# Glossary

The vocabulary of the [Object Storage](/en/documentation/platform/object-storage/) documentation, one row per term, each linked to the page that owns it.

| Term                   | Definition                                                                                                                                                                                                                                                                                                                                                                                 |
| ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| access key             | The public half of an [S3 credential](/en/documentation/platform/object-storage/s3-compatibility/), sent with every request signed for the S3 protocol. It identifies the credential and is readable again after creation, unlike the secret key.                                                                                                                                          |
| `azion:storage`        | The [Azion Runtime](/en/documentation/devtools/runtime/api-reference/storage/) module a function imports to read and write objects without leaving the request. It exposes `put`, `get`, `delete`, and `list` on a bucket the function names.                                                                                                                                              |
| bucket                 | The container Object Storage keeps objects in. Buckets do not nest, a name is unique across every Azion account, and the name cannot be changed after creation. [Buckets and objects](/en/documentation/platform/object-storage/buckets-and-objects/) documents every field and the rules a name follows.                                                                                  |
| capability             | One permission on an [S3 credential](/en/documentation/platform/object-storage/s3-compatibility/), naming a group of S3 operations it may run. The six are `listFiles`, `readFiles`, `writeFiles`, `deleteFiles`, `listAllBucketNames`, and `listBuckets`, and a capability outside that set is rejected.                                                                                  |
| Connector              | The platform resource that points an application at a bucket, so requests to a domain are answered from the objects in it. A connector of type Object Storage names the bucket and, optionally, a prefix inside it. For more information, refer to [Connectors](/en/documentation/platform/connectors/).                                                                                   |
| grace period           | The 24 hours a deleted object is retained before it is removed permanently. The object stops being listed and stops being served at once, and the bucket cannot be deleted until the period ends. [Buckets and objects](/en/documentation/platform/object-storage/buckets-and-objects/) documents the delete operations it applies to.                                                     |
| object                 | A file stored in a bucket, together with the key it is stored under and the content type it is served with. An object is replaced whole: uploading to a key that is in use overwrites the content, and the earlier version cannot be recovered.                                                                                                                                            |
| object key             | The string that identifies one object inside a bucket, between 1 and 1,024 characters. A key may contain the forward slash, which the interfaces read as a [prefix](/en/documentation/platform/object-storage/buckets-and-objects/), and a key cannot be renamed.                                                                                                                          |
| Object Storage         | The Azion product that stores unstructured data as objects in buckets, reachable through Azion Console, the Azion API, the Azion CLI, Azion Runtime, the `azion` library, and the S3 protocol. It is a Store product, alongside [KV Store](/en/documentation/platform/kv-store/) and [SQL Database](/en/documentation/platform/sql-database/).                                             |
| operation class        | The billing group a request falls into. Class A covers control and listing operations, Class B covers object reads, and Class C covers writes and upload management and is included on every plan. [Object Storage limits](/en/documentation/platform/object-storage/limits/) lists the operations in each class and the amount each plan includes.                                        |
| prefix                 | A leading segment shared by a group of object keys, which the interfaces present as a grouping. A prefix is not a folder and is not created in advance: uploading to `src/assets/logo.svg` creates the object and its prefixes in one request. A [Connector](/en/documentation/platform/connectors/) can serve one prefix as the root of an application path.                              |
| S3 credential          | The access key and secret key pair that authenticates a request to the S3 protocol endpoint, scoped by its capabilities and, optionally, by a list of buckets. A credential works independently of the personal token that created it, so it keeps working after that token expires. [S3 compatibility](/en/documentation/platform/object-storage/s3-compatibility/) documents the fields. |
| secret key             | The private half of an [S3 credential](/en/documentation/platform/object-storage/s3-compatibility/), used to sign a request for the S3 protocol. It is returned only by the request that creates the credential and cannot be read or changed afterwards. A lost secret key is replaced by creating another credential.                                                                    |
| `Storage-Content-Type` | A header the Azion API accepts on an upload and does not act on. The content type stored with an object comes from `Content-Type`, and Azion detects the type when the request sends no `Content-Type`. [Buckets and objects](/en/documentation/platform/object-storage/buckets-and-objects/) documents the behavior.                                                                      |
| workloads access       | The bucket field that decides what the Azion platform may do with the objects in it, set to `read_only`, `read_write`, or `restricted`. It does not restrict the Azion API or the S3 protocol, which are governed by the token or the credential the request carries. [Buckets and objects](/en/documentation/platform/object-storage/buckets-and-objects/) documents each value.          |
