> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nscale.com/llms.txt
> Use this file to discover all available pages before exploring further.

# S3 API

> Manage buckets and objects on S3-compatible object storage endpoints.

`nscale s3api` is an S3 client built into the CLI. For the operations it supports, it follows [`aws s3api`](https://docs.aws.amazon.com/cli/latest/reference/s3api/), plus `presign` from `aws s3`: the same flag names and the same PascalCase response bodies. Use it to work with buckets and objects on an [Object Storage](/docs/storage/object-storage) endpoint without installing or configuring the AWS CLI.

**Aliases:** `s3api`, `s3`

<Info>
  To create object storage endpoints, identity policies, and access keys, use [`nscale object-storage`](/docs/cli/object-storage). `nscale s3api` works with the buckets and objects inside an endpoint.
</Info>

## Quick start

<Steps>
  <Step title="Save a profile">
    Run `configure` and follow the prompts. It asks for a profile name (default `default`), lets you pick an organization and object storage endpoint, and then either creates a new access key or takes the ID and secret of an existing one.

    ```bash theme={null}
    nscale s3api configure
    ```
  </Step>

  <Step title="Run commands">
    Commands use the `default` profile automatically. Pass `--profile` to use another one.

    ```bash theme={null}
    nscale s3api create-bucket --bucket my-bucket
    nscale s3api put-object --bucket my-bucket --key data.csv --body ./data.csv
    nscale s3api list-objects-v2 --bucket my-bucket -q '.Contents[]?.Key'
    ```
  </Step>
</Steps>

## Endpoint and credentials

Every `s3api` command accepts these flags to choose the endpoint and credentials:

| Flag | Description |
| - | - |
| `--profile string` | Profile to use. A profile saved with [`configure`](#configure) is checked first, then an AWS shared-config profile of the same name |
| `--id string` | Object storage endpoint ID. The CLI looks up the endpoint's public URL through the Nscale API, so you must be logged in |
| `--endpoint-url string` | Object storage endpoint URL, used as given. Mutually exclusive with `--id` |
| `--org string` | Organization ID, used to look up the endpoint by `--id` or to pick one interactively |

The CLI resolves credentials and the endpoint in this order:

1. **Saved profile.** If a profile named by `--profile` (or `default` when `--profile` is not set) exists in `object-storage-profiles.yaml`, its access key and endpoint URL are used. `--endpoint-url` or `--id` override the saved endpoint URL.
2. **AWS credential chain.** Otherwise, credentials come from the AWS default chain, the same as the AWS CLI: the AWS profile named by `--profile` or `AWS_PROFILE`, the `AWS_ACCESS_KEY_ID` and `AWS_SECRET_ACCESS_KEY` environment variables, and the files in `~/.aws`. The endpoint comes from `--endpoint-url` or `--id`, then from an `endpoint_url` in the AWS profile or `AWS_ENDPOINT_URL`. If none is set, the CLI prompts you to pick an endpoint.

Saved profiles live in `object-storage-profiles.yaml` in the CLI config directory: `~/.config/nscale/` on macOS and Linux (or `$XDG_CONFIG_HOME/nscale/` when set), and `%AppData%\nscale\` on Windows. The file stores access key secrets in plain text and is readable only by your user.

```yaml theme={null}
default:
  access_key_id: <access-key-id>
  access_key_secret: <access-key-secret>
  endpoint_url: https://<endpoint-dns-name>
```

## Output

`s3api` commands print the S3 response object as JSON, exactly as the AWS SDK returns it: PascalCase keys and no `metadata`/`spec`/`status` envelope. Use `-q` with a jq filter to pick out fields:

```bash theme={null}
# Bucket names, one per line
nscale s3api list-buckets -q '.Buckets[]?.Name'

# Keys and sizes under a prefix
nscale s3api list-objects-v2 --bucket my-bucket --prefix logs/ -q '.Contents[]?.Key' -q '.Contents[]?.Size'
```

S3 leaves empty lists out of the response, so a listing with no matches has no `Contents` field and `.Contents[]` fails. Use `.Contents[]?` in scripts that may list an empty prefix.

Commands that change bucket configuration (`put-bucket-*`, `delete-bucket-lifecycle`, `delete-bucket-tagging`) and `delete-bucket` print a confirmation message instead of a response body. `get-object` streams the object itself to stdout unless you pass `--outfile`.

## Input values

Flags that take a structured value, such as `--delete`, `--multipart-upload`, `--lifecycle-configuration`, `--versioning-configuration`, `--create-bucket-configuration`, and `--tagging` on the bucket and object tagging commands, accept either inline JSON in the AWS SDK shape or a `file://` path to a file that holds it:

```bash theme={null}
nscale s3api put-bucket-versioning --bucket my-bucket --versioning-configuration '{"Status":"Enabled"}'
nscale s3api delete-objects --bucket my-bucket --delete file://delete.json --yes
```

Date and time flags take RFC3339 timestamps, for example `2026-01-31T12:00:00Z`.

## Pagination

The list commands follow the AWS CLI pagination model and fetch every page by default:

* `--max-items` caps the total number of items returned across all pages.
* `--page-size` caps the number of items requested in each call to the endpoint.
* `--starting-token` resumes a listing from the continuation token in a previous response, such as `NextContinuationToken` from `list-objects-v2`, `NextMarker` from `list-objects`, or `NextToken` from `list-object-versions` and `list-multipart-uploads`.

```bash theme={null}
nscale s3api list-objects-v2 --bucket my-bucket --max-items 100
```

## Subcommands

Each command lists its common flags first. The rest, such as server-side encryption, ACLs, Object Lock, and requester-pays settings, are under **Advanced flags**.

<Note>
  Advanced flags are passed to the S3 API as given. Nscale Object Storage does not implement every S3 feature, for example SSE-C, public ACLs, lifecycle rules, and suspending versioning. See [S3 API compatibility](/docs/storage/object-storage#s3-api-compatibility).
</Note>

**Setup**

* [configure](#configure) — Save an s3api profile (endpoint and access key) for reuse

**Buckets**

* [list-buckets](#list-buckets) — List buckets owned by the authenticated account
* [create-bucket](#create-bucket) — Create a new bucket
* [head-bucket](#head-bucket) — Check whether a bucket exists and is accessible
* [get-bucket-location](#get-bucket-location) — Get the region a bucket resides in
* [delete-bucket](#delete-bucket) — Delete an empty bucket

**Bucket configuration**

* [get-bucket-versioning](#get-bucket-versioning) — Get the versioning state of a bucket
* [put-bucket-versioning](#put-bucket-versioning) — Set the versioning state of a bucket
* [get-bucket-lifecycle-configuration](#get-bucket-lifecycle-configuration) — Get the lifecycle configuration of a bucket
* [put-bucket-lifecycle-configuration](#put-bucket-lifecycle-configuration) — Set the lifecycle configuration of a bucket
* [delete-bucket-lifecycle](#delete-bucket-lifecycle) — Delete the lifecycle configuration of a bucket
* [get-bucket-tagging](#get-bucket-tagging) — Get the tag set of a bucket
* [put-bucket-tagging](#put-bucket-tagging) — Set the tags of a bucket
* [delete-bucket-tagging](#delete-bucket-tagging) — Delete the tags from a bucket

**Objects**

* [list-objects-v2](#list-objects-v2) — List objects in a bucket (S3 ListObjectsV2)
* [list-objects](#list-objects) — List objects in a bucket (legacy S3 ListObjects V1)
* [list-object-versions](#list-object-versions) — List object versions and delete markers in a bucket
* [put-object](#put-object) — Add an object to a bucket, streaming the body from a file or stdin
* [get-object](#get-object) — Retrieve an object from a bucket, streaming it to a file or stdout
* [head-object](#head-object) — Retrieve metadata from an object without returning the object itself
* [copy-object](#copy-object) — Create a copy of an object already stored in the bucket
* [delete-object](#delete-object) — Remove an object from a bucket
* [delete-objects](#delete-objects) — Delete multiple objects from a bucket in a single request
* [presign](#presign) — Generate a pre-signed URL for an object

**Object tagging**

* [get-object-tagging](#get-object-tagging) — Get the tag-set of an object
* [put-object-tagging](#put-object-tagging) — Set the tag-set of an object
* [delete-object-tagging](#delete-object-tagging) — Remove the entire tag-set from an object

**Multipart uploads**

* [create-multipart-upload](#create-multipart-upload) — Initiate a multipart upload and return its upload ID
* [upload-part](#upload-part) — Upload a part in a multipart upload
* [upload-part-copy](#upload-part-copy) — Upload a part by copying data from an existing object
* [list-parts](#list-parts) — List the parts uploaded for a specific multipart upload
* [list-multipart-uploads](#list-multipart-uploads) — List in-progress multipart uploads in a bucket
* [complete-multipart-upload](#complete-multipart-upload) — Complete a multipart upload by assembling its uploaded parts
* [abort-multipart-upload](#abort-multipart-upload) — Abort a multipart upload and discard its uploaded parts

***

## configure

Save an s3api profile so later commands can run with just `--profile`. Run it interactively to be prompted for the profile name, the endpoint, and the access key. When the endpoint is picked from your organization or passed with `--id`, `configure` can create a new access key for you; the secret is saved to the profile and not printed.

To run it without prompts, pass `--profile`, an endpoint (`--endpoint-url` or `--id`), `--key-id`, and `--key-secret`. Read the secret from an environment variable rather than typing it inline, so it does not end up in your shell history. An existing profile with the same name is overwritten; interactively, you are asked to confirm first.

```bash theme={null}
nscale s3api configure [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--key-id string"}</code></td><td>Access key ID (skips the access-key prompt)</td></tr>
    <tr><td><code>{"--key-secret string"}</code></td><td>Access key secret (skips the access-key prompt)</td></tr>
  </tbody>
</table>

### Examples

```bash theme={null}
# Interactive: pick an endpoint and create an access key
nscale s3api configure

# Non-interactive, with an existing access key from the environment
nscale s3api configure --profile prod --id <endpoint-id> \
  --key-id "$ACCESS_KEY_ID" --key-secret "$ACCESS_KEY_SECRET"
```

***

## list-buckets

List the buckets owned by the access key's account.

