Sure! Here’s how you can create and retrieve your Wasabi credentials (Access Key & Secret Key) for using with Wasabi S3-compatible object storage, similar to AWS S3.
1. Create a Wasabi Account
- Go to: https://wasabi.com/sign-up/
- Create a free trial or paid account.
- Log in to: https://console.wasabisys.com
2. Create an Access Key & Secret Key (like AWS IAM)
- In the Wasabi console, go to the left menu:
- Click on Access Keys
- Select:
- Root Account (or create a User via IAM for better security)
- Click Create New Access Key
- Copy:
- Access Key (like
WASABIEXAMPLEKEY) - Secret Key (like
wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY)
- Access Key (like
Save these immediately — the Secret Key is shown only once.
3. Create a Bucket
Follow these steps to create a storage bucket and configure public read access.
Step 1: Create the Bucket
- Go to the Buckets tab.
- Click Create Bucket.
- Enter the following details:
- Bucket Name
Example:next3-test-bucket - Region
Example:us-east-1,ap-northeast-1, etc.
- Bucket Name
- Click Create to finish creating the bucket.
Step 2: Configure Bucket Permissions
- Open the newly created bucket.
- Navigate to Settings → Permissions.
- Click Edit to modify the bucket policy.
- Add the policy below and replace
bucket-namewith your actual bucket name. - Save the changes.
Public Read Bucket Policy
This policy allows public read access to objects in the bucket (required for serving media files such as images, videos, CSS, and JS).
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "AllowPublicRead",
"Effect": "Allow",
"Principal": {
"AWS": "*"
},
"Action": [
"s3:GetObject",
"s3:GetObjectVersion"
],
"Resource": "arn:aws:s3:::bucket-name/*"
}
]
}
4. Find the Correct Endpoint
Each Wasabi region has a different endpoint. Example:
| Region | Endpoint |
|---|---|
| us-east-1 | s3.wasabisys.com |
| ap-northeast-1 | s3.ap-northeast-1.wasabisys.com |
| eu-central-1 | s3.eu-central-1.wasabisys.com |
Full List: https://wasabi.com/help/docs/wasabi-service-url-endpoints
Security Best Practices
- Do not use Root credentials in production.
- Create IAM Users with limited policies.
- Store credentials securely (
.env, Secrets Manager, etc.)