创建应用存储临时访问凭证

最近更新时间:2024-09-11 19:07:18

我的收藏

1. 接口描述

接口请求域名: vod.tencentcloudapi.com 。

用于按指定策略,生成专业版应用的临时访问凭证,比如生成用于客户端上传的临时凭证。

默认接口请求频率限制:20次/秒。

推荐使用 API Explorer
点击调试
API Explorer 提供了在线调用、签名验证、SDK 代码生成和快速检索接口等能力。您可查看每次调用的请求内容和返回结果以及自动生成 SDK 调用示例。

2. 输入参数

以下请求参数列表仅列出了接口请求参数和部分公共参数,完整公共参数列表见 公共请求参数

参数名称 必选 类型 描述
Action String 公共参数,本接口取值:CreateStorageCredentials。
Version String 公共参数,本接口取值:2024-07-18。
Region String 公共参数,此参数为可选参数。
SubAppId Integer 点播应用 ID。
示例值:123456789012
Policy String 按照下方语法组装好策略后,先序列化为字符串,再做 urlencode,结果作为 Policy 字段入参。服务端会对该字段做 urldecode,并按解析后的策略授予临时访问凭证权限,请按规范传入参数。
注意:
1.策略语法参照访问管理策略
2.策略中不能包含 principal 元素。
3.策略的 action 元素仅支持:
  • name/vod:PutObject;
  • name/vod:ListParts;
  • name/vod:PostObject;
  • name/vod:InitiateMultipartUpload;
  • name/vod:UploadPart;
  • name/vod:CompleteMultipartUpload;
  • name/vod:AbortMultipartUpload;
  • name/vod:ListMultipartUploads;
  • 4.策略的 resource 元素填写格式为:qcs::vod::uid/[账号AppID]:prefix//[子应用ID]/[存储桶ID]/[存储路径],其中账号AppID、子应用ID、存储桶ID和存储路径要按需填写,其他内容不允许改动,例:qcs::vod::uid/1:prefix//1/1/path。

    示例值:%7B%22statement%22%3A%5B%7B%22action%22%3A%5B%22name%2Fvod%3APutObject%22%2C%22name%2Fvod%3AListParts%22%2C%22name%2Fvod%3APostObject%22%2C%22name%2Fvod%3AInitiateMultipartUpload%22%2C%22name%2Fvod%3AUploadPart%22%2C%22name%2Fvod%3ACompleteMultipartUpload%22%2C%22name%2Fvod%3AAbortMultipartUpload%22%2C%22name%2Fvod%3AListMultipartUploads%22%5D%2C%22effect%22%3A%22allow%22%2C%22resource%22%3A%5B%22qcs%3A%3Avod%3A%3Auid%2F1%3Aprefix%2F%2F1%2F1%2Fpath%22%5D%7D%5D%2C%22version%22%3A%222.0%22%7D
    DurationSeconds Integer 指定临时证书的有效期,单位:秒。
    默认 1800 秒,最大 129600 秒。
    示例值:1800

    3. 输出参数

    参数名称 类型 描述
    Credentials Credentials 临时访问凭证。
    RequestId String 唯一请求 ID,由服务端生成,每次请求都会返回(若请求因其他原因未能抵达服务端,则该次请求不会获得 RequestId)。定位问题时需要提供该次请求的 RequestId。

    4. 示例

    示例1 申请上传单个文件临时凭证

    申请上传单个文件临时凭证

    输入示例

    POST / HTTP/1.1
    Host: vod.tencentcloudapi.com
    Content-Type: application/json
    X-TC-Action: CreateStorageCredentials
    <公共请求参数>
    
    {
        "SubAppId": 220209,
        "DurationSeconds": 7200,
        "Policy": "%7B%22statement%22%3A%5B%7B%22action%22%3A%5B%22name%2Fvod%3AInitiateMultipartUpload%22%2C%22name%2Fvod%3AListMultipartUploads%22%2C%22name%2Fvod%3AListParts%22%2C%22name%2Fvod%3AUploadPart%22%2C%22name%2Fvod%3ACompleteMultipartUpload%22%5D%2C%22effect%22%3A%22allow%22%2C%22resource%22%3A%5B%22qcs%3A%3Avod%3Aap-beijing%3Auid%2F251197738%3Aprefix%2F%2F220209%2Fa%2F001.png%22%5D%7D%5D%2C%22version%22%3A%222.0%22%7D"
    }

    输出示例

    {
        "Response": {
            "Credentials": {
                "SessionToken": "kTRt***Jb7m",
                "AccessKeyId": "AKID****CjE6",
                "SecretAccessKey": "Eo28***7ps=",
                "Expiration": "2024-08-20T13:55:53Z"
            },
            "RequestId": "59a5e07e-4147-4d2e-a808-dca76ac5b3fd"
        }
    }

    示例2 申请上传多个文件临时凭证

    申请上传多个文件临时凭证

    输入示例

    POST / HTTP/1.1
    Host: vod.tencentcloudapi.com
    Content-Type: application/json
    X-TC-Action: CreateStorageCredentials
    <公共请求参数>
    