```bash theme={null}
nscale s3api list-buckets [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--max-items int32"}</code></td><td>Total number of items to return across all pages</td></tr>
    <tr><td><code>{"--page-size int32"}</code></td><td>Number of items to request per service call</td></tr>
    <tr><td><code>{"--prefix string"}</code></td><td>Limit the response to bucket names with this prefix</td></tr>
    <tr><td><code>{"--starting-token string"}</code></td><td>Pagination token marking where a previous listing should resume</td></tr>

    <tr>
      <td>
        <code>
          {"--json"}
        </code>
      </td>

      <td>Emit the full JSON payload (mutually exclusive with <code>-q</code>)</td>
    </tr>

    <tr>
      <td>
        <code>
          {"-q, --query stringArray"}
        </code>
      </td>

      <td>jq filter for value extraction (see <a href="/docs/cli/query-output">Query output with <code>-q</code></a>)</td>
    </tr>
  </tbody>
</table>

### Examples

```bash theme={null}
nscale s3api list-buckets
nscale s3api list-buckets --prefix logs- -q '.Buckets[]?.Name'
```

***

## create-bucket

Create a new bucket.

```bash theme={null}
nscale s3api create-bucket --bucket <bucket> [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The name of the bucket to create</td></tr>
    <tr><td><code>{"--acl string"}</code></td><td>The canned ACL to apply to the bucket (<code>private</code> | <code>public-read</code> | <code>public-read-write</code> | <code>authenticated-read</code>)</td></tr>
    <tr><td><code>{"--create-bucket-configuration string"}</code></td><td>The configuration for the bucket, as JSON</td></tr>
    <tr><td><code>{"--object-lock-enabled-for-bucket"}</code></td><td>Enable S3 Object Lock for the new bucket</td></tr>
    <tr><td><code>{"--object-ownership string"}</code></td><td>Object ownership for the bucket (<code>BucketOwnerPreferred</code> | <code>ObjectWriter</code> | <code>BucketOwnerEnforced</code>)</td></tr>

    <tr>
      <td>
        <code>
          {"--json"}
        </code>
      </td>

      <td>Emit the full JSON payload (mutually exclusive with <code>-q</code>)</td>
    </tr>

    <tr>
      <td>
        <code>
          {"-q, --query stringArray"}
        </code>
      </td>

      <td>jq filter for value extraction (see <a href="/docs/cli/query-output">Query output with <code>-q</code></a>)</td>
    </tr>
  </tbody>
</table>

### Example

```bash theme={null}
nscale s3api create-bucket --bucket my-bucket
```

***

## head-bucket

Check whether a bucket exists and you have permission to access it. The command fails if the bucket does not exist or is not accessible.

```bash theme={null}
nscale s3api head-bucket --bucket <bucket> [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The name of the bucket to check</td></tr>

    <tr>
      <td>
        <code>
          {"--json"}
        </code>
      </td>

      <td>Emit the full JSON payload (mutually exclusive with <code>-q</code>)</td>
    </tr>

    <tr>
      <td>
        <code>
          {"-q, --query stringArray"}
        </code>
      </td>

      <td>jq filter for value extraction (see <a href="/docs/cli/query-output">Query output with <code>-q</code></a>)</td>
    </tr>
  </tbody>
</table>

### Example

```bash theme={null}
nscale s3api head-bucket --bucket my-bucket
```

***

## get-bucket-location

Get the region a bucket resides in.

```bash theme={null}
nscale s3api get-bucket-location --bucket <bucket> [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The name of the bucket</td></tr>

    <tr>
      <td>
        <code>
          {"--json"}
        </code>
      </td>

      <td>Emit the full JSON payload (mutually exclusive with <code>-q</code>)</td>
    </tr>

    <tr>
      <td>
        <code>
          {"-q, --query stringArray"}
        </code>
      </td>

      <td>jq filter for value extraction (see <a href="/docs/cli/query-output">Query output with <code>-q</code></a>)</td>
    </tr>
  </tbody>
</table>

### Example

```bash theme={null}
nscale s3api get-bucket-location --bucket my-bucket -q '.LocationConstraint'
```

***

## delete-bucket

Delete a bucket. The bucket must be empty: delete its objects first, including every object version when versioning is enabled.

```bash theme={null}
nscale s3api delete-bucket --bucket <bucket> [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The name of the bucket to delete</td></tr>
    <tr><td><code>{"-y, --yes"}</code></td><td>Automatically confirm bucket deletion</td></tr>
  </tbody>
</table>

### Example

```bash theme={null}
nscale s3api delete-bucket --bucket my-bucket --yes
```

***

## get-bucket-versioning

Get the versioning state of a bucket.

```bash theme={null}
nscale s3api get-bucket-versioning --bucket <bucket> [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The name of the bucket</td></tr>
    <tr><td><code>{"--expected-bucket-owner string"}</code></td><td>Account ID of the expected bucket owner</td></tr>

    <tr>
      <td>
        <code>
          {"--json"}
        </code>
      </td>

      <td>Emit the full JSON payload (mutually exclusive with <code>-q</code>)</td>
    </tr>

    <tr>
      <td>
        <code>
          {"-q, --query stringArray"}
        </code>
      </td>

      <td>jq filter for value extraction (see <a href="/docs/cli/query-output">Query output with <code>-q</code></a>)</td>
    </tr>
  </tbody>
</table>

### Example

```bash theme={null}
nscale s3api get-bucket-versioning --bucket my-bucket -q '.Status'
```

***

## put-bucket-versioning

Set the versioning state of a bucket. Nscale Object Storage supports enabling versioning but not suspending it once enabled. `--versioning-configuration` takes JSON in the SDK `VersioningConfiguration` shape, or a `file://` reference to it.

```bash theme={null}
nscale s3api put-bucket-versioning --bucket <bucket> --versioning-configuration <json> [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The name of the bucket</td></tr>
    <tr><td><code>{"--versioning-configuration string"}</code></td><td><strong>Required.</strong> Versioning state, as JSON matching the SDK VersioningConfiguration shape or a <code>file://</code> reference</td></tr>
  </tbody>
</table>

<Accordion title="Advanced flags">
  <table>
    <thead><tr><th>Flag</th><th>Description</th></tr></thead>

    <tbody>
      <tr><td><code>{"--checksum-algorithm string"}</code></td><td>Algorithm used to create the request checksum (<code>CRC32</code> | <code>CRC32C</code> | <code>CRC64NVME</code> | <code>SHA1</code> | <code>SHA256</code>)</td></tr>
      <tr><td><code>{"--content-md5 string"}</code></td><td>Base64-encoded 128-bit MD5 digest for an integrity check</td></tr>
      <tr><td><code>{"--expected-bucket-owner string"}</code></td><td>Account ID of the expected bucket owner</td></tr>
      <tr><td><code>{"--mfa string"}</code></td><td>MFA device serial number, a space, and the current MFA code</td></tr>
    </tbody>
  </table>
</Accordion>

### Example

```bash theme={null}
nscale s3api put-bucket-versioning --bucket my-bucket --versioning-configuration '{"Status":"Enabled"}'
```

***

## get-bucket-lifecycle-configuration

<Warning>
  Nscale Object Storage does not support lifecycle configuration. This command is for other S3-compatible endpoints; see [S3 API compatibility](/docs/storage/object-storage#s3-api-compatibility).
</Warning>

Get the lifecycle configuration of a bucket.

```bash theme={null}
nscale s3api get-bucket-lifecycle-configuration --bucket <bucket> [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The name of the bucket</td></tr>
    <tr><td><code>{"--expected-bucket-owner string"}</code></td><td>Account ID of the expected bucket owner</td></tr>

    <tr>
      <td>
        <code>
          {"--json"}
        </code>
      </td>

      <td>Emit the full JSON payload (mutually exclusive with <code>-q</code>)</td>
    </tr>

    <tr>
      <td>
        <code>
          {"-q, --query stringArray"}
        </code>
      </td>

      <td>jq filter for value extraction (see <a href="/docs/cli/query-output">Query output with <code>-q</code></a>)</td>
    </tr>
  </tbody>
</table>

### Example

```bash theme={null}
nscale s3api get-bucket-lifecycle-configuration --bucket my-bucket -q '.Rules[].ID'
```

***

## put-bucket-lifecycle-configuration

<Warning>
  Nscale Object Storage does not support lifecycle configuration. This command is for other S3-compatible endpoints; see [S3 API compatibility](/docs/storage/object-storage#s3-api-compatibility).
</Warning>

Set the lifecycle configuration of a bucket, replacing any existing rules. `--lifecycle-configuration` takes JSON in the SDK `BucketLifecycleConfiguration` shape, or a `file://` reference to it.

```bash theme={null}
nscale s3api put-bucket-lifecycle-configuration --bucket <bucket> --lifecycle-configuration <json> [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The name of the bucket</td></tr>
    <tr><td><code>{"--checksum-algorithm string"}</code></td><td>Algorithm used to create the request checksum (<code>CRC32</code> | <code>CRC32C</code> | <code>CRC64NVME</code> | <code>SHA1</code> | <code>SHA256</code>)</td></tr>
    <tr><td><code>{"--expected-bucket-owner string"}</code></td><td>Account ID of the expected bucket owner</td></tr>
    <tr><td><code>{"--lifecycle-configuration string"}</code></td><td>Lifecycle rules, as JSON matching the SDK BucketLifecycleConfiguration shape or a <code>file://</code> reference</td></tr>
    <tr><td><code>{"--transition-default-minimum-object-size string"}</code></td><td>Default minimum object size behaviour (<code>varies\_by\_storage\_class</code> | <code>all\_storage\_classes\_128K</code>)</td></tr>
  </tbody>
</table>

### Examples

```bash theme={null}
# Expire objects under logs/ after 30 days
nscale s3api put-bucket-lifecycle-configuration --bucket my-bucket \
  --lifecycle-configuration '{"Rules":[{"ID":"expire-logs","Status":"Enabled","Filter":{"Prefix":"logs/"},"Expiration":{"Days":30}}]}'

nscale s3api put-bucket-lifecycle-configuration --bucket my-bucket --lifecycle-configuration file://lifecycle.json
```

***

## delete-bucket-lifecycle

<Warning>
  Nscale Object Storage does not support lifecycle configuration. This command is for other S3-compatible endpoints; see [S3 API compatibility](/docs/storage/object-storage#s3-api-compatibility).
</Warning>

Delete the lifecycle configuration of a bucket.

```bash theme={null}
nscale s3api delete-bucket-lifecycle --bucket <bucket> [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The name of the bucket</td></tr>
    <tr><td><code>{"--expected-bucket-owner string"}</code></td><td>Account ID of the expected bucket owner</td></tr>
  </tbody>
</table>

### Example

```bash theme={null}
nscale s3api delete-bucket-lifecycle --bucket my-bucket
```

***

## get-bucket-tagging

Get the tag set of a bucket.

