{"id":"storage.object.set_acl","module":"storage","namespace":"storage","action":"object.set_acl","method":"POST","path":"/v1/storage/object/set_acl/{bucket}/{key}","idempotent":true,"available":true,"vendors":[],"vendors_ready":[],"vendors_pending":[],"key_status":"live","default_vendor":null,"self_hosted":true,"minimum_tier":"standard","supported_message_classes":null,"regions":["western","china"],"dynamic_params":{},"models_tracked":false,"sdk_hint":"Regular parameters + types are stable — read them from the typed SDK signature / API reference for this capability. discovery only carries the runtime-dynamic values above (available, vendors, dynamic_params).","params":{"title":"ObjectSetAclRequest","description":"Set a single object access policy for storage.object.set_acl. Current supported values are private and signed-only; public/public-read are rejected. Returns ObjectSetAclResult. bucket and key are path params.","type":"object","required":["acl"],"additionalProperties":false,"properties":{"acl":{"description":"Access policy. Supported values: private, signed-only. public/public-read are not supported; public_url remains null.","type":"string","enum":["private","signed-only"]},"idempotency_key":{"type":["string","null"],"description":"Client-provided idempotency key; prevents duplicate execution on retry"}}},"response":{"title":"ObjectSetAclResult","description":"Result of storage.object.set_acl. acl ∈ private/signed-only (public-read removed 2026-06-06, secure-by-default). public_url is ALWAYS null — Infrai never mints a permanent public direct link; share via short-TTL presign.","type":"object","required":["acl"],"additionalProperties":false,"properties":{"acl":{"description":"Access control list for the bucket or object","type":"string","enum":["private","signed-only"]},"public_url":{"type":["string","null"],"description":"Always null (public-read removed; no permanent public direct link)."}}},"errors":["ACCOUNT_AUTORECHARGE_LIMIT","ACCOUNT_FROZEN","AUTH_RATE_LIMIT","AUTH_REFRESH_TOO_FREQUENT","IDEMPOTENCY_KEY_CONFLICT","INSUFFICIENT_CREDIT","INTERNAL_ERROR","INVALID_ARGUMENT","KEY_REVOKED","MAINTENANCE","NETWORK_ERROR","RATE_LIMIT_ACCOUNT","RATE_LIMIT_USER","RATE_LIMIT_VENDOR","SCOPE_INSUFFICIENT","STORAGE_ACL_INVALID","STORAGE_BANDWIDTH_EXCEEDED","STORAGE_BUCKET_EXISTS","STORAGE_BUCKET_NAME_TAKEN","STORAGE_BUCKET_NOT_FOUND","STORAGE_CONTENT_BLOCKED","STORAGE_CONTENT_TYPE_BLOCKED","STORAGE_DELETE_NOT_FORCED","STORAGE_INVALID_BUCKET_NAME","STORAGE_INVALID_CORS_RULES","STORAGE_INVALID_DATA","STORAGE_INVALID_LIFECYCLE_RULES","STORAGE_INVALID_MODE","STORAGE_INVALID_OBJECT_KEY","STORAGE_INVALID_REGION","STORAGE_INVALID_TTL","STORAGE_INVALID_VENDOR","STORAGE_MULTIPART_INCONSISTENT","STORAGE_OBJECT_NOT_FOUND","STORAGE_OBJECT_TOO_LARGE","STORAGE_PRESIGN_EXPIRED","UNAUTHORIZED","VENDOR_AUTH_ERROR","VENDOR_DOWN","VENDOR_TIMEOUT","WALLET_EXPIRED"],"examples":{"curl":"curl -X POST https://api.infrai.cc/v1/storage/object/set_acl/BUCKET/KEY \\\n  -H \"Authorization: Bearer $INFRAI_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"acl\": \"private\"}'","python":"# Zero-install REST call — no SDK required (short-term the API is REST-only).\nimport os, requests\n\nresp = requests.post(\n    \"https://api.infrai.cc/v1/storage/object/set_acl/BUCKET/KEY\",\n    headers={\n        \"Authorization\": f\"Bearer {os.environ['INFRAI_API_KEY']}\",\n    },\n    json={'acl': 'private'},\n)\nresp.raise_for_status()\nprint(resp.json())","javascript":"// Zero-install REST call — no SDK required (short-term the API is REST-only).\nconst resp = await fetch(\n  \"https://api.infrai.cc/v1/storage/object/set_acl/BUCKET/KEY\",\n  {\n    method: \"POST\",\n    headers: {\n      \"Authorization\": `Bearer ${process.env.INFRAI_API_KEY}`,\n      \"Content-Type\": \"application/json\",\n    },\n    body: JSON.stringify({\"acl\": \"private\"}),\n  },\n);\nconsole.log(await resp.json());","typescript":"// Zero-install REST call — no SDK required (short-term the API is REST-only).