- Print
- DarkLight
GetBucketPolicy
- Print
- DarkLight
Availability
Early Access: July 1, 2026
Early Access is gated; contact the Backblaze Sales team for access.
Limited Availability: July 1, 2026
This API is available only to customers with access to the Backblaze Enterprise Web Console. For more information, contact the Backblaze Sales team.
Return the current bucket policy
Endpoint: GET /{bucket}/?policy on s3.{region}.backblazeb2.com.
Example request
GET /analytics-bucket/?policy HTTP/1.1 Host: s3.us-west-002.backblazeb2.com
Example response
HTTP/1.1 200 x-amz-request-id: req-1234567890 x-amz-id-2: abcdefghijklmnopqrstuvwxyz1234567890abcdef
{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Principal":{"AWS":"arn:aws:iam::123456789012:role/analytics-role"},"Action":["s3:GetObject"],"Resource":["arn:aws:s3:::analytics-bucket/*"]}]} Errors
NoSuchBucketAccessDenied
AWS Signature Version 4. The Authorization header takes the form AWS4-HMAC-SHA256 Credential=..., SignedHeaders=..., Signature=.... For IAM and STS requests, the signing region is not validated; use any non-empty region value consistently. The signing service must be iam for IAM requests and sts for STS requests. When using temporary credentials, also include X-Amz-Security-Token: <session-token>.
The name of the bucket. Provided in the request path.
Subresource indicator. Must be present as ?policy (no value).
The current bucket policy as JSON.
"{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",...}]}"| HTTP Status | Code | Description |
|---|---|---|
| 403 | AccessDenied | The authenticated principal lacks permission. |
| HTTP Status | Code | Description |
|---|---|---|
| 404 | NoSuchBucket | Bucket not found. |
| 404 | NoSuchBucketPolicy | The bucket has no policy configured. |