```bash theme={null}
nscale s3api get-bucket-tagging --bucket <bucket> [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The name of the bucket</td></tr>
    <tr><td><code>{"--expected-bucket-owner string"}</code></td><td>Account ID of the expected bucket owner</td></tr>

    <tr>
      <td>
        <code>
          {"--json"}
        </code>
      </td>

      <td>Emit the full JSON payload (mutually exclusive with <code>-q</code>)</td>
    </tr>

    <tr>
      <td>
        <code>
          {"-q, --query stringArray"}
        </code>
      </td>

      <td>jq filter for value extraction (see <a href="/docs/cli/query-output">Query output with <code>-q</code></a>)</td>
    </tr>
  </tbody>
</table>

### Example

```bash theme={null}
nscale s3api get-bucket-tagging --bucket my-bucket -q '.TagSet[] | "\(.Key)=\(.Value)"'
```

***

## put-bucket-tagging

Set the tags of a bucket, replacing any existing tags. Pass the tags as `key=value` pairs with `--tags`, or as JSON in the SDK `Tagging` shape with `--tagging`. Use `--tagging` when a value contains a comma.

```bash theme={null}
nscale s3api put-bucket-tagging --bucket <bucket> (--tags <pairs> | --tagging <json>) [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The name of the bucket</td></tr>
    <tr><td><code>{"--checksum-algorithm string"}</code></td><td>Algorithm used to create the request checksum (<code>CRC32</code> | <code>CRC32C</code> | <code>CRC64NVME</code> | <code>SHA1</code> | <code>SHA256</code>)</td></tr>
    <tr><td><code>{"--content-md5 string"}</code></td><td>Base64-encoded 128-bit MD5 digest of the data</td></tr>
    <tr><td><code>{"--expected-bucket-owner string"}</code></td><td>Account ID of the expected bucket owner</td></tr>
    <tr><td><code>{"--tagging string"}</code></td><td>Tag-set, as JSON matching the SDK Tagging shape or a <code>file://</code> reference; required unless <code>{"--tags"}</code> is given</td></tr>
    <tr><td><code>{"--tags string"}</code></td><td>Tag-set shorthand as <code>key=value</code> pairs, or a <code>file://</code> reference to them; an alternative to <code>{"--tagging"}</code>. Use <code>{"--tagging"}</code> for values that contain a comma</td></tr>
  </tbody>
</table>

### Examples

```bash theme={null}
nscale s3api put-bucket-tagging --bucket my-bucket --tags 'env=prod,team=data'
nscale s3api put-bucket-tagging --bucket my-bucket --tagging '{"TagSet":[{"Key":"env","Value":"prod"}]}'
```

***

## delete-bucket-tagging

Delete the tags from a bucket.

```bash theme={null}
nscale s3api delete-bucket-tagging --bucket <bucket> [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The name of the bucket</td></tr>
    <tr><td><code>{"--expected-bucket-owner string"}</code></td><td>Account ID of the expected bucket owner</td></tr>
  </tbody>
</table>

### Example

```bash theme={null}
nscale s3api delete-bucket-tagging --bucket my-bucket
```

***

## list-objects-v2

List the objects in a bucket with the S3 ListObjectsV2 operation. Use `--prefix` to list a "directory" and `--delimiter /` to group deeper keys into `CommonPrefixes`.

```bash theme={null}
nscale s3api list-objects-v2 --bucket <bucket> [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The bucket to list objects from</td></tr>
    <tr><td><code>{"--delimiter string"}</code></td><td>Character used to group keys into common prefixes</td></tr>
    <tr><td><code>{"--encoding-type string"}</code></td><td>Encoding used for object keys in the response (<code>url</code>)</td></tr>
    <tr><td><code>{"--expected-bucket-owner string"}</code></td><td>Account ID of the expected bucket owner</td></tr>
    <tr><td><code>{"--fetch-owner"}</code></td><td>Return the owner field for each key</td></tr>
    <tr><td><code>{"--max-items int32"}</code></td><td>Total number of items to return across all pages</td></tr>
    <tr><td><code>{"--page-size int32"}</code></td><td>Number of items to request per service call</td></tr>
    <tr><td><code>{"--prefix string"}</code></td><td>Limit the response to keys that begin with this prefix</td></tr>
    <tr><td><code>{"--request-payer string"}</code></td><td>Confirms the requester will be charged for the request (<code>requester</code>)</td></tr>
    <tr><td><code>{"--start-after string"}</code></td><td>Start listing after this key</td></tr>
    <tr><td><code>{"--starting-token string"}</code></td><td>Pagination token marking where a previous listing should resume</td></tr>

    <tr>
      <td>
        <code>
          {"--json"}
        </code>
      </td>

      <td>Emit the full JSON payload (mutually exclusive with <code>-q</code>)</td>
    </tr>

    <tr>
      <td>
        <code>
          {"-q, --query stringArray"}
        </code>
      </td>

      <td>jq filter for value extraction (see <a href="/docs/cli/query-output">Query output with <code>-q</code></a>)</td>
    </tr>
  </tbody>
</table>

### Examples

```bash theme={null}
nscale s3api list-objects-v2 --bucket my-bucket
nscale s3api list-objects-v2 --bucket my-bucket --prefix logs/ --delimiter / -q '.CommonPrefixes[]?.Prefix'
nscale s3api list-objects-v2 --bucket my-bucket --max-items 100 -q '.Contents[]?.Key'
```

***

## list-objects

List the objects in a bucket with the legacy S3 ListObjects (V1) operation. Prefer [`list-objects-v2`](#list-objects-v2) unless a tool depends on the V1 response shape.

```bash theme={null}
nscale s3api list-objects --bucket <bucket> [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The bucket to list objects from</td></tr>
    <tr><td><code>{"--delimiter string"}</code></td><td>Character used to group keys into common prefixes</td></tr>
    <tr><td><code>{"--encoding-type string"}</code></td><td>Encoding used for object keys in the response (<code>url</code>)</td></tr>
    <tr><td><code>{"--expected-bucket-owner string"}</code></td><td>Account ID of the expected bucket owner</td></tr>
    <tr><td><code>{"--marker string"}</code></td><td>Key to start listing from</td></tr>
    <tr><td><code>{"--max-items int32"}</code></td><td>Total number of items to return across all pages</td></tr>
    <tr><td><code>{"--page-size int32"}</code></td><td>Number of items to request per service call</td></tr>
    <tr><td><code>{"--prefix string"}</code></td><td>Limit the response to keys that begin with this prefix</td></tr>
    <tr><td><code>{"--request-payer string"}</code></td><td>Confirms the requester will be charged for the request (<code>requester</code>)</td></tr>
    <tr><td><code>{"--starting-token string"}</code></td><td>Pagination token marking where a previous listing should resume</td></tr>

    <tr>
      <td>
        <code>
          {"--json"}
        </code>
      </td>

      <td>Emit the full JSON payload (mutually exclusive with <code>-q</code>)</td>
    </tr>

    <tr>
      <td>
        <code>
          {"-q, --query stringArray"}
        </code>
      </td>

      <td>jq filter for value extraction (see <a href="/docs/cli/query-output">Query output with <code>-q</code></a>)</td>
    </tr>
  </tbody>
</table>

### Example

```bash theme={null}
nscale s3api list-objects --bucket my-bucket --prefix logs/
```

***

## list-object-versions

List every version of the objects in a bucket, and any delete markers.

```bash theme={null}
nscale s3api list-object-versions --bucket <bucket> [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The bucket to list object versions from</td></tr>
    <tr><td><code>{"--delimiter string"}</code></td><td>Character used to group keys into common prefixes</td></tr>
    <tr><td><code>{"--encoding-type string"}</code></td><td>Encoding used for object keys in the response (<code>url</code>)</td></tr>
    <tr><td><code>{"--expected-bucket-owner string"}</code></td><td>Account ID of the expected bucket owner</td></tr>
    <tr><td><code>{"--key-marker string"}</code></td><td>Key to start listing from</td></tr>
    <tr><td><code>{"--max-items int32"}</code></td><td>Total number of items to return across all pages</td></tr>
    <tr><td><code>{"--page-size int32"}</code></td><td>Number of items to request per service call</td></tr>
    <tr><td><code>{"--prefix string"}</code></td><td>Limit the response to keys that begin with this prefix</td></tr>
    <tr><td><code>{"--request-payer string"}</code></td><td>Confirms the requester will be charged for the request (<code>requester</code>)</td></tr>
    <tr><td><code>{"--starting-token string"}</code></td><td>Pagination token marking where a previous listing should resume</td></tr>
    <tr><td><code>{"--version-id-marker string"}</code></td><td>Version ID to start listing from</td></tr>

    <tr>
      <td>
        <code>
          {"--json"}
        </code>
      </td>

      <td>Emit the full JSON payload (mutually exclusive with <code>-q</code>)</td>
    </tr>

    <tr>
      <td>
        <code>
          {"-q, --query stringArray"}
        </code>
      </td>

      <td>jq filter for value extraction (see <a href="/docs/cli/query-output">Query output with <code>-q</code></a>)</td>
    </tr>
  </tbody>
</table>

### Examples

```bash theme={null}
nscale s3api list-object-versions --bucket my-bucket --prefix data.csv
nscale s3api list-object-versions --bucket my-bucket -q '.Versions[]?.VersionId'
```

***

## put-object

Upload an object to a bucket. The body streams from the file named by `--body`, or from stdin when `--body -` is passed, so large files are not read into memory. Omitting `--body` creates an empty object.

```bash theme={null}
nscale s3api put-object --bucket <bucket> --key <key> [--body <path>] [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The target bucket</td></tr>
    <tr><td><code>{"--key string"}</code></td><td><strong>Required.</strong> The object key</td></tr>
    <tr><td><code>{"--body string"}</code></td><td>Path to the object data; <code>-</code> reads from stdin (streamed, not buffered); omitted uploads an empty object</td></tr>
    <tr><td><code>{"--content-type string"}</code></td><td>Standard MIME type describing the content format</td></tr>
    <tr><td><code>{"--metadata string"}</code></td><td>Metadata to store with the object, as JSON or <code>key=value</code> pairs (or a <code>file://</code> reference)</td></tr>
    <tr><td><code>{"--tagging string"}</code></td><td>Tag-set for the object, URL query encoded</td></tr>

    <tr>
      <td>
        <code>
          {"--json"}
        </code>
      </td>

      <td>Emit the full JSON payload (mutually exclusive with <code>-q</code>)</td>
    </tr>

    <tr>
      <td>
        <code>
          {"-q, --query stringArray"}
        </code>
      </td>

      <td>jq filter for value extraction (see <a href="/docs/cli/query-output">Query output with <code>-q</code></a>)</td>
    </tr>
  </tbody>
</table>

<Accordion title="Advanced flags">
  <table>
    <thead><tr><th>Flag</th><th>Description</th></tr></thead>