\nconst resp = await fetch(\n  \"https://api.infrai.cc/v1/storage/object/set_acl/BUCKET/KEY\",\n  {\n    method: \"POST\",\n    headers: {\n      \"Authorization\": `Bearer ${process.env.INFRAI_API_KEY}`,\n      \"Content-Type\": \"application/json\",\n    },\n    body: JSON.stringify({\"acl\": \"private\"}),\n  },\n);\nif (!resp.ok) throw new Error(`infrai ${resp.status}`);\nconst data: unknown = await resp.json();\nconsole.log(data);","go":"// Zero-install REST call — no SDK required (short-term the API is REST-only).\npackage main\n\nimport (\n\t\"bytes\"\n\t\"fmt\"\n\t\"net/http\"\n\t\"os\"\n)\n\nfunc main() {\n\tbody := []byte(`{\"acl\": \"private\"}`)\n\treq, _ := http.NewRequest(\"POST\", \"https://api.infrai.cc/v1/storage/object/set_acl/BUCKET/KEY\", bytes.NewReader(body))\n\treq.Header.Set(\"Authorization\", \"Bearer \"+os.Getenv(\"INFRAI_API_KEY\"))\n\treq.Header.Set(\"Content-Type\", \"application/json\")\n\tresp, err := http.DefaultClient.Do(req)\n\tif err != nil {\n\t\tpanic(err)\n\t}\n\tdefer resp.Body.Close()\n\tfmt.Println(resp.Status)\n}","java":"// Zero-install REST call — no SDK required (short-term the API is REST-only).\nimport java.net.URI;\nimport java.net.http.*;\n\nHttpRequest req = HttpRequest.newBuilder()\n    .uri(URI.create(\"https://api.infrai.cc/v1/storage/object/set_acl/BUCKET/KEY\"))\n    .header(\"Authorization\", \"Bearer \" + System.getenv(\"INFRAI_API_KEY\"))\n    .header(\"Content-Type\", \"application/json\")\n    .method(\"POST\", HttpRequest.BodyPublishers.ofString(\"{\\\"acl\\\": \\\"private\\\"}\"))\n    .build();\nHttpResponse<String> resp = HttpClient.newHttpClient()\n    .send(req, HttpResponse.BodyHandlers.ofString());\nSystem.out.println(resp.body());","csharp":"// Zero-install REST call — no SDK required (short-term the API is REST-only).\nusing System;\nusing System.Net.Http;\n\nvar client = new HttpClient();\nvar req = new HttpRequestMessage(new HttpMethod(\"POST\"), \"https://api.infrai.cc/v1/storage/object/set_acl/BUCKET/KEY\");\nvar key = Environment.GetEnvironmentVariable(\"INFRAI_API_KEY\");\nreq.Headers.Add(\"Authorization\", \"Bearer \" + key);\nreq.Content = new StringContent(\"{\\\"acl\\\": \\\"private\\\"}\", System.Text.Encoding.UTF8, \"application/json\");\nvar resp = await client.SendAsync(req);\nConsole.WriteLine(await resp.Content.ReadAsStringAsync());","php":"<?php\n// Zero-install REST call — no SDK required (short-term the API is REST-only).\n$ch = curl_init(\"https://api.infrai.cc/v1/storage/object/set_acl/BUCKET/KEY\");\ncurl_setopt($ch, CURLOPT_CUSTOMREQUEST, \"POST\");\ncurl_setopt($ch, CURLOPT_RETURNTRANSFER, true);\ncurl_setopt($ch, CURLOPT_HTTPHEADER, [\n    \"Authorization: Bearer \" . getenv(\"INFRAI_API_KEY\"),\n    \"Content-Type: application/json\",\n]);\ncurl_setopt($ch, CURLOPT_POSTFIELDS, \"{\\\"acl\\\": \\\"private\\\"}\");\n$response = curl_exec($ch);\ncurl_close($ch);\necho $response;","ruby":"# Zero-install REST call — no SDK required (short-term the API is REST-only).\nrequire \"net/http\"\nrequire \"uri\"\n\nuri = URI(\"https://api.infrai.cc/v1/storage/object/set_acl/BUCKET/KEY\")\nhttp = Net::HTTP.new(uri.host, uri.port)\nhttp.use_ssl = true\nreq = Net::HTTP::Post.new(uri)\nreq[\"Authorization\"] = \"Bearer #{ENV['INFRAI_API_KEY']}\"\nreq[\"Content-Type\"] = \"application/json\"\nreq.body = '{\"acl\": \"private\"}'\nres = http.request(req)\nputs res.body","rust":"// Zero-install REST call — no SDK required (short-term the API is REST-only). (uses the reqwest + tokio crates)\nuse std::env;\n\n#[tokio::main]\nasync fn main() -> Result<(), Box<dyn std::error::Error>> {\n    let resp = reqwest::Client::new()\n        .post(\"https://api.infrai.cc/v1/storage/object/set_acl/BUCKET/KEY\")\n        .header(\"Authorization\", format!(\"Bearer {}\", env::var(\"INFRAI_API_KEY\")?))\n        .header(\"Content-Type\", \"application/json\")\n        .body(r#\"{\"acl\": \"private\"}\"#)\n        .send()\n        .await?;\n    println!(\"{}\", resp.text().await?);\n    Ok(())\n}","request":{"acl":"private"}},"billing":{"is_billable":false,"free":true,"billing_class":"floored","unit":"per_call","note":"free (rate-limited); does NOT consume the new-account trial"}}