# Get Object stores

> Source: https://truto.one/docs/api-reference/unified-cloud-infrastructure-api/objectstores/get/

`GET /unified/cloud-infrastructure/object_stores/{id}`

Resource: **ObjectStores** · API: **Unified Cloud Infrastructure API**

## Supported integrations

Amazon Web Services

## Path parameters

- **`id`** _(string, required)_
  The ID of the resource.

## Query parameters

- **`integrated_account_id`** _(string, required)_
  The ID of the integrated account to use for the request.
- **`truto_response_format`** _(string)_
  The format of the response. - `unified` returns the response with unified mappings applied. - `raw` returns the unprocessed, raw response from the remote API. - `normalized` applies the unified mappings and returns the data in a normalized format. - `stream` returns the response as a stream, which is ideal for transmitting large datasets, files, or binary data. Using streaming mode helps to efficiently handle large payloads or real-time data flows without requiring the entire data to be buffered in memory. - `debug` returns the final unified result alongside raw remote fetch information. The response is an envelope containing `result` (identical to unified mode output) and `debug` (with `requestUrl`, `requestOptions`, `data`, `responseHeaders`, and for list operations: `nextCursor`, `isLooping`, `isEmptyResult`, `resultCount`). When the upstream body exceeds 1 MiB, `data` is replaced by `{ truto_truncated: true, truto_max_bytes, truto_excerpt }`. `debug` is `null` for static responses or when `truto_skip_api_call=true`. Defaults to `unified`.
  Allowed: `unified`, `raw`, `normalized`, `stream`, `debug`
- **`truto_ignore_remote_data`** _(boolean)_
  Excludes the `remote_data` attribute from the response.
- **`truto_exclude_fields`** _(array<string>)_
  Array of fields to exclude from the response.
- **`remote_query`** _(object)_
  Query parameters to pass to the underlying API without any transformations. Refer [this guide](https://truto.one/docs/api-reference/overview/querying#remote-query-parameters) to see how to structure the query parameters.