    <tbody>
      <tr><td><code>{"--acl string"}</code></td><td>Canned ACL to apply to the object</td></tr>
      <tr><td><code>{"--bucket-key-enabled"}</code></td><td>Toggle an S3 Bucket Key for SSE-KMS encryption</td></tr>
      <tr><td><code>{"--cache-control string"}</code></td><td>Caching behaviour along the request/reply chain</td></tr>
      <tr><td><code>{"--checksum-algorithm string"}</code></td><td>Algorithm used to create the object checksum</td></tr>
      <tr><td><code>{"--checksum-crc32 string"}</code></td><td>Base64 CRC32 checksum for data integrity</td></tr>
      <tr><td><code>{"--checksum-crc32-c string"}</code></td><td>Base64 CRC32C checksum for data integrity</td></tr>
      <tr><td><code>{"--checksum-crc64-nvme string"}</code></td><td>Base64 CRC64NVME checksum for data integrity</td></tr>
      <tr><td><code>{"--checksum-md5 string"}</code></td><td>Base64 MD5 checksum for data integrity</td></tr>
      <tr><td><code>{"--checksum-sha1 string"}</code></td><td>Base64 SHA1 checksum for data integrity</td></tr>
      <tr><td><code>{"--checksum-sha256 string"}</code></td><td>Base64 SHA256 checksum for data integrity</td></tr>
      <tr><td><code>{"--content-disposition string"}</code></td><td>Presentational information for the object</td></tr>
      <tr><td><code>{"--content-encoding string"}</code></td><td>Content encodings applied to the object</td></tr>
      <tr><td><code>{"--content-language string"}</code></td><td>The language the content is in</td></tr>
      <tr><td><code>{"--content-length int"}</code></td><td>Size of the body in bytes</td></tr>
      <tr><td><code>{"--content-md5 string"}</code></td><td>Base64-encoded 128-bit MD5 digest for an integrity check</td></tr>
      <tr><td><code>{"--expected-bucket-owner string"}</code></td><td>Account ID of the expected bucket owner</td></tr>
      <tr><td><code>{"--expires string"}</code></td><td>Date/time the object is no longer cacheable (RFC3339)</td></tr>
      <tr><td><code>{"--grant-full-control string"}</code></td><td>Grants READ, READ\_ACP, and WRITE\_ACP permissions on the object</td></tr>
      <tr><td><code>{"--grant-read string"}</code></td><td>Allows grantee to read the object and its metadata</td></tr>
      <tr><td><code>{"--grant-read-acp string"}</code></td><td>Allows grantee to read the object ACL</td></tr>
      <tr><td><code>{"--grant-write-acp string"}</code></td><td>Allows grantee to write the object ACL</td></tr>
      <tr><td><code>{"--if-match string"}</code></td><td>Upload only if the provided ETag matches the existing object</td></tr>
      <tr><td><code>{"--if-none-match string"}</code></td><td>Upload only if the object key does not already exist</td></tr>
      <tr><td><code>{"--object-lock-legal-hold-status string"}</code></td><td>Whether a legal hold applies to the object (<code>ON</code> | <code>OFF</code>)</td></tr>
      <tr><td><code>{"--object-lock-mode string"}</code></td><td>Object Lock mode to apply to the object (<code>GOVERNANCE</code> | <code>COMPLIANCE</code>)</td></tr>
      <tr><td><code>{"--object-lock-retain-until-date string"}</code></td><td>When the object's Object Lock expires (RFC3339)</td></tr>
      <tr><td><code>{"--request-payer string"}</code></td><td>Confirms the requester will be charged (<code>requester</code>)</td></tr>
      <tr><td><code>{"--server-side-encryption string"}</code></td><td>Server-side encryption algorithm to use (<code>AES256</code> | <code>aws:kms</code> | <code>aws:kms:dsse</code>)</td></tr>
      <tr><td><code>{"--sse-customer-algorithm string"}</code></td><td>Algorithm to use when encrypting the object (SSE-C)</td></tr>
      <tr><td><code>{"--sse-customer-key string"}</code></td><td>Customer-provided encryption key (SSE-C)</td></tr>
      <tr><td><code>{"--sse-customer-key-md5 string"}</code></td><td>128-bit MD5 digest of the SSE-C encryption key</td></tr>
      <tr><td><code>{"--ssekms-encryption-context string"}</code></td><td>Base64-encoded KMS encryption context for the object</td></tr>
      <tr><td><code>{"--ssekms-key-id string"}</code></td><td>KMS key ID to use for object encryption</td></tr>
      <tr><td><code>{"--storage-class string"}</code></td><td>Storage class for the object. Default: <code>STANDARD</code></td></tr>
      <tr><td><code>{"--website-redirect-location string"}</code></td><td>Redirect requests for this object to another object or URL</td></tr>
      <tr><td><code>{"--write-offset-bytes int"}</code></td><td>Offset for appending data to an existing object</td></tr>
    </tbody>
  </table>
</Accordion>

### Examples

```bash theme={null}
nscale s3api put-object --bucket my-bucket --key data.csv --body ./data.csv --content-type text/csv

# Stream from another command
tar -cz ./results | nscale s3api put-object --bucket my-bucket --key results.tar.gz --body -

# Store metadata and tags with the object
nscale s3api put-object --bucket my-bucket --key report.pdf --body ./report.pdf \
  --metadata 'owner=data-team' --tagging 'env=prod&team=data'
```

***

## get-object

Download an object. Without `--outfile`, or with `--outfile -`, the object streams to stdout and nothing else is printed. With `--outfile`, the object is written to that file and the response metadata is printed as JSON. `--json` and `-q` require `--outfile`.

```bash theme={null}
nscale s3api get-object --bucket <bucket> --key <key> [--outfile <path>] [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The bucket containing the object</td></tr>
    <tr><td><code>{"--key string"}</code></td><td><strong>Required.</strong> The key of the object to get</td></tr>
    <tr><td><code>{"--outfile string"}</code></td><td>Path to write the object to; <code>-</code> or omitted streams to stdout</td></tr>
    <tr><td><code>{"--part-number int32"}</code></td><td>Part number of the object being read</td></tr>
    <tr><td><code>{"--range string"}</code></td><td>Download only the specified byte range of the object</td></tr>
    <tr><td><code>{"--version-id string"}</code></td><td>Reference a specific version of the object</td></tr>

    <tr>
      <td>
        <code>
          {"--json"}
        </code>
      </td>

      <td>Emit the full JSON payload (mutually exclusive with <code>-q</code>)</td>
    </tr>

    <tr>
      <td>
        <code>
          {"-q, --query stringArray"}
        </code>
      </td>

      <td>jq filter for value extraction (see <a href="/docs/cli/query-output">Query output with <code>-q</code></a>)</td>
    </tr>
  </tbody>
</table>

<Accordion title="Advanced flags">
  <table>
    <thead><tr><th>Flag</th><th>Description</th></tr></thead>

    <tbody>
      <tr><td><code>{"--checksum-mode string"}</code></td><td>Enable checksum retrieval (<code>ENABLED</code>)</td></tr>
      <tr><td><code>{"--expected-bucket-owner string"}</code></td><td>Account ID of the expected bucket owner</td></tr>
      <tr><td><code>{"--if-match string"}</code></td><td>Return the object only if its ETag matches this value</td></tr>
      <tr><td><code>{"--if-modified-since string"}</code></td><td>Return the object only if modified since this time (RFC3339)</td></tr>
      <tr><td><code>{"--if-none-match string"}</code></td><td>Return the object only if its ETag differs from this value</td></tr>
      <tr><td><code>{"--if-unmodified-since string"}</code></td><td>Return the object only if not modified since this time (RFC3339)</td></tr>
      <tr><td><code>{"--request-payer string"}</code></td><td>Confirms the requester will be charged (<code>requester</code>)</td></tr>
      <tr><td><code>{"--response-cache-control string"}</code></td><td>Sets the Cache-Control header of the response</td></tr>
      <tr><td><code>{"--response-content-disposition string"}</code></td><td>Sets the Content-Disposition header of the response</td></tr>
      <tr><td><code>{"--response-content-encoding string"}</code></td><td>Sets the Content-Encoding header of the response</td></tr>
      <tr><td><code>{"--response-content-language string"}</code></td><td>Sets the Content-Language header of the response</td></tr>
      <tr><td><code>{"--response-content-type string"}</code></td><td>Sets the Content-Type header of the response</td></tr>
      <tr><td><code>{"--response-expires string"}</code></td><td>Sets the Expires header of the response (RFC3339)</td></tr>
      <tr><td><code>{"--sse-customer-algorithm string"}</code></td><td>Algorithm to use when encrypting/decrypting with a customer-provided key (SSE-C)</td></tr>
      <tr><td><code>{"--sse-customer-key string"}</code></td><td>Customer-provided encryption key (SSE-C)</td></tr>
      <tr><td><code>{"--sse-customer-key-md5 string"}</code></td><td>128-bit MD5 digest of the SSE-C encryption key</td></tr>
    </tbody>
  </table>
</Accordion>

### Examples

```bash theme={null}
nscale s3api get-object --bucket my-bucket --key data.csv --outfile ./data.csv

# Stream to another command
nscale s3api get-object --bucket my-bucket --key data.csv | head

# Download the first kilobyte of a specific version
nscale s3api get-object --bucket my-bucket --key data.csv --version-id <version-id> --range bytes=0-1023 --outfile ./head.csv
```

***

## head-object

Get an object's metadata, such as its size, ETag, content type, and user metadata, without downloading it.

```bash theme={null}
nscale s3api head-object --bucket <bucket> --key <key> [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The bucket containing the object</td></tr>
    <tr><td><code>{"--key string"}</code></td><td><strong>Required.</strong> The object key</td></tr>
    <tr><td><code>{"--part-number int32"}</code></td><td>Part number of the object being read</td></tr>
    <tr><td><code>{"--range string"}</code></td><td>HTTP Range header for the requested byte range</td></tr>
    <tr><td><code>{"--version-id string"}</code></td><td>Reference a specific version of the object</td></tr>

    <tr>
      <td>
        <code>
          {"--json"}
        </code>
      </td>

      <td>Emit the full JSON payload (mutually exclusive with <code>-q</code>)</td>
    </tr>

    <tr>
      <td>
        <code>
          {"-q, --query stringArray"}
        </code>
      </td>

      <td>jq filter for value extraction (see <a href="/docs/cli/query-output">Query output with <code>-q</code></a>)</td>
    </tr>
  </tbody>
</table>

<Accordion title="Advanced flags">
  <table>
    <thead><tr><th>Flag</th><th>Description</th></tr></thead>

