Storage

Amazon S3

Store watermarked files in your own Amazon S3 bucket. Create a limited cross-account IAM role, add the bucket as a destination, then test it.

Connect a general-purpose S3 bucket with a cross-account IAM role. This is a role in your AWS account that Etchv is allowed to use. Etchv gets short-lived credentials from it, so you don't share an AWS access key.

Create a limited role

Name the role with the prefix etchv-storage-, such as etchv-storage-production. Grant access only to your destination prefix:

JSON
{
  "Version": "2012-10-17",
  "Statement": [{
    "Effect": "Allow",
    "Action": ["s3:PutObject", "s3:GetObject"],
    "Resource": "arn:aws:s3:::YOUR_BUCKET/etchv/*"
  }]
}

Replace the bucket and prefix. Etchv does not need DeleteObject, ListBucket or ACL permissions. If the bucket uses a customer-managed KMS key for encryption, also grant kms:GenerateDataKey and kms:Decrypt. The key policy must allow this access too.

Add the destination

Use Dashboard storage or an owner/admin key with storage:write:

Shell
curl -X POST https://api.etchv.com/storage/destinations \
  -H "X-API-Key: $ETCHV_API_KEY" -H 'Content-Type: application/json' \
  -d '{"name":"Production S3","provider":"s3","bucket":"YOUR_BUCKET",
       "region":"us-east-1","prefix":"etchv","visibility":"private",
       "role_arn":"arn:aws:iam::YOUR_ACCOUNT_ID:role/etchv-storage-production"}'

The response includes id, aws_principal_arn and a unique external_id. Copy these exact values into your role’s trust policy. The trust policy says who may use the role:

JSON
{
  "Version": "2012-10-17",
  "Statement": [{
    "Effect": "Allow",
    "Principal": {"AWS": "RETURNED_AWS_PRINCIPAL_ARN"},
    "Action": "sts:AssumeRole",
    "Condition": {"StringEquals": {"sts:ExternalId": "RETURNED_EXTERNAL_ID"}}
  }]
}

Keep the external ID condition exactly as returned. It stops other Etchv customers from using your connection. See AWS third-party role access.

Test and use

  1. Click Test connection, or POST /storage/destinations/{id}/verify. Etchv writes and reads a small test file (a probe) under your prefix.
  2. Fix any trust or permission error, then verify again.
  3. Pass the destination ID in your embedding request.
VisibilityConfiguration
PrivateKeep S3 Block Public Access enabled
Already publicSet visibility: "public" to include direct URLs
Private
Configuration
Keep S3 Block Public Access enabled
Already public
Configuration
Set visibility: "public" to include direct URLs

Etchv uses your bucket’s default encryption. It never changes your bucket policy or ACLs. Conditional writes stop Etchv from overwriting objects that already exist. When a write is retried, Etchv checks the stored bytes before accepting them.

Supported S3 configurations

Etchv supports commercial AWS regions and official S3 endpoints. It does not support S3 Express directory buckets, access-point ARNs, custom S3-compatible endpoints or per-request bucket overrides. To use another bucket, create a separate destination.

View source on GitHub

Your privacy, your choice

We use essential cookies to keep Etchv working. Optional analytics helps us improve the site. Analytics is on by default; you can turn it off in preferences. PostHog loads only if you accept all. Privacy policy

ETCHV

Privacy preferences

Choose what you allow on this browser. Analytics is enabled by default. You can turn it off, and change your choice at any time.

Essential

Always active

Supports secure sign-in, account sessions, site security, and remembering your privacy choice. These are needed for Etchv to work.

Analytics

Helps us understand visits and improve the website using page-view and device statistics, which do not use cookies. PostHog also measures visits and campaigns and may set cookies; it loads only after you save a choice with analytics on. Turning this off stops future analytics events.

We do not load advertising scripts. Meeting calendars load only when you open them. These preferences do not change your account, watermarking requests, or asset storage.

Your choice is remembered for 180 days on this browser. Privacy policy