# Connect to an S3 bucket

Connect an Amazon S3 bucket or S3-compatible storage to access its data directly from your notebook in Python, Scala, Kotlin, or R without intermediate exports.

Procedure: Step 1. Create and configure an S3 connection

1. Open the New cloud storage connection dialog.

In a workspace:

1.  On the Home page, select the workspace where you want to add an S3 connection.

2.  In the resource list, select ![Document](https://resources.jetbrains.com.cn/help/img/datalore/2026.3/document.svg)Data and switch to the Cloud storage tab.

3.

Click ![Plus](https://resources.jetbrains.com.cn/help/img/datalore/2026.3/plus.svg) New cloud storage connection at the top right.

![Cloud storage tab](https://resources.jetbrains.com.cn/help/img/datalore/2026.3/cloud-storage.png)

In a notebook:

1.

In the sidebar, select ![Attach](https://resources.jetbrains.com.cn/help/img/datalore/2026.3/attach.svg) Attached data and switch to the Cloud storage tab.

![Cloud storage connections in a notebook](https://resources.jetbrains.com.cn/help/img/datalore/2026.3/cs_nb.png)

2.  At the bottom of the tab, click New cloud storage.

2. In the New cloud storage connection dialog, select Amazon S3.

3. Fill in the following fields:

* Display name: Enter the name for this data source.

* Use default credentials: Select this option to authenticate with the credentials provided by the workspace service account instead of entering access keys. [Learn more](#default-credentials)

* [AWS access key and AWS secret access key](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_access-keys.html): Enter your AWS credentials. > **Tip:** > These fields are hidden when Use default credentials is enabled.

* Region: Specify your [AWS region](https://docs.aws.amazon.com/powershell/latest/userguide/pstools-installing-specifying-region.html).

* Amazon Bucket name: Enter the name of the bucket you want to mount.

* Custom options: Add optional parameters. See the [examples below](#ssec). > **Tip:** > Use the `endpoint_url` parameter to connect to other bucket providers from [this list](https://github.com/s3fs-fuse/s3fs-fuse/wiki/Non-Amazon-S3/). > **Note:** > When using an IAM role associated with Datalore for authentication, `httpPutResponseHopLimit>1` is required.

* Custom endpoint URL: Specify the [endpoint URL](https://docs.aws.amazon.com/AmazonS3/latest/userguide/WebsiteEndpoints.html) for the bucket you want to mount.

![New S3 cloud storage connection dialog](https://resources.jetbrains.com.cn/help/img/datalore/2026.3/s3.png)

4. (Optional) Click Test connection to verify the provided parameters.

> **Note:**
> The Test connection button is disabled when Use default credentials is enabled. In this mode the credentials are validated on first use, when the connection is mounted to a notebook.

5. Click Create and close.

Procedure: Step 2. Configure optional S3 connection parameters

Use Custom options to configure optional S3 connection parameters. The following are examples.

* To enable SSE-C, add the following to Custom options:

```
use_sse=c:/path/to/keys/file
```

In this example, `/path/to/keys/file` is the path to the file that contains the keys. Make sure its permissions are `600`.

* To provide access based on a role associated with that of an EC2 instance profile, add `public_bucket=0,iam_role` to Custom options.

Procedure: Step 3. Attach the connection to a notebook

In a workspace:

1. Open the notebook you want to attach the connection to.

2.  In the sidebar, select Attached data and switch to the Cloud storage tab.

3.

Enable the toggle for your S3 connection.

In a notebook:

1.  In the sidebar, select Attached data and switch to the Cloud storage tab.

2.

Enable the toggle for your S3 connection.

Procedure: Step 4. Use the connection in a notebook

After the connection is mounted, access files in the S3 bucket from your notebook code:

```PYTHON
import pandas as pd

df = pd.read_csv("/data/s3/my_file.csv")
df
```

```KOTLIN
%use dataframe

val df = DataFrame.readCsv("/data/s3/my_file.csv")
df
```

```SCALA
val lines = scala.io.Source.fromFile("/data/s3/my_file.txt").mkString
```

```R
df <- read.csv("/data/s3/my_file.csv")

print(df)
```

> **Tip:**
> The connection’s mount path, such as `/data/s3/`, is shown on the connection card. To copy the path, click ![Three docs icon](https://resources.jetbrains.com.cn/help/img/datalore/2026.3/dots.svg) (More) and select Copy directory path.

## Use default credentials

Instead of providing an access key and secret access key, you can enable Use default credentials to authenticate the connection with the credentials provided by the workspace service account.

Use this option when Datalore runs with an ambient IAM identity provided by the underlying platform. The bucket is then accessed without storing long-lived access keys. The identity is resolved from the workspace service account, which is bound to a cloud IAM role.

The exact mechanism depends on where Datalore runs:

* On AWS, use [IAM roles for service accounts (IRSA)](https://docs.aws.amazon.com/eks/latest/userguide/iam-roles-for-service-accounts.html) or [EKS Pod Identity](https://docs.aws.amazon.com/eks/latest/userguide/pod-identities.html) to associate an IAM role with the Kubernetes service account.

* On Google Cloud, use [Workload Identity Federation for GKE](https://cloud.google.com/kubernetes-engine/docs/concepts/workload-identity) to let the Kubernetes service account impersonate a Google Cloud service account.

Procedure: Configure a workspace service account

> **Note:**
> You need the Admin or Super Admin role.

1. Click your avatar at the top right and select Admin panel.

2. In the sidebar, select Manage workspaces.

3. Next to the workspace where you want to add the service account, click ![three dots icon](https://resources.jetbrains.com.cn/help/img/datalore/2026.3/dots.svg) (More) and select Edit identity bindings.

4. In the dialog, enter the service account name in K8s agent service account and click Save.

> **Note:**
> When Use default credentials is enabled, the access key fields and the Test connection button are unavailable.
>
>
>
> The credentials are validated on first use, when you mount the connection to a notebook.

## Next steps

* Learn how to manage or delete cloud storage connections [in a workspace](manage-cloud-storage-connections-in-a-workspace.html) and [in a notebook](manage-cloud-storage-connections-attached-to-a-notebook.html).