    <tbody>
      <tr><td><code>{"--checksum-mode string"}</code></td><td>Enable checksum retrieval (<code>ENABLED</code>)</td></tr>
      <tr><td><code>{"--expected-bucket-owner string"}</code></td><td>Account ID of the expected bucket owner</td></tr>
      <tr><td><code>{"--if-match string"}</code></td><td>Return the object only if its ETag matches this value</td></tr>
      <tr><td><code>{"--if-modified-since string"}</code></td><td>Return the object only if modified since this time (RFC3339)</td></tr>
      <tr><td><code>{"--if-none-match string"}</code></td><td>Return the object only if its ETag differs from this value</td></tr>
      <tr><td><code>{"--if-unmodified-since string"}</code></td><td>Return the object only if not modified since this time (RFC3339)</td></tr>
      <tr><td><code>{"--request-payer string"}</code></td><td>Confirms the requester will be charged (<code>requester</code>)</td></tr>
      <tr><td><code>{"--response-cache-control string"}</code></td><td>Sets the Cache-Control header of the response</td></tr>
      <tr><td><code>{"--response-content-disposition string"}</code></td><td>Sets the Content-Disposition header of the response</td></tr>
      <tr><td><code>{"--response-content-encoding string"}</code></td><td>Sets the Content-Encoding header of the response</td></tr>
      <tr><td><code>{"--response-content-language string"}</code></td><td>Sets the Content-Language header of the response</td></tr>
      <tr><td><code>{"--response-content-type string"}</code></td><td>Sets the Content-Type header of the response</td></tr>
      <tr><td><code>{"--response-expires string"}</code></td><td>Sets the Expires header of the response (RFC3339)</td></tr>
      <tr><td><code>{"--sse-customer-algorithm string"}</code></td><td>Algorithm to use when encrypting/decrypting with a customer-provided key (SSE-C)</td></tr>
      <tr><td><code>{"--sse-customer-key string"}</code></td><td>Customer-provided encryption key (SSE-C)</td></tr>
      <tr><td><code>{"--sse-customer-key-md5 string"}</code></td><td>128-bit MD5 digest of the SSE-C encryption key</td></tr>
    </tbody>
  </table>
</Accordion>

### Example

```bash theme={null}
nscale s3api head-object --bucket my-bucket --key data.csv -q '.ContentLength'
```

***

## copy-object

Copy an object that is already stored in object storage. `--copy-source` names the source as `bucket/key`, optionally with `?versionId=<version-id>`; pass the key unencoded, since the CLI URL-encodes it for you.

```bash theme={null}
nscale s3api copy-object --bucket <bucket> --key <key> --copy-source <bucket/key> [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The destination bucket</td></tr>
    <tr><td><code>{"--copy-source string"}</code></td><td><strong>Required.</strong> The source object as <code>bucket/key\[?versionId=...]</code>, given raw/unencoded — the key is URL-encoded for you</td></tr>
    <tr><td><code>{"--key string"}</code></td><td><strong>Required.</strong> The key of the destination object</td></tr>
    <tr><td><code>{"--content-type string"}</code></td><td>Standard MIME type describing the object data</td></tr>
    <tr><td><code>{"--metadata string"}</code></td><td>Metadata to store with the object, as JSON or <code>key=value</code> pairs (with <code>{"--metadata-directive REPLACE"}</code>)</td></tr>
    <tr><td><code>{"--tagging string"}</code></td><td>Tag-set for the destination object, URL query encoded</td></tr>

    <tr>
      <td>
        <code>
          {"--json"}
        </code>
      </td>

      <td>Emit the full JSON payload (mutually exclusive with <code>-q</code>)</td>
    </tr>

    <tr>
      <td>
        <code>
          {"-q, --query stringArray"}
        </code>
      </td>

      <td>jq filter for value extraction (see <a href="/docs/cli/query-output">Query output with <code>-q</code></a>)</td>
    </tr>
  </tbody>
</table>

<Accordion title="Advanced flags">
  <table>
    <thead><tr><th>Flag</th><th>Description</th></tr></thead>

    <tbody>
      <tr><td><code>{"--acl string"}</code></td><td>Canned ACL to apply to the object</td></tr>
      <tr><td><code>{"--bucket-key-enabled"}</code></td><td>Toggle an S3 Bucket Key for SSE-KMS encryption</td></tr>
      <tr><td><code>{"--cache-control string"}</code></td><td>Caching behaviour along the request/reply chain</td></tr>
      <tr><td><code>{"--checksum-algorithm string"}</code></td><td>Algorithm S3 uses to create the object checksum</td></tr>
      <tr><td><code>{"--content-disposition string"}</code></td><td>Presentational information for the object</td></tr>
      <tr><td><code>{"--content-encoding string"}</code></td><td>Content encodings applied to the object</td></tr>
      <tr><td><code>{"--content-language string"}</code></td><td>The language the content is in</td></tr>
      <tr><td><code>{"--copy-source-if-match string"}</code></td><td>Copy only if the source ETag matches this value</td></tr>
      <tr><td><code>{"--copy-source-if-modified-since string"}</code></td><td>Copy only if the source was modified since this time (RFC3339)</td></tr>
      <tr><td><code>{"--copy-source-if-none-match string"}</code></td><td>Copy only if the source ETag differs from this value</td></tr>
      <tr><td><code>{"--copy-source-if-unmodified-since string"}</code></td><td>Copy only if the source was not modified since this time (RFC3339)</td></tr>
      <tr><td><code>{"--copy-source-sse-customer-algorithm string"}</code></td><td>Algorithm to use when decrypting the source object (SSE-C)</td></tr>
      <tr><td><code>{"--copy-source-sse-customer-key string"}</code></td><td>Customer-provided key to decrypt the source object (SSE-C)</td></tr>
      <tr><td><code>{"--copy-source-sse-customer-key-md5 string"}</code></td><td>128-bit MD5 digest of the source SSE-C key</td></tr>
      <tr><td><code>{"--expected-bucket-owner string"}</code></td><td>Account ID of the expected destination bucket owner</td></tr>
      <tr><td><code>{"--expected-source-bucket-owner string"}</code></td><td>Account ID of the expected source bucket owner</td></tr>
      <tr><td><code>{"--expires string"}</code></td><td>Date/time the object is no longer cacheable (RFC3339)</td></tr>
      <tr><td><code>{"--grant-full-control string"}</code></td><td>Grants READ, READ\_ACP, and WRITE\_ACP permissions on the object</td></tr>
      <tr><td><code>{"--grant-read string"}</code></td><td>Allows grantee to read the object and its metadata</td></tr>
      <tr><td><code>{"--grant-read-acp string"}</code></td><td>Allows grantee to read the object ACL</td></tr>
      <tr><td><code>{"--grant-write-acp string"}</code></td><td>Allows grantee to write the object ACL</td></tr>
      <tr><td><code>{"--if-match string"}</code></td><td>Copy only if the destination object ETag matches this value</td></tr>
      <tr><td><code>{"--if-none-match string"}</code></td><td>Copy only if the destination key does not already exist</td></tr>
      <tr><td><code>{"--metadata-directive string"}</code></td><td>Whether metadata is copied from the source or replaced (<code>COPY</code> | <code>REPLACE</code>)</td></tr>
      <tr><td><code>{"--object-lock-legal-hold-status string"}</code></td><td>Whether a legal hold applies to the copy (<code>ON</code> | <code>OFF</code>)</td></tr>
      <tr><td><code>{"--object-lock-mode string"}</code></td><td>Object Lock mode to apply to the copy (<code>GOVERNANCE</code> | <code>COMPLIANCE</code>)</td></tr>
      <tr><td><code>{"--object-lock-retain-until-date string"}</code></td><td>When the copy's Object Lock expires (RFC3339)</td></tr>
      <tr><td><code>{"--request-payer string"}</code></td><td>Confirms the requester will be charged (<code>requester</code>)</td></tr>
      <tr><td><code>{"--server-side-encryption string"}</code></td><td>Server-side encryption algorithm to use (<code>AES256</code> | <code>aws:kms</code> | <code>aws:kms:dsse</code>)</td></tr>
      <tr><td><code>{"--sse-customer-algorithm string"}</code></td><td>Algorithm to use when encrypting the destination object (SSE-C)</td></tr>
      <tr><td><code>{"--sse-customer-key string"}</code></td><td>Customer-provided encryption key (SSE-C)</td></tr>
      <tr><td><code>{"--sse-customer-key-md5 string"}</code></td><td>128-bit MD5 digest of the SSE-C encryption key</td></tr>
      <tr><td><code>{"--ssekms-encryption-context string"}</code></td><td>Base64-encoded KMS encryption context for the destination object</td></tr>
      <tr><td><code>{"--ssekms-key-id string"}</code></td><td>KMS key ID to use for object encryption</td></tr>
      <tr><td><code>{"--storage-class string"}</code></td><td>Storage class for the copied object</td></tr>
      <tr><td><code>{"--tagging-directive string"}</code></td><td>Whether the tag-set is copied from the source or replaced (<code>COPY</code> | <code>REPLACE</code>)</td></tr>
      <tr><td><code>{"--website-redirect-location string"}</code></td><td>Redirect requests for this copy to another object or URL</td></tr>
    </tbody>
  </table>
</Accordion>

### Examples

```bash theme={null}
nscale s3api copy-object --bucket backup-bucket --key data.csv --copy-source my-bucket/data.csv

# Replace the metadata on the copy
nscale s3api copy-object --bucket my-bucket --key data.csv --copy-source my-bucket/data.csv \
  --metadata-directive REPLACE --content-type text/csv --metadata 'owner=data-team'
```

***

## delete-object

Delete an object. In a versioned bucket, this adds a delete marker unless you pass `--version-id` to delete a specific version.

```bash theme={null}
nscale s3api delete-object --bucket <bucket> --key <key> [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The bucket containing the object</td></tr>
    <tr><td><code>{"--key string"}</code></td><td><strong>Required.</strong> The key of the object to delete</td></tr>
    <tr><td><code>{"--version-id string"}</code></td><td>Reference a specific version of the object</td></tr>
    <tr><td><code>{"-y, --yes"}</code></td><td>Automatically confirm object deletion</td></tr>

    <tr>
      <td>
        <code>
          {"--json"}
        </code>
      </td>

      <td>Emit the full JSON payload (mutually exclusive with <code>-q</code>)</td>
    </tr>

    <tr>
      <td>
        <code>
          {"-q, --query stringArray"}
        </code>
      </td>

      <td>jq filter for value extraction (see <a href="/docs/cli/query-output">Query output with <code>-q</code></a>)</td>
    </tr>
  </tbody>
</table>

<Accordion title="Advanced flags">
  <table>
    <thead><tr><th>Flag</th><th>Description</th></tr></thead>

    <tbody>
      <tr><td><code>{"--bypass-governance-retention"}</code></td><td>Bypass Governance-mode Object Lock restrictions</td></tr>
      <tr><td><code>{"--expected-bucket-owner string"}</code></td><td>Account ID of the expected bucket owner</td></tr>
      <tr><td><code>{"--if-match string"}</code></td><td>Delete only if the object's ETag matches this value</td></tr>
      <tr><td><code>{"--if-match-last-modified-time string"}</code></td><td>Delete only if the object's last-modified time matches this value (RFC3339)</td></tr>
      <tr><td><code>{"--if-match-size int"}</code></td><td>Delete only if the object size matches this many bytes</td></tr>
      <tr><td><code>{"--mfa string"}</code></td><td>MFA device serial number and code for versioned deletes</td></tr>
      <tr><td><code>{"--request-payer string"}</code></td><td>Confirms the requester will be charged (<code>requester</code>)</td></tr>
    </tbody>
  </table>
</Accordion>

### Examples

```bash theme={null}
nscale s3api delete-object --bucket my-bucket --key data.csv --yes
nscale s3api delete-object --bucket my-bucket --key data.csv --version-id <version-id> --yes
```