    {
        "SubAppId": 220209,
        "DurationSeconds": 7200,
        "Policy": "%7B%22statement%22%3A%5B%7B%22action%22%3A%5B%22name%2Fvod%3AInitiateMultipartUpload%22%2C%22name%2Fvod%3AListMultipartUploads%22%2C%22name%2Fvod%3AListParts%22%2C%22name%2Fvod%3AUploadPart%22%2C%22name%2Fvod%3ACompleteMultipartUpload%22%5D%2C%22effect%22%3A%22allow%22%2C%22resource%22%3A%5B%22qcs%3A%3Avod%3Aap-beijing%3Auid%2F251197738%3Aprefix%2F%2F220209%2Fa%2F1024x1024.png%22%2C%22qcs%3A%3Avod%3Aap-beijing%3Auid%2F251197738%3Aprefix%2F%2F220209%2Fa%2Fb%2Fc%2F1042x1042.png%22%2C%22qcs%3A%3Avod%3Aap-beijing%3Auid%2F251197738%3Aprefix%2F%2F220209%2Fpath%2F2060.gif_wh300.gif%22%5D%7D%5D%2C%22version%22%3A%222.0%22%7D"
    }

    输出示例

    {
        "Response": {
            "Credentials": {
                "SessionToken": "kTRt***Jb7m",
                "AccessKeyId": "AKID****CjE6",
                "SecretAccessKey": "Eo28***7ps=",
                "Expiration": "2024-08-20T13:55:53Z"
            },
            "RequestId": "59a5e07e-4147-4d2e-a808-dca76ac5b3fd"
        }
    }

    示例3 申请列出桶内指定对象键前缀所有对象的临时凭证

    申请列出桶内指定对象键前缀所有对象的临时凭证

    输入示例

    POST / HTTP/1.1
    Host: vod.tencentcloudapi.com
    Content-Type: application/json
    X-TC-Action: CreateStorageCredentials
    <公共请求参数>
    
    {
        "SubAppId": 220209,
        "DurationSeconds": 7200,
        "Policy": "%7B%22statement%22%3A%5B%7B%22action%22%3A%5B%22name%2Fvod%3AGetBucket%22%5D%2C%22effect%22%3A%22allow%22%2C%22resource%22%3A%5B%22qcs%3A%3Avod%3Aap-beijing%3Auid%2F251197738%3Aprefix%2F%2F220209%2F98gw6e1b4hds0zh%2F%22%5D%7D%5D%2C%22version%22%3A%222.0%22%7D"
    }

    输出示例

    {
        "Response": {
            "Credentials": {
                "SessionToken": "kTRt***Jb7m",
                "AccessKeyId": "AKID****CjE6",
                "SecretAccessKey": "Eo28***7ps=",
                "Expiration": "2024-08-20T13:55:53Z"
            },
            "RequestId": "59a5e07e-4147-4d2e-a808-dca76ac5b3fd"
        }
    }

    示例4 申请自动就近上传文件的临时凭证

    申请自动就近上传文件的临时凭证

    输入示例

    POST / HTTP/1.1
    Host: vod.tencentcloudapi.com
    Content-Type: application/json
    X-TC-Action: CreateStorageCredentials
    <公共请求参数>
    
    {
        "SubAppId": 220209,
        "DurationSeconds": 7200,
        "Policy": "%7B%22statement%22%3A%5B%7B%22action%22%3A%5B%22name%2Fvod%3AInitiateMultipartUpload%22%2C%22name%2Fvod%3AListMultipartUploads%22%2C%22name%2Fvod%3AListParts%22%2C%22name%2Fvod%3AUploadPart%22%2C%22name%2Fvod%3ACompleteMultipartUpload%22%5D%2C%22effect%22%3A%22allow%22%2C%22resource%22%3A%5B%22qcs%3A%3Avod%3Aauto%3Auid%2F251197738%3Aprefix%2F%2F220209%2Fauto%2F001.png%22%5D%7D%5D%2C%22version%22%3A%222.0%22%7D"
    }

    输出示例

    {
        "Response": {
            "Credentials": {
                "SessionToken": "kTRt***Jb7m",
                "AccessKeyId": "AKID****CjE6",
                "SecretAccessKey": "Eo28***7ps=",
                "Expiration": "2024-08-20T13:55:53Z"
            },
            "RequestId": "59a5e07e-4147-4d2e-a808-dca76ac5b3fd"
        }
    }

    5. 开发者资源

    腾讯云 API 平台

    腾讯云 API 平台 是综合 API 文档、错误码、API Explorer 及 SDK 等资源的统一查询平台,方便您从同一入口查询及使用腾讯云提供的所有 API 服务。

    API Inspector

    用户可通过 API Inspector 查看控制台每一步操作关联的 API 调用情况,并自动生成各语言版本的 API 代码,也可前往 API Explorer 进行在线调试。

    SDK

    云 API 3.0 提供了配套的开发工具集(SDK),支持多种编程语言,能更方便的调用 API。

    命令行工具

    6. 错误码

    该接口暂无业务逻辑相关的错误码,其他错误码详见 公共错误码