Storage
Azure Blob Storage
Store watermarked files in your own Azure Blob Storage container. Create a scoped SAS token, connect and verify it, and renew access before it expires.
Connect an Azure Blob container with a container-scoped SAS token. A SAS (shared access signature) token is a signed string that grants limited access to one container. Etchv delivers verified files without changing their format or your container’s access policy.
Create a container SAS
Use a dedicated container in a standard Azure public-cloud account.
| Setting | Required value |
|---|---|
| Resource | Container: sr=c |
| Permissions | Read, create, write: sp=rcw |
| Protocol | HTTPS only: spr=https |
| Expiry | A date within your rotation policy |
- Resource
- Required value
- Container:
sr=c
- Permissions
- Required value
- Read, create, write:
sp=rcw
- Protocol
- Required value
- HTTPS only:
spr=https
- Expiry
- Required value
- A date within your rotation policy
Use a user-delegation SAS when you can. It is valid only as long as its delegation key, and never longer than seven days. Etchv does not support account keys, connection strings, account-wide SAS, URLs or private endpoints. See Microsoft’s SAS overview.
Connect and verify
Choose Azure Blob Storage in Dashboard storage, or send this to POST with a storage:write owner/admin key:
{
"name": "Production Azure",
"provider": "azure",
"account": "YOUR_STORAGE_ACCOUNT",
"bucket": "watermarked-assets",
"prefix": "etchv",
"visibility": "private",
"credentials": "sv=...&sr=c&sp=rcw&spr=https&se=...&sig=..."
}Send only the SAS query string. It may start with ?. Click Test connection, or call POST . Etchv checks write and read access. Tokens are encrypted and never returned in responses or URLs.
Store and retrieve
Pass the destination ID in an embedding request. Etchv writes a block blob (Azure’s standard file type). It never overwrites a file that holds different bytes.
| Visibility | Returned location |
|---|---|
| Private | azure:; download with Azure credentials or Etchv’s authenticated proxy |
| Already public | Also includes https:, without a SAS |
- Private
- Returned location
azure:; download with Azure credentials or Etchv’s authenticated proxy/ /account /container /key
- Already public
- Returned location
- Also includes
https:, without a SAS/ /account. blob. core. windows. net /container /key
Etchv does not change anonymous access settings. It never sends the token that can write to your container to a browser. Your container controls how long files are kept.
Renew access before expiry
- Check
credential_expires_atin the API or dashboard. It shows whichever expires first: the SAS or the delegation key. - Replace
credentialswithPATCH, or Storage → Details → Replace credentials./storage /destinations /{id} - Test the connection again. Within 30 days, retry any deliveries that ran out of attempts.
You can't save a token that has expired or is not valid yet. An expired destination cannot receive new jobs. Downloads through Etchv also need valid credentials, even when the file still exists in Azure.
Generate a user-delegation SAS with Azure CLI
After signing in with an authorized identity:
az storage container generate-sas \
--account-name YOUR_STORAGE_ACCOUNT \
--name watermarked-assets \
--auth-mode login --as-user \
--permissions rcw --https-only \
--expiry YOUR_UTC_EXPIRY --output tsvGrant blob read/write access on the container and delegation-key access on the storage account. A custom role scoped to the container, plus Storage Blob Delegator, avoids granting general storage admin rights. Keep tokens out of logs and source control. See Microsoft’s user-delegation guide.
Account-key authentication can stay disabled. Your pipeline can use GitHub OIDC to create new tokens. The Etchv connection still uses the SAS you supply. Direct Azure workload identity is not supported.