***

## delete-objects

Delete multiple objects from a bucket in a single request. `--delete` takes JSON in the SDK `Delete` shape, or a `file://` reference to it.

```bash theme={null}
nscale s3api delete-objects --bucket <bucket> --delete <json> [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The bucket containing the objects</td></tr>
    <tr><td><code>{"--delete string"}</code></td><td><strong>Required.</strong> Objects to delete, as JSON matching the SDK Delete shape or a <code>file://</code> reference</td></tr>
    <tr><td><code>{"-y, --yes"}</code></td><td>Automatically confirm object deletion</td></tr>

    <tr>
      <td>
        <code>
          {"--json"}
        </code>
      </td>

      <td>Emit the full JSON payload (mutually exclusive with <code>-q</code>)</td>
    </tr>

    <tr>
      <td>
        <code>
          {"-q, --query stringArray"}
        </code>
      </td>

      <td>jq filter for value extraction (see <a href="/docs/cli/query-output">Query output with <code>-q</code></a>)</td>
    </tr>
  </tbody>
</table>

<Accordion title="Advanced flags">
  <table>
    <thead><tr><th>Flag</th><th>Description</th></tr></thead>

    <tbody>
      <tr><td><code>{"--bypass-governance-retention"}</code></td><td>Bypass Governance-mode Object Lock restrictions</td></tr>
      <tr><td><code>{"--checksum-algorithm string"}</code></td><td>Algorithm used to create the object checksum (<code>CRC32</code> | <code>CRC32C</code> | <code>CRC64NVME</code> | <code>SHA1</code> | <code>SHA256</code>)</td></tr>
      <tr><td><code>{"--expected-bucket-owner string"}</code></td><td>Account ID of the expected bucket owner</td></tr>
      <tr><td><code>{"--mfa string"}</code></td><td>MFA device serial number and code for versioned deletes</td></tr>
      <tr><td><code>{"--request-payer string"}</code></td><td>Confirms the requester will be charged (<code>requester</code>)</td></tr>
    </tbody>
  </table>
</Accordion>

### Examples

```bash theme={null}
nscale s3api delete-objects --bucket my-bucket --delete '{"Objects":[{"Key":"a.csv"},{"Key":"b.csv"}]}' --yes
nscale s3api delete-objects --bucket my-bucket --delete file://delete.json --yes
```

***

## presign

Generate a pre-signed URL that lets anyone who holds it download the object with a plain HTTP GET until it expires. This is the equivalent of `aws s3 presign`. See [Share objects with pre-signed URLs](/docs/storage/object-storage#share-objects-with-pre-signed-urls) for guidance on using them safely.

The URL is signed locally with the resolved credentials, so it stops working early if the access key is deleted or temporary credentials expire. The command prints the bare URL; `--json` and `-q` return it together with its expiry time as `URL` and `ExpiresAt`.

```bash theme={null}
nscale s3api presign s3://<bucket>/<key> [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--expires-in int"}</code></td><td>Number of seconds until the pre-signed URL expires (max 604800). Default: <code>3600</code></td></tr>

    <tr>
      <td>
        <code>
          {"--json"}
        </code>
      </td>

      <td>Emit the full JSON payload (mutually exclusive with <code>-q</code>)</td>
    </tr>

    <tr>
      <td>
        <code>
          {"-q, --query stringArray"}
        </code>
      </td>

      <td>jq filter for value extraction (see <a href="/docs/cli/query-output">Query output with <code>-q</code></a>)</td>
    </tr>
  </tbody>
</table>

### Examples

```bash theme={null}
# Valid for 1 hour (the default)
nscale s3api presign s3://my-bucket/report.pdf

# Valid for 7 days, the maximum
nscale s3api presign s3://my-bucket/report.pdf --expires-in 604800

# Download with the URL, no credentials required
curl -fSL -o report.pdf "$(nscale s3api presign s3://my-bucket/report.pdf)"
```

***

## get-object-tagging

Get the tag-set of an object.

```bash theme={null}
nscale s3api get-object-tagging --bucket <bucket> --key <key> [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The name of the bucket</td></tr>
    <tr><td><code>{"--key string"}</code></td><td><strong>Required.</strong> Object key to get the tagging for</td></tr>
    <tr><td><code>{"--expected-bucket-owner string"}</code></td><td>Account ID of the expected bucket owner</td></tr>
    <tr><td><code>{"--request-payer string"}</code></td><td>Confirms the requester will be charged (<code>requester</code>)</td></tr>
    <tr><td><code>{"--version-id string"}</code></td><td>Version ID of the object</td></tr>

    <tr>
      <td>
        <code>
          {"--json"}
        </code>
      </td>

      <td>Emit the full JSON payload (mutually exclusive with <code>-q</code>)</td>
    </tr>

    <tr>
      <td>
        <code>
          {"-q, --query stringArray"}
        </code>
      </td>

      <td>jq filter for value extraction (see <a href="/docs/cli/query-output">Query output with <code>-q</code></a>)</td>
    </tr>
  </tbody>
</table>

### Example

```bash theme={null}
nscale s3api get-object-tagging --bucket my-bucket --key data.csv -q '.TagSet'
```

***

## put-object-tagging

Set the tag-set of an object, replacing any existing tags. Pass the tags as `key=value` pairs with `--tags`, or as JSON in the SDK `Tagging` shape with `--tagging`. Use `--tagging` when a value contains a comma.

```bash theme={null}
nscale s3api put-object-tagging --bucket <bucket> --key <key> (--tags <pairs> | --tagging <json>) [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The name of the bucket</td></tr>
    <tr><td><code>{"--key string"}</code></td><td><strong>Required.</strong> Name of the object key</td></tr>
    <tr><td><code>{"--tagging string"}</code></td><td>Tag-set, as JSON matching the SDK Tagging shape or a <code>file://</code> reference; required unless <code>{"--tags"}</code> is given</td></tr>
    <tr><td><code>{"--tags string"}</code></td><td>Tag-set shorthand as <code>key=value</code> pairs, or a <code>file://</code> reference to them; an alternative to <code>{"--tagging"}</code>. Use <code>{"--tagging"}</code> for values that contain a comma</td></tr>
    <tr><td><code>{"--version-id string"}</code></td><td>Version ID the tag-set is added to</td></tr>

    <tr>
      <td>
        <code>
          {"--json"}
        </code>
      </td>

      <td>Emit the full JSON payload (mutually exclusive with <code>-q</code>)</td>
    </tr>

    <tr>
      <td>
        <code>
          {"-q, --query stringArray"}
        </code>
      </td>

      <td>jq filter for value extraction (see <a href="/docs/cli/query-output">Query output with <code>-q</code></a>)</td>
    </tr>
  </tbody>
</table>

<Accordion title="Advanced flags">
  <table>
    <thead><tr><th>Flag</th><th>Description</th></tr></thead>

    <tbody>
      <tr><td><code>{"--checksum-algorithm string"}</code></td><td>Algorithm used to create the request checksum (<code>CRC32</code> | <code>CRC32C</code> | <code>CRC64NVME</code> | <code>SHA1</code> | <code>SHA256</code>)</td></tr>
      <tr><td><code>{"--content-md5 string"}</code></td><td>MD5 hash for the request body</td></tr>
      <tr><td><code>{"--expected-bucket-owner string"}</code></td><td>Account ID of the expected bucket owner</td></tr>
      <tr><td><code>{"--request-payer string"}</code></td><td>Confirms the requester will be charged (<code>requester</code>)</td></tr>
    </tbody>
  </table>
</Accordion>

### Examples

```bash theme={null}
nscale s3api put-object-tagging --bucket my-bucket --key data.csv --tags 'env=prod,team=data'
nscale s3api put-object-tagging --bucket my-bucket --key data.csv --tagging '{"TagSet":[{"Key":"env","Value":"prod"}]}'
```

***

## delete-object-tagging

Remove the entire tag-set from an object.

```bash theme={null}
nscale s3api delete-object-tagging --bucket <bucket> --key <key> [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The name of the bucket</td></tr>
    <tr><td><code>{"--key string"}</code></td><td><strong>Required.</strong> Key identifying the object to remove tags from</td></tr>
    <tr><td><code>{"--expected-bucket-owner string"}</code></td><td>Account ID of the expected bucket owner</td></tr>
    <tr><td><code>{"--version-id string"}</code></td><td>Version ID the tag-set is removed from</td></tr>

    <tr>
      <td>
        <code>
          {"--json"}
        </code>
      </td>

      <td>Emit the full JSON payload (mutually exclusive with <code>-q</code>)</td>
    </tr>

    <tr>
      <td>
        <code>
          {"-q, --query stringArray"}
        </code>
      </td>

      <td>jq filter for value extraction (see <a href="/docs/cli/query-output">Query output with <code>-q</code></a>)</td>
    </tr>
  </tbody>
</table>

### Example

```bash theme={null}
nscale s3api delete-object-tagging --bucket my-bucket --key data.csv
```

***

## create-multipart-upload

Start a multipart upload and return its `UploadId`. Upload the parts with [`upload-part`](#upload-part) or [`upload-part-copy`](#upload-part-copy), then assemble them with [`complete-multipart-upload`](#complete-multipart-upload). The object's metadata, tags, and storage class are set here, not when the upload completes.

