytics helps us improve the site. Analytics is on by default; you can turn it off in preferences. PostHog loads only if you accept all. Privacy policy

ETCHV

Privacy preferences

Choose what you allow on this browser. Analytics is enabled by default. You can turn it off, and change your choice at any time.

Essential

Always active

Supports secure sign-in, account sessions, site security, and remembering your privacy choice. These are needed for Etchv to work.

Analytics

Helps us understand visits and improve the website using page-view and device statistics, which do not use cookies. PostHog also measures visits and campaigns and may set cookies; it loads only after you save a choice with analytics on. Turning this off stops future analytics events.

We do not load advertising scripts. Meeting calendars load only when you open them. These preferences do not change your account, watermarking requests, or asset storage.

Your choice is remembered for 180 days on this browser. Privacy policy