Creating Storage Connections | Vendia

Creating Storage Connections

Storage Connections enable AI applications to access your Amazon S3 buckets through Vendia MCP Gateway. This guide covers the complete setup process, including AWS IAM configuration and creating storage connections in the Vendia platform.

Prerequisites

Before creating Storage Connections, ensure you have:

  1. AWS IAM Role: A role with appropriate permissions for the S3 buckets you want to access

  2. S3 Bucket Access: Access to the S3 bucket(s) you want to use through AI applications. If you do not have an S3 bucket or AWS account, see How to Create an AWS S3 Bucket for step-by-step instructions.

  3. Vendia Account Permissions: Permissions to configure Storage Connections in your Vendia account

Step 1: Start Storage Connection Configuration in Vendia

Start the configuration process in Vendia to obtain the required AWS account numbers:

  1. In your Vendia dashboard, click Go to my MCP Project.

  2. Go to Storage Connections.

  3. Click the + Connection button.

  4. Note the Vendia AWS account numbers displayed in the UI — you will need these to configure the IAM trust relationship.

Step 2: Configure IAM Trust Relationship

Using the account numbers from Step 1, configure the AWS IAM role that Vendia will assume to access your S3 bucket(s).

Grant Vendia access to your S3 bucket by adding a trust relationship to your IAM role:

  1. Go to the AWS IAM dashboard (click All Services > IAM).

  2. In the left navigation, click Roles. On the Roles page, either select an existing role or create a new role, then follow these steps:

  3. Click Create role.

  4. Under Select trusted entity, select Custom trust policy.

  5. Under Custom trust policy, add or merge the trust relationship by copy-pasting the policy shown below.

{
     "Version": "2012-10-17",
     "Statement": [
       {
         "Effect": "Allow",
         "Principal": {
           "AWS": [
             "arn:aws:iam::VENDIA_ACCOUNT_ID1:root",
             "arn:aws:iam::VENDIA_ACCOUNT_ID2:root"
           ]
         },
         "Action": "sts:AssumeRole"
       }
     ]
}
  1. Click Next.

  2. On the Add permissions step, click Next.

  3. On the Name, review and create step, enter the role name (e.g., vendia-mcp-access) and add a description.

  4. Review your trusted entities and click Create role.

Step 3: Configure IAM Permissions

Choose the appropriate permission set based on your intended use case:

  1. Click the Permissions tab for the selected IAM role.

  2. Click Add permissions and then click Create inline policy.

  3. On the Specify permissions page, you can either select Visual or JSON in the policy editor.

For most users, we recommend using the JSON editor for precise control and security. See below for JSON policy examples and instructions.

Option A: Read-Only Access (Full Bucket)

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": ["s3:GetObject", "s3:ListBucket"],
      "Resource": ["arn:aws:s3:::my-s3-bucket", "arn:aws:s3:::my-s3-bucket/*"]
    }
  ]
}

Option B: Read and Write Access (Full Bucket)

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": ["s3:GetObject", "s3:ListBucket", "s3:PutObject"],
      "Resource": ["arn:aws:s3:::my-s3-bucket", "arn:aws:s3:::my-s3-bucket/*"]
    }
  ]
}

Option C: Complete Access (Read, Write, and Delete - Full Bucket)

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": ["s3:GetObject", "s3:ListBucket", "s3:PutObject", "s3:DeleteObject"],
      "Resource": ["arn:aws:s3:::my-s3-bucket", "arn:aws:s3:::my-s3-bucket/*"]
    }
  ]
}

Option D: Segregated Directories (Recommended for Enhanced Security)

Replace my-s3-bucket, my-read-folder, my-write-folder, and my-temp-folder with your actual bucket and folder names.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": ["s3:ListBucket"],
      "Resource": "arn:aws:s3:::my-s3-bucket"
    },
    {
      "Sid": "AllowReadFromSpecificFolder",
      "Effect": "Allow",
      "Action": ["s3:GetObject"],
      "Resource": "arn:aws:s3:::my-s3-bucket/my-read-folder/*"
    },
    {
      "Sid": "AllowWriteToSpecificFolder",
      "Effect": "Allow",
      "Action": ["s3:PutObject"],
      "Resource": "arn:aws:s3:::my-s3-bucket/my-write-folder/*"
    },
    {
      "Sid": "AllowDeleteInSpecificFolder",
      "Effect": "Allow",
      "Action": ["s3:DeleteObject"],
      "Resource": "arn:aws:s3:::my-s3-bucket/my-temp-folder/*"
    }
  ]
}

Copy-paste your chosen policy into the editor and click Next.

  1. On the Review and create step, enter the policy name (e.g., vendia-mcp-s3-policy) and review the permissions.

  2. Click Create policy to finish.

Step 4: Complete Storage Connection Configuration in Vendia

Return to Storage Connections in the Vendia dashboard to complete the configuration:

  1. Provide the following information in the Storage Connection configuration dialog (from Step 1):
    • Name: A friendly name to identify this storage connection configuration
    • Role ARN: The ARN of the AWS role that Vendia will assume (configured in Step 2 and Step 3;

you can copy-paste it from the role information page in the IAM dashboard)

  1. Configure Access Policies:

You’ll be asked: “Give AI agents full access to all files and folders in this S3 bucket?”

  1. Advanced Settings (Optional):

Expand the “Advanced settings” section if you need to configure client-side encryption:

  1. Click Create Storage Connection to complete the setup:

You will see your newly created Storage Connection in the list:

  1. If you selected No in step 2 above, configure access policies now:
    • Navigate to the Access Policy tab of your newly created Storage Connection
    • Click + Add Path to define which files and folders AI agents can access
    • See Access Policies for detailed instructions on how to specify which files and folders are accessible, set granular permissions, and manage AI agent access to your S3 bucket.

Using Your Storage Connection

After configuration, you can:

Need Help?

If you encounter issues during setup or have questions about creating Storage Connections:

Free Tier Support

Enterprise Tier Support