```bash theme={null}
nscale s3api create-multipart-upload --bucket <bucket> --key <key> [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The bucket to create the object in</td></tr>
    <tr><td><code>{"--key string"}</code></td><td><strong>Required.</strong> The object key</td></tr>
    <tr><td><code>{"--content-type string"}</code></td><td>Standard MIME type describing the content format</td></tr>
    <tr><td><code>{"--metadata string"}</code></td><td>Metadata to store with the object, as JSON or <code>key=value</code> pairs (or a <code>file://</code> reference)</td></tr>
    <tr><td><code>{"--tagging string"}</code></td><td>Tag-set for the object, URL query encoded</td></tr>

    <tr>
      <td>
        <code>
          {"--json"}
        </code>
      </td>

      <td>Emit the full JSON payload (mutually exclusive with <code>-q</code>)</td>
    </tr>

    <tr>
      <td>
        <code>
          {"-q, --query stringArray"}
        </code>
      </td>

      <td>jq filter for value extraction (see <a href="/docs/cli/query-output">Query output with <code>-q</code></a>)</td>
    </tr>
  </tbody>
</table>

<Accordion title="Advanced flags">
  <table>
    <thead><tr><th>Flag</th><th>Description</th></tr></thead>

    <tbody>
      <tr><td><code>{"--acl string"}</code></td><td>Canned ACL to apply to the object</td></tr>
      <tr><td><code>{"--bucket-key-enabled"}</code></td><td>Toggle an S3 Bucket Key for SSE-KMS encryption</td></tr>
      <tr><td><code>{"--cache-control string"}</code></td><td>Caching behaviour along the request/reply chain</td></tr>
      <tr><td><code>{"--checksum-algorithm string"}</code></td><td>Algorithm used to create the object checksum</td></tr>
      <tr><td><code>{"--checksum-type string"}</code></td><td>How the object checksum is calculated across parts (<code>COMPOSITE</code> | <code>FULL\_OBJECT</code>)</td></tr>
      <tr><td><code>{"--content-disposition string"}</code></td><td>Presentational information for the object</td></tr>
      <tr><td><code>{"--content-encoding string"}</code></td><td>Content encodings applied to the object</td></tr>
      <tr><td><code>{"--content-language string"}</code></td><td>The language the content is in</td></tr>
      <tr><td><code>{"--expected-bucket-owner string"}</code></td><td>Account ID of the expected bucket owner</td></tr>
      <tr><td><code>{"--expires string"}</code></td><td>Date/time the object is no longer cacheable (RFC3339)</td></tr>
      <tr><td><code>{"--grant-full-control string"}</code></td><td>Grants READ, READ\_ACP, and WRITE\_ACP permissions on the object</td></tr>
      <tr><td><code>{"--grant-read string"}</code></td><td>Allows grantee to read the object and its metadata</td></tr>
      <tr><td><code>{"--grant-read-acp string"}</code></td><td>Allows grantee to read the object ACL</td></tr>
      <tr><td><code>{"--grant-write-acp string"}</code></td><td>Allows grantee to write the object ACL</td></tr>
      <tr><td><code>{"--object-lock-legal-hold-status string"}</code></td><td>Whether a legal hold applies to the object (<code>ON</code> | <code>OFF</code>)</td></tr>
      <tr><td><code>{"--object-lock-mode string"}</code></td><td>Object Lock mode to apply to the object (<code>GOVERNANCE</code> | <code>COMPLIANCE</code>)</td></tr>
      <tr><td><code>{"--object-lock-retain-until-date string"}</code></td><td>When the object's Object Lock expires (RFC3339)</td></tr>
      <tr><td><code>{"--request-payer string"}</code></td><td>Confirms the requester will be charged (<code>requester</code>)</td></tr>
      <tr><td><code>{"--server-side-encryption string"}</code></td><td>Server-side encryption algorithm to use (<code>AES256</code> | <code>aws:kms</code> | <code>aws:kms:dsse</code>)</td></tr>
      <tr><td><code>{"--sse-customer-algorithm string"}</code></td><td>Algorithm to use when encrypting/decrypting with a customer-provided key (SSE-C)</td></tr>
      <tr><td><code>{"--sse-customer-key string"}</code></td><td>Customer-provided encryption key (SSE-C)</td></tr>
      <tr><td><code>{"--sse-customer-key-md5 string"}</code></td><td>128-bit MD5 digest of the SSE-C encryption key</td></tr>
      <tr><td><code>{"--ssekms-encryption-context string"}</code></td><td>Base64-encoded KMS encryption context for the object</td></tr>
      <tr><td><code>{"--ssekms-key-id string"}</code></td><td>KMS key ID to use for object encryption</td></tr>
      <tr><td><code>{"--storage-class string"}</code></td><td>Storage class for the object. Default: <code>STANDARD</code></td></tr>
      <tr><td><code>{"--website-redirect-location string"}</code></td><td>Redirect requests for this object to another object or URL</td></tr>
    </tbody>
  </table>
</Accordion>

### Example

```bash theme={null}
UPLOAD_ID=$(nscale s3api create-multipart-upload --bucket my-bucket --key large.bin -q '.UploadId')
```

***

## upload-part

Upload one part of a multipart upload. Part numbers run from 1 to 10000. The body streams from the file named by `--body`, or from stdin with `--body -`. Keep the `ETag` from each response: [`complete-multipart-upload`](#complete-multipart-upload) needs it.

```bash theme={null}
nscale s3api upload-part --bucket <bucket> --key <key> --upload-id <upload-id> --part-number <n> --body <path> [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The target bucket</td></tr>
    <tr><td><code>{"--key string"}</code></td><td><strong>Required.</strong> The object key</td></tr>
    <tr><td><code>{"--part-number int32"}</code></td><td><strong>Required.</strong> The part number, between 1 and 10000</td></tr>
    <tr><td><code>{"--upload-id string"}</code></td><td><strong>Required.</strong> The ID identifying the multipart upload</td></tr>
    <tr><td><code>{"--body string"}</code></td><td>Path to the part data; <code>-</code> reads from stdin (streamed, not buffered); omitted uploads an empty part</td></tr>

    <tr>
      <td>
        <code>
          {"--json"}
        </code>
      </td>

      <td>Emit the full JSON payload (mutually exclusive with <code>-q</code>)</td>
    </tr>

    <tr>
      <td>
        <code>
          {"-q, --query stringArray"}
        </code>
      </td>

      <td>jq filter for value extraction (see <a href="/docs/cli/query-output">Query output with <code>-q</code></a>)</td>
    </tr>
  </tbody>
</table>

<Accordion title="Advanced flags">
  <table>
    <thead><tr><th>Flag</th><th>Description</th></tr></thead>

    <tbody>
      <tr><td><code>{"--checksum-algorithm string"}</code></td><td>Algorithm used to create the part checksum</td></tr>
      <tr><td><code>{"--checksum-crc32 string"}</code></td><td>Base64 CRC32 checksum for data integrity</td></tr>
      <tr><td><code>{"--checksum-crc32-c string"}</code></td><td>Base64 CRC32C checksum for data integrity</td></tr>
      <tr><td><code>{"--checksum-crc64-nvme string"}</code></td><td>Base64 CRC64NVME checksum for data integrity</td></tr>
      <tr><td><code>{"--checksum-sha1 string"}</code></td><td>Base64 SHA1 checksum for data integrity</td></tr>
      <tr><td><code>{"--checksum-sha256 string"}</code></td><td>Base64 SHA256 checksum for data integrity</td></tr>
      <tr><td><code>{"--content-length int"}</code></td><td>Size of the body in bytes</td></tr>
      <tr><td><code>{"--content-md5 string"}</code></td><td>Base64-encoded 128-bit MD5 digest for an integrity check</td></tr>
      <tr><td><code>{"--expected-bucket-owner string"}</code></td><td>Account ID of the expected bucket owner</td></tr>
      <tr><td><code>{"--request-payer string"}</code></td><td>Confirms the requester will be charged (<code>requester</code>)</td></tr>
      <tr><td><code>{"--sse-customer-algorithm string"}</code></td><td>Algorithm to use when encrypting/decrypting with a customer-provided key (SSE-C); must match the create-multipart-upload request</td></tr>
      <tr><td><code>{"--sse-customer-key string"}</code></td><td>Customer-provided encryption key (SSE-C)</td></tr>
      <tr><td><code>{"--sse-customer-key-md5 string"}</code></td><td>128-bit MD5 digest of the SSE-C encryption key</td></tr>
    </tbody>
  </table>
</Accordion>

### Example

```bash theme={null}
nscale s3api upload-part --bucket my-bucket --key large.bin --upload-id "$UPLOAD_ID" \
  --part-number 1 --body ./large.bin.part1 -q '.ETag'
```

***

## upload-part-copy

Upload one part of a multipart upload by copying data from an existing object. Use `--copy-source-range` to copy only part of the source object.

```bash theme={null}
nscale s3api upload-part-copy --bucket <bucket> --key <key> --upload-id <upload-id> --part-number <n> --copy-source <bucket/key> [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The destination bucket</td></tr>
    <tr><td><code>{"--copy-source string"}</code></td><td><strong>Required.</strong> The source object as <code>bucket/key\[?versionId=...]</code>, given raw/unencoded — the key is URL-encoded for you</td></tr>
    <tr><td><code>{"--key string"}</code></td><td><strong>Required.</strong> The key of the destination object</td></tr>
    <tr><td><code>{"--part-number int32"}</code></td><td><strong>Required.</strong> The part number, between 1 and 10000</td></tr>
    <tr><td><code>{"--upload-id string"}</code></td><td><strong>Required.</strong> The ID identifying the multipart upload</td></tr>
    <tr><td><code>{"--copy-source-range string"}</code></td><td>The byte range of the source object to copy</td></tr>

    <tr>
      <td>
        <code>
          {"--json"}
        </code>
      </td>

      <td>Emit the full JSON payload (mutually exclusive with <code>-q</code>)</td>
    </tr>

    <tr>
      <td>
        <code>
          {"-q, --query stringArray"}
        </code>
      </td>

      <td>jq filter for value extraction (see <a href="/docs/cli/query-output">Query output with <code>-q</code></a>)</td>
    </tr>
  </tbody>
</table>

<Accordion title="Advanced flags">
  <table>
    <thead><tr><th>Flag</th><th>Description</th></tr></thead>

    <tbody>
      <tr><td><code>{"--copy-source-if-match string"}</code></td><td>Copy only if the source ETag matches this value</td></tr>
      <tr><td><code>{"--copy-source-if-modified-since string"}</code></td><td>Copy only if the source was modified since this time (RFC3339)</td></tr>
      <tr><td><code>{"--copy-source-if-none-match string"}</code></td><td>Copy only if the source ETag differs from this value</td></tr>
      <tr><td><code>{"--copy-source-if-unmodified-since string"}</code></td><td>Copy only if the source was not modified since this time (RFC3339)</td></tr>
      <tr><td><code>{"--copy-source-sse-customer-algorithm string"}</code></td><td>Algorithm to use when decrypting the source object (SSE-C)</td></tr>
      <tr><td><code>{"--copy-source-sse-customer-key string"}</code></td><td>Customer-provided key to decrypt the source object (SSE-C)</td></tr>
      <tr><td><code>{"--copy-source-sse-customer-key-md5 string"}</code></td><td>128-bit MD5 digest of the source SSE-C key</td></tr>
      <tr><td><code>{"--expected-bucket-owner string"}</code></td><td>Account ID of the expected destination bucket owner</td></tr>
      <tr><td><code>{"--expected-source-bucket-owner string"}</code></td><td>Account ID of the expected source bucket owner</td></tr>
      <tr><td><code>{"--request-payer string"}</code></td><td>Confirms the requester will be charged (<code>requester</code>)</td></tr>
      <tr><td><code>{"--sse-customer-algorithm string"}</code></td><td>Algorithm to use when encrypting/decrypting with a customer-provided key (SSE-C)</td></tr>
      <tr><td><code>{"--sse-customer-key string"}</code></td><td>Customer-provided encryption key (SSE-C)</td></tr>
      <tr><td><code>{"--sse-customer-key-md5 string"}</code></td><td>128-bit MD5 digest of the SSE-C encryption key</td></tr>
    </tbody>
  </table>
</Accordion>

### Example

```bash theme={null}
nscale s3api upload-part-copy --bucket my-bucket --key large.bin --upload-id "$UPLOAD_ID" \
  --part-number 2 --copy-source my-bucket/source.bin --copy-source-range bytes=0-104857599
```

