S3 access keys let approved post-production partners and vendors securely upload media to, and download media from, the studio's cloud storage. Each key is scoped to a specific production and to the folders you need, and is used with tools such as Cyberduck, Syncovery, or the AWS CLI.
How do I request S3 access keys?
Open a request with ProdTech support at post-support@amazonstudios.com and include the details below so your key can be set up correctly the first time. If you're getting set up for the first time, Setting Up Your Cloud Post-Production Environment covers the wider onboarding steps.
- The production (show or project) the media is for.
- The name and email address of each person who needs a key.
- The bucket or workspace you need to reach, if you know it.
- The folders/paths you need (for example, an original-capture folder or a work-in-progress/dailies folder).
- The access level required: browse/list, download, upload, create folders, or preview.
- The tool you plan to use (Cyberduck, Syncovery, AWS CLI, etc.).
Your access key (an Access Key ID and a Secret Access Key) will be delivered to you securely. Treat both values as confidential.
I received my keys: how do I use them to connect?
Most S3-compatible tools need the same handful of values. Enter them in your tool's connection or profile settings:
- Access Key ID, the public identifier provided to you.
- Secret Access Key, the secret value provided to you (keep this private).
- Region, the region given to you with your keys (for example, a US or EU region).
- Bucket name and path/prefix, the bucket and folder you were granted access to.
Tips by tool:
- Cyberduck: Create a new "Amazon S3" bookmark, paste the Access Key ID and Secret Access Key, then browse to the bucket/path you were given.
-
AWS CLI: Configure a profile with your Access Key ID, Secret Access Key, and region, then reference the bucket and prefix in your
aws s3commands. - Syncovery: Use the credentials and bucket path provided, and make sure your client software is up to date before transferring.
My keys aren't working / I get an access denied error. What do I check?
Most failures are simple to self-diagnose. Check these first:
- Typos in the keys, re-copy the Access Key ID and Secret Access Key carefully, with no extra spaces or line breaks.
- Wrong bucket or path, confirm you're pointing at the exact bucket name and folder/prefix you were granted. Access is limited to the folders in your request.
- Region mismatch, make sure your tool is set to the region that came with your keys.
- Clock skew, if your computer's clock is wrong, S3 can reject requests. Make sure your system date/time is set to update automatically.
- Outdated transfer software, older versions of your transfer tool can block transfers. Update to the current version and retry.
- Expired or rotated keys, keys are refreshed periodically. If they previously worked and now don't, they may need to be re-issued (see below).
If it still fails after these checks, contact ProdTech support at post-support@amazonstudios.com with the exact error message and the details listed in "When to contact support."
How do I keep my keys secure?
Your access keys are credentials, anyone with them can access the media you can access. Please:
- Never share your keys over chat, email threads, or with people outside your approved team.
- Don't paste keys into source code, scripts, or anything that gets committed to a code repository.
- Store them in a secure location, such as your tool's encrypted credential store or a password manager.
- If you think a key has been exposed or shared by mistake, contact ProdTech support at post-support@amazonstudios.com immediately and request that it be rotated (replaced).
My keys expired or were rotated. How do I get new ones?
Access keys have a lifespan of 90 days. Just before 90 days we will reach out with a new set of keys for you to use that have the same access as the previous set. Please implement these keys promptly to avoid losing access.
To get a fresh set:
- Contact ProdTech support at post-support@amazonstudios.com and let them know you need your keys re-issued.
- Include the production and the email address the keys were issued to.
- Note the tool and bucket/path you're using so the replacement is scoped the same way.
New credentials will be delivered to you securely, and you can update them in your tool's connection settings.
When to contact support
If the self-service steps above don't resolve your issue, reach out to the team that handles your type of request:
ProdTech, post-support@amazonstudios.com
ProdTech manages Studio in the Cloud, including initial user onboarding, new account creation, and provisioning access to storage, workspaces, cloud workstations, applications, and tools, plus the setup, performance, and technical issues covered in this guide.
TechOps (TOPS), support@amazonstudios.com
TechOps manages your Originals Access account, and will assist you with issues around Okta sign-in/SSO problems, password resets, MFA/2FA resets (including a new phone), and account lockouts.
TechOps also handles requests for access to specific applications (such as Box, Flow Capture, or Aspera on Cloud).
When contacting us, help us resolve your issue quickly by always including:
- Your full name and account email (
@originalsaccess.com). - A clear description of the problem and the exact error message you see (a screenshot helps).
- Your show code and show name.
- The show/workspace, workstation, or application involved.
- When the problem started and what you've already tried.
Please open a new request for each separate issue rather than replying to an older, resolved one, so it reaches the right team.
Comments
0 comments
Please sign in to leave a comment.