---
sidebar:
  hidden: true
title: roboto.domain.orgs.s3_integration
---
## Module Contents

### RegisterS3IntegrationRequest

```python
class roboto.domain.orgs.s3_integration.RegisterS3IntegrationRequest(/, **data: Any)
```

`from roboto.domain.orgs.s3_integration import RegisterS3IntegrationRequest`

[Source](https://github.com/roboto-ai/roboto-python-sdk/blob/main/src/roboto/domain/orgs/s3_integration.py#L77-L96)

Bases: `pydantic.BaseModel`

Request payload to integrate an S3 bucket with Roboto.

**Parameters**

- **data** (`Any`)

**Attributes**

- **RegisterS3IntegrationRequest.account_id** (`str`): AWS account ID that owns the S3 bucket.
- **RegisterS3IntegrationRequest.aws_region** (`str`): AWS region where the S3 bucket is located.
- **RegisterS3IntegrationRequest.bucket_name** (`str`): Name of the S3 bucket to integrate.
- **RegisterS3IntegrationRequest.org_id** (`str`): Organization ID to associate with this S3 integration.
- **RegisterS3IntegrationRequest.readonly** (`bool`) = `False`: Whether Roboto should have read-only access to the bucket.
- **RegisterS3IntegrationRequest.transfer_accelerated** (`bool`) = `False`: Whether to enable S3 Transfer Acceleration for faster uploads.

### RegisterS3IntegrationResponse

```python
class roboto.domain.orgs.s3_integration.RegisterS3IntegrationResponse(/, **data: Any)
```

`from roboto.domain.orgs.s3_integration import RegisterS3IntegrationResponse`

[Source](https://github.com/roboto-ai/roboto-python-sdk/blob/main/src/roboto/domain/orgs/s3_integration.py#L99-L112)

Bases: `pydantic.BaseModel`

Response payload containing S3 integration setup instructions.

**Parameters**

- **data** (`Any`)

**Attributes**

- **RegisterS3IntegrationResponse.iam_role_name** (`str`): Name of the IAM role to create for Roboto access.
- **RegisterS3IntegrationResponse.iam_role_policy** (`dict[str, Any]`): IAM policy document to attach to the role.
- **RegisterS3IntegrationResponse.iam_role_trust_relationship** (`dict[str, Any]`): IAM trust policy document for the role.
- **RegisterS3IntegrationResponse.s3_bucket_cors_policy** (`list[dict[str, Any]]`): CORS policy to apply to the S3 bucket.

### S3BucketHealthCheck

```python
class roboto.domain.orgs.s3_integration.S3BucketHealthCheck(/, **data: Any)
```

`from roboto.domain.orgs.s3_integration import S3BucketHealthCheck`

[Source](https://github.com/roboto-ai/roboto-python-sdk/blob/main/src/roboto/domain/orgs/s3_integration.py#L24-L43)

Bases: `pydantic.BaseModel`

Summary of the most recent health check against an S3 bucket integration.

Carries only a machine-readable classification and curated, non-sensitive copy: no identifiers (bucket name, role ARN, account ID), no secrets, and no raw AWS error text. The identifiers a reader needs live on the enclosing [`S3BucketIntegrationRecord`](/reference/python-sdk/roboto/domain/orgs/s3_integration#roboto.domain.orgs.s3_integration.S3BucketIntegrationRecord).

**Parameters**

- **data** (`Any`)

**Attributes**

- **S3BucketHealthCheck.aws_error_code** (`str | None`) = `None`: AWS error code that drove the classification (e.g. `AccessDenied`), if any — a fixed token, never AWS's free-text message.
- **S3BucketHealthCheck.message** (`str`): Curated, human-readable explanation, safe to display.
- **S3BucketHealthCheck.probes** (`dict[str, str]`) = `None`: Outcome per probe name (assume_role, list, put, …), each one of `ok` / `denied` / `error` / `skipped`.
- **S3BucketHealthCheck.reason_code** (`str`): Machine-readable result classification — a fixed token, e.g. `ok` or `permission_denied`.

### S3BucketIntegrationRecord

```python
class roboto.domain.orgs.s3_integration.S3BucketIntegrationRecord(/, **data: Any)
```

`from roboto.domain.orgs.s3_integration import S3BucketIntegrationRecord`

[Source](https://github.com/roboto-ai/roboto-python-sdk/blob/main/src/roboto/domain/orgs/s3_integration.py#L46-L74)

Bases: `pydantic.BaseModel`

Record representing an S3 bucket integration with a Roboto organization.