***

## list-parts

List the parts uploaded so far for a multipart upload.

```bash theme={null}
nscale s3api list-parts --bucket <bucket> --key <key> --upload-id <upload-id> [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The bucket the multipart upload targets</td></tr>
    <tr><td><code>{"--key string"}</code></td><td><strong>Required.</strong> The object key of the multipart upload</td></tr>
    <tr><td><code>{"--upload-id string"}</code></td><td><strong>Required.</strong> The ID identifying the multipart upload</td></tr>
    <tr><td><code>{"--max-items int32"}</code></td><td>Total number of items to return across all pages</td></tr>
    <tr><td><code>{"--page-size int32"}</code></td><td>Number of items to request per service call</td></tr>
    <tr><td><code>{"--part-number-marker string"}</code></td><td>Part number after which listing begins</td></tr>
    <tr><td><code>{"--starting-token string"}</code></td><td>Pagination token marking where a previous listing should resume</td></tr>

    <tr>
      <td>
        <code>
          {"--json"}
        </code>
      </td>

      <td>Emit the full JSON payload (mutually exclusive with <code>-q</code>)</td>
    </tr>

    <tr>
      <td>
        <code>
          {"-q, --query stringArray"}
        </code>
      </td>

      <td>jq filter for value extraction (see <a href="/docs/cli/query-output">Query output with <code>-q</code></a>)</td>
    </tr>
  </tbody>
</table>

<Accordion title="Advanced flags">
  <table>
    <thead><tr><th>Flag</th><th>Description</th></tr></thead>

    <tbody>
      <tr><td><code>{"--expected-bucket-owner string"}</code></td><td>Account ID of the expected bucket owner</td></tr>
      <tr><td><code>{"--request-payer string"}</code></td><td>Confirms the requester will be charged for the request (<code>requester</code>)</td></tr>
      <tr><td><code>{"--sse-customer-algorithm string"}</code></td><td>Algorithm to use when encrypting/decrypting with a customer-provided key (SSE-C); must match the create-multipart-upload request</td></tr>
      <tr><td><code>{"--sse-customer-key string"}</code></td><td>Customer-provided encryption key (SSE-C)</td></tr>
      <tr><td><code>{"--sse-customer-key-md5 string"}</code></td><td>128-bit MD5 digest of the SSE-C encryption key</td></tr>
    </tbody>
  </table>
</Accordion>

### Example

```bash theme={null}
nscale s3api list-parts --bucket my-bucket --key large.bin --upload-id "$UPLOAD_ID" \
  -q '.Parts[]?.PartNumber' -q '.Parts[]?.ETag'
```

***

## list-multipart-uploads

List the multipart uploads in a bucket that have started but not yet been completed or aborted. Incomplete uploads keep their parts stored until you abort them.

```bash theme={null}
nscale s3api list-multipart-uploads --bucket <bucket> [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The bucket to list multipart uploads from</td></tr>
    <tr><td><code>{"--delimiter string"}</code></td><td>Character used to group keys into common prefixes</td></tr>
    <tr><td><code>{"--encoding-type string"}</code></td><td>Encoding used for object keys in the response (<code>url</code>)</td></tr>
    <tr><td><code>{"--expected-bucket-owner string"}</code></td><td>Account ID of the expected bucket owner</td></tr>
    <tr><td><code>{"--key-marker string"}</code></td><td>Key to start listing from</td></tr>
    <tr><td><code>{"--max-items int32"}</code></td><td>Total number of items to return across all pages</td></tr>
    <tr><td><code>{"--page-size int32"}</code></td><td>Number of items to request per service call</td></tr>
    <tr><td><code>{"--prefix string"}</code></td><td>Limit the response to keys that begin with this prefix</td></tr>
    <tr><td><code>{"--request-payer string"}</code></td><td>Confirms the requester will be charged for the request (<code>requester</code>)</td></tr>
    <tr><td><code>{"--starting-token string"}</code></td><td>Pagination token marking where a previous listing should resume</td></tr>
    <tr><td><code>{"--upload-id-marker string"}</code></td><td>Upload ID to start listing from (used with <code>{"--key-marker"}</code>)</td></tr>

    <tr>
      <td>
        <code>
          {"--json"}
        </code>
      </td>

      <td>Emit the full JSON payload (mutually exclusive with <code>-q</code>)</td>
    </tr>

    <tr>
      <td>
        <code>
          {"-q, --query stringArray"}
        </code>
      </td>

      <td>jq filter for value extraction (see <a href="/docs/cli/query-output">Query output with <code>-q</code></a>)</td>
    </tr>
  </tbody>
</table>

### Example

```bash theme={null}
nscale s3api list-multipart-uploads --bucket my-bucket -q '.Uploads[]?.Key' -q '.Uploads[]?.UploadId'
```

***

## complete-multipart-upload

Complete a multipart upload by assembling its parts into one object. `--multipart-upload` lists every part by `PartNumber` and `ETag`, as JSON in the SDK `CompletedMultipartUpload` shape or a `file://` reference to it. The quickest way to build it is from [`list-parts`](#list-parts).

```bash theme={null}
nscale s3api complete-multipart-upload --bucket <bucket> --key <key> --upload-id <upload-id> --multipart-upload <json> [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The target bucket</td></tr>
    <tr><td><code>{"--key string"}</code></td><td><strong>Required.</strong> The object key</td></tr>
    <tr><td><code>{"--multipart-upload string"}</code></td><td><strong>Required.</strong> The parts to assemble, as JSON or a <code>file://</code> reference</td></tr>
    <tr><td><code>{"--upload-id string"}</code></td><td><strong>Required.</strong> The ID identifying the multipart upload</td></tr>

    <tr>
      <td>
        <code>
          {"--json"}
        </code>
      </td>

      <td>Emit the full JSON payload (mutually exclusive with <code>-q</code>)</td>
    </tr>

    <tr>
      <td>
        <code>
          {"-q, --query stringArray"}
        </code>
      </td>

      <td>jq filter for value extraction (see <a href="/docs/cli/query-output">Query output with <code>-q</code></a>)</td>
    </tr>
  </tbody>
</table>

<Accordion title="Advanced flags">
  <table>
    <thead><tr><th>Flag</th><th>Description</th></tr></thead>

    <tbody>
      <tr><td><code>{"--checksum-crc32 string"}</code></td><td>Base64 CRC32 checksum of the full object</td></tr>
      <tr><td><code>{"--checksum-crc32-c string"}</code></td><td>Base64 CRC32C checksum of the full object</td></tr>
      <tr><td><code>{"--checksum-crc64-nvme string"}</code></td><td>Base64 CRC64NVME checksum of the full object</td></tr>
      <tr><td><code>{"--checksum-sha1 string"}</code></td><td>Base64 SHA1 checksum of the full object</td></tr>
      <tr><td><code>{"--checksum-sha256 string"}</code></td><td>Base64 SHA256 checksum of the full object</td></tr>
      <tr><td><code>{"--checksum-type string"}</code></td><td>How the object checksum is calculated across parts (<code>COMPOSITE</code> | <code>FULL\_OBJECT</code>)</td></tr>
      <tr><td><code>{"--expected-bucket-owner string"}</code></td><td>Account ID of the expected bucket owner</td></tr>
      <tr><td><code>{"--if-match string"}</code></td><td>Complete only if the existing object's ETag matches this value</td></tr>
      <tr><td><code>{"--if-none-match string"}</code></td><td>Complete only if the object key does not already exist</td></tr>
      <tr><td><code>{"--mpu-object-size int"}</code></td><td>Expected total size of the assembled object in bytes</td></tr>
      <tr><td><code>{"--request-payer string"}</code></td><td>Confirms the requester will be charged (<code>requester</code>)</td></tr>
      <tr><td><code>{"--sse-customer-algorithm string"}</code></td><td>Algorithm to use when encrypting/decrypting with a customer-provided key (SSE-C); must match the upload-part requests</td></tr>
      <tr><td><code>{"--sse-customer-key string"}</code></td><td>Customer-provided encryption key (SSE-C)</td></tr>
      <tr><td><code>{"--sse-customer-key-md5 string"}</code></td><td>128-bit MD5 digest of the SSE-C encryption key</td></tr>
    </tbody>
  </table>
</Accordion>

### Examples

```bash theme={null}
# Build the parts list from the uploaded parts
nscale s3api list-parts --bucket my-bucket --key large.bin --upload-id "$UPLOAD_ID" \
  -q '{Parts: [.Parts[]? | {ETag, PartNumber}]}' > parts.json

nscale s3api complete-multipart-upload --bucket my-bucket --key large.bin --upload-id "$UPLOAD_ID" \
  --multipart-upload file://parts.json
```

***

## abort-multipart-upload

Abort a multipart upload and discard the parts uploaded so far.

```bash theme={null}
nscale s3api abort-multipart-upload --bucket <bucket> --key <key> --upload-id <upload-id> [flags]
```

### Flags

<table>
  <thead><tr><th>Flag</th><th>Description</th></tr></thead>

  <tbody>
    <tr><td><code>{"--bucket string"}</code></td><td><strong>Required.</strong> The bucket the multipart upload targets</td></tr>
    <tr><td><code>{"--key string"}</code></td><td><strong>Required.</strong> The object key of the multipart upload</td></tr>
    <tr><td><code>{"--upload-id string"}</code></td><td><strong>Required.</strong> The ID identifying the multipart upload to abort</td></tr>
    <tr><td><code>{"--expected-bucket-owner string"}</code></td><td>Account ID of the expected bucket owner</td></tr>
    <tr><td><code>{"--if-match-initiated-time string"}</code></td><td>Abort only if the upload was initiated at this time (RFC3339)</td></tr>
    <tr><td><code>{"--request-payer string"}</code></td><td>Confirms the requester will be charged (<code>requester</code>)</td></tr>

    <tr>
      <td>
        <code>
          {"--json"}
        </code>
      </td>

      <td>Emit the full JSON payload (mutually exclusive with <code>-q</code>)</td>
    </tr>

    <tr>
      <td>
        <code>
          {"-q, --query stringArray"}
        </code>
      </td>

      <td>jq filter for value extraction (see <a href="/docs/cli/query-output">Query output with <code>-q</code></a>)</td>
    </tr>
  </tbody>
</table>

### Example

```bash theme={null}
nscale s3api abort-multipart-upload --bucket my-bucket --key large.bin --upload-id "$UPLOAD_ID"
```

***

## Related

<CardGroup cols={2}>
  <Card title="Object Storage (CLI)" icon="box-archive" href="/docs/cli/object-storage">
    Manage object storage endpoints, identity policies, and access keys.
  </Card>

  <Card title="Object Storage (Console)" icon="browser" href="/docs/storage/object-storage">
    Create and manage object storage via the Console UI.
  </Card>
</CardGroup>
