buckets

Re-validate a bucket

Re-run the access check on a bucket and mark it active again.

A bucket moves to error when Mixedbread is refused access to it, and uploads and store creation are rejected until this probe (reachability + write/delete, with the stored credentials) passes. A failing probe leaves the status unchanged.

Args: bucket_id: The ID of the bucket to re-validate.

Returns: Bucket: The re-validated bucket. Credentials are never returned.

post/v1/buckets/{bucket_id}/validate

Path parameters

bucket_idstring uuid required

The ID of the bucket to re-validate

The ID of the bucket to re-validate

Response

The bucket, active again

idstring required

The ID of the bucket

created_atstring date-time required

Creation time

updated_atstring date-time required

Last update time

namestring required

Display name

provider'aws_s3' required

Object-storage provider backing a bring-your-own bucket.

bucketstring required

The bucket name

regionstring nullable required

The bucket region

endpoint_urlstring nullable required

Custom S3-compatible endpoint

prefixstring required

Key prefix within the bucket

sse_kms_key_idstring nullable required

KMS key id/ARN used to encrypt writes (SSE-KMS)

auth_type'assume_role' | 'access_key' required

How omni authenticates against a customer bucket.

ASSUME_ROLE is the recommended default for AWS: nothing secret is stored, every service assumes the customer's IAM role via STS on use. ACCESS_KEY remains for S3-compatible providers that have no STS.

role_arnstring nullable required

IAM role Mixedbread assumes (auth_type=assume_role); not a secret

external_idstring nullable required

sts:ExternalId the role's trust policy must require (auth_type=assume_role); not a secret

status'pending' | 'active' | 'error' required

Validation lifecycle of a customer bucket.

last_validated_atstring date-time nullable required

When the bucket was last validated

has_credentialsboolean required

Whether secret credentials are stored (always false for assume-role buckets)

credentials_versioninteger required

Increments on every credential rotation

object'bucket'

The type of the object

Changes