**Parameters**

- **data** (`Any`)

**Attributes**

- **S3BucketIntegrationRecord.aws_region** (`str`): AWS region where the S3 bucket is located.
- **S3BucketIntegrationRecord.bucket_name** (`str`): Name of the integrated S3 bucket.
- **S3BucketIntegrationRecord.created** (`datetime.datetime`): Timestamp when the integration was created.
- **S3BucketIntegrationRecord.last_health_check** (`S3BucketHealthCheck | None`) = `None`: Summary of the most recent health check, or `None` if the integration has never been checked.
- **S3BucketIntegrationRecord.modified** (`datetime.datetime`): Timestamp when the integration was last modified.
- **S3BucketIntegrationRecord.org_id** (`str`): Organization ID this bucket is associated with.
- **S3BucketIntegrationRecord.readonly** (`bool`): Whether Roboto has read-only access to the bucket.
- **S3BucketIntegrationRecord.status** (`str`): Integration status: one of 'unverified', 'healthy', 'unhealthy', 'unknown'.
- **S3BucketIntegrationRecord.status_last_updated** (`datetime.datetime | None`) = `None`: Timestamp when `status` was last written, i.e. when the most recent health check ran.

### S3IntegrationService

```python
class roboto.domain.orgs.s3_integration.S3IntegrationService(
    roboto_client: roboto.http.RobotoClient,
    sts_client: Optional[Any] = None,
    s3_client: Optional[Any] = None,
    iam_client: Optional[Any] = None,
)
```

`from roboto.domain.orgs.s3_integration import S3IntegrationService`

[Source](https://github.com/roboto-ai/roboto-python-sdk/blob/main/src/roboto/domain/orgs/s3_integration.py#L115-L237)

Service for integrating S3 buckets with Roboto organizations.

This service handles the setup of cross-account IAM roles and S3 bucket policies to allow Roboto to access customer S3 buckets for data storage and processing.

**Parameters**

- **roboto_client** (`roboto.http.RobotoClient`)
- **sts_client** (`Optional[Any]`)
- **s3_client** (`Optional[Any]`)
- **iam_client** (`Optional[Any]`)

#### S3IntegrationService.register_bucket()

```python
def register_bucket(
    org_id: str,
    account_id: str,
    bucket_name: str,
    transfer_accelerated: bool = False,
    readonly: bool = False,
)
```

[Source](https://github.com/roboto-ai/roboto-python-sdk/blob/main/src/roboto/domain/orgs/s3_integration.py#L148-L237)

Register an S3 bucket for use with a Roboto organization.

This method sets up the necessary IAM roles and S3 bucket policies to allow Roboto to access the specified S3 bucket. The caller must have appropriate AWS credentials with permissions to create IAM roles and modify S3 bucket policies.

**Parameters**

- **org_id** (`str`): Organization ID to associate with this S3 integration.
- **account_id** (`str`): AWS account ID that owns the S3 bucket.
- **bucket_name** (`str`): Name of the S3 bucket to integrate.
- **transfer_accelerated** (`bool`): Whether to enable S3 Transfer Acceleration.
- **readonly** (`bool`): Whether Roboto should have read-only access to the bucket.

**Raises**

- [`RobotoInvalidRequestException`](/reference/python-sdk/roboto/exceptions/domain#roboto.exceptions.domain.RobotoInvalidRequestException): AWS credentials are invalid or account ID mismatch.
- `ValueError`: The specified bucket does not exist or is not owned by the account.
- `botocore.exceptions.ClientError`: AWS API errors during setup.

**Usage**

Register a bucket for read-write access:

```python
from roboto.domain.orgs import S3IntegrationService
from roboto import RobotoClient
service = S3IntegrationService(RobotoClient())
service.register_bucket(org_id="org_12345", account_id="123456789012", bucket_name="my-data-bucket")
```

Register a bucket with read-only access:

```python
service.register_bucket(
    org_id="org_12345", account_id="123456789012", bucket_name="my-readonly-bucket", readonly=True
)
```

### logger

```python
roboto.domain.orgs.s3_integration.logger
```

`from roboto.domain.orgs.s3_integration import logger`

[Source](https://github.com/roboto-ai/roboto-python-sdk/blob/main/src/roboto/domain/orgs/s3_integration.py#L21-L21)
