BucketAccessControls Stay organized with collections Save and categorize content based on your preferences.
The BucketAccessControls resource represents the Access Control Lists (ACLs) for buckets within Cloud Storage. ACLs let you specify who has access to your data and to what extent.Important: The methods for this resource fail with a400 Bad Request response for buckets with uniform bucket-level access enabled. Usestorage.buckets.getIamPolicy andstorage.buckets.setIamPolicy to control access instead. There are three roles that can be assigned to an entity:
READERs canget the bucket, though noaclproperty will be returned, andlist the bucket's objects.WRITERs areREADERs, and they caninsert objects into the bucket anddelete the bucket's objects.OWNERs areWRITERs, and they can get theaclproperty of abucket,update a bucket, and call all BucketAccessControls methods on the bucket.
READER,WRITER, andOWNER instead ofREAD,WRITE, andFULL_CONTROL.To try out the methods for this resource, seeMethods.
Resource representations
{ "kind": "storage#bucketAccessControl", "id":string, "selfLink":string, "bucket":string, "entity":string, "role":string, "email":string, "domain":string, "entityId":string, "etag":string, "projectTeam": { "projectNumber":string, "team":string }}| Property name | Value | Description | Notes |
|---|---|---|---|
bucket | string | The name of the bucket. | |
domain | string | The domain associated with the entity, if any. | |
email | string | The email address associated with the entity, if any. | |
entity | string | The entity holding the permission, in one of the following forms:
| writable |
entityId | string | The ID for the entity, if any. | |
etag | string | HTTP 1.1Entity tag for the access-control entry. | |
id | string | The ID of the access-control entry. | |
kind | string | The kind of item this is. For bucket access control entries, this is alwaysstorage#bucketAccessControl. | |
projectTeam | object | The project team associated with the entity, if any. | |
projectTeam.projectNumber | string | The project number. | |
projectTeam.team | string | The team. Acceptable values are:
| |
role | string | The access permission for the entity. Acceptable values are:
| writable |
selfLink | string | The link to this access-control entry. |
Methods
The methods for working with a bucket's access controls are as follows:
- delete
- Permanently deletes the ACL entry for the specified entity on the specifiedbucket.
- get
- Returns the ACL entry for the specified entity on the specified bucket.
- insert
- Creates a new ACL entry on the specifiedbucket.
- list
- Retrieves ACL entries on a specifiedbucket.
- patch
- Updates an ACL entry on the specifiedbucket. This method supportspatch semantics.
- update
- Updates an ACL entry on the specifiedbucket.
Except as otherwise noted, the content of this page is licensed under theCreative Commons Attribution 4.0 License, and code samples are licensed under theApache 2.0 License. For details, see theGoogle Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2025-12-17 UTC.