## Response body

- **`id`** _(string, required)_
  Truto's stable unified identifier for this object. Opaque; use provider_id to address the object in the provider's own console or API.
- **`provider_id`** _(string)_
  The provider's own identifier. S3 returns an ARN only for directory buckets; for general-purpose buckets this is the canonical `arn:<partition>:s3:::<name>`, which is how AWS itself addresses the bucket.
- **`provider`** _(string)_
  Which cloud this object was read from.
  Allowed: `aws`, `azure`, `gcp`
- **`account`** _(string)_
  The account, subscription or project this object belongs to.
- **`region`** _(string)_
  Where the object is located. 'global' denotes genuinely global resources (e.g. IAM, GCP VPC networks) rather than a guessed region. A substituted region (when none is derivable) is flagged in unreadable_fields.
- **`native_type`** _(string)_
  The provider's own type string, unmodified — for example 'AWS::S3::Bucket', 'aws_iam_role', 'Microsoft.Sql/servers'. Used for display and drill-down.
- **`tags`** _(object)_
  Key-value pairs exactly as the customer set them: no case folding, key/value normalization, or merging of separate provider concepts. An empty object means no tags; tags that could not be read appear in unreadable_fields instead.
- **`collected_at`** _(string)_
  When Truto actually read this object from the provider, in UTC ISO 8601 with the offset present — not the request time, and not a provider timestamp.
- **`updated_at`** _(string)_
  When the object was last modified at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.
- **`created_at`** _(string)_
  When the object was created at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.
- **`unreadable_fields`** _(array<object>)_
  Fields on this object that could not be read, and why. An empty array means everything was read. Use this to tell a real value from a missing one.
  - **`field`** _(string)_
    The property on this resource that could not be read.
  - **`reason`** _(string)_
    Why the field could not be read. available_on_get: Not read on list to keep the list fast; call GET for this resource's id to get it.
    Allowed: `not_supported_by_provider`, `not_configured`, `permission_denied`, `not_collected`, `collection_error`, `partially_collected`, `available_on_get`
  - **`detail`** _(string)_
    Explanation of the reason, where one adds anything.
- **`remote_data`** _(object)_
  Raw data returned from the remote API call.
- **`store_id`** _(string)_
  The provider's own identifier for the store.
- **`name`** _(string)_
  The bucket or container name.
- **`location`** _(string)_
  Where the store's data physically sits.
- **`public_access_blocked`** _(boolean)_
  Whether public access is comprehensively blocked. True only when all four effective block-public-access flags are set (the more restrictive of account- and bucket-level config); a missing configuration counts as all-false.
- **`anonymous_access_allowed`** _(boolean)_
  Whether the store is effectively reachable without credentials. Computed from the provider's effective access rules, not a single flag.
- **`policy_grants_anyone`** _(boolean)_
  Whether the bucket policy grants access to anyone (distinct from account-level toggles, which can disagree). On AWS, cross-account access often can't read the policy body itself, so this may be marked permission_denied.
- **`acl_grants_anyone`** _(boolean)_
  Whether an ACL grants access to a public group, tracked separately from policy_grants_anyone since the two can differ.
- **`acl_grants_authenticated_users`** _(boolean)_
  Whether an ACL grants access to any authenticated account on the provider (not anonymous — requests must be signed, but any account on the provider qualifies).
- **`effective_public_access_block`** _(object)_
  The per-flag effective block configuration, combining account-level and store-level settings.
  - **`block_public_acls`** _(boolean)_
    AWS BlockPublicAcls. Rejects new public ACLs on the store and its objects.
  - **`ignore_public_acls`** _(boolean)_
    AWS IgnorePublicAcls. Ignores any public ACL already present.
  - **`block_public_policy`** _(boolean)_
    AWS BlockPublicPolicy. Rejects a store policy that would grant public access.
  - **`restrict_public_buckets`** _(boolean)_
    AWS RestrictPublicBuckets. Limits access under a public policy to principals in this account and AWS services.
- **`encryption_key_type`** _(string)_
  Who manages the encryption key. On AWS every bucket now gets default provider-side encryption, so 'none' is effectively obsolete; what matters is whether the key is customer_managed.
  Allowed: `provider_managed`, `provider_owned`, `customer_managed`, `customer_supplied`, `none`, `unknown`
- **`encryption_key`** _(object)_
  The key protecting the store, where a customer-managed one is configured.
  - **`id`** _(string)_
    The target's `id`.
- **`encryption_algorithm`** _(string)_
  The provider's own algorithm string, verbatim.
- **`versioning_enabled`** _(boolean)_
  Whether object versioning is on. On AWS, a bucket that never had versioning enabled returns no status field, read as false rather than unknown.
- **`object_lock_enabled`** _(boolean)_
  Whether write-once retention is enabled on the store.
- **`retention_policy_days`** _(integer)_
  Default retention period applied to objects, in days.
- **`retention_locked`** _(boolean)_
  Whether the retention period cannot be shortened or removed. On AWS this maps to a COMPLIANCE-mode default rule, which only governs future objects, not what's already stored.
- **`lifecycle_rules`** _(array<object>)_
  Lifecycle rules configured on the store.
  - **`id`** _(string)_
    The provider's own rule id.
  - **`status`** _(string)_
    Whether the rule is enabled.
  - **`prefix`** _(string)_
    Object key prefix the rule applies to, if scoped.
  - **`expiration_days`** _(integer)_
    Days after which matching objects expire.
- **`access_logging_enabled`** _(boolean)_
  Whether access logging is on. On AWS an unlogged bucket returns an empty document rather than an error, read as false.
- **`min_tls_version`** _(string)_
  Minimum TLS version accepted. AWS has no bucket-level setting — only a per-action policy condition, so requirements can vary by action. Null with not_supported_by_provider there.
- **`replication_targets`** _(array<string>)_
  Destination stores this store replicates to, as provider references. The destination region is not returned by the provider.
- **`replication_enabled`** _(boolean)_
  Whether any replication rule is configured and enabled.

## Code examples

### Truto CLI

```bash
truto unified cloud-infrastructure objectstores '<resource_id>' \
  -m get \
  -a '<integrated_account_id>' \
  -o json
```

### Truto TS SDK

```typescript
import Truto from '@truto/truto-ts-sdk';

const truto = new Truto({
  token: '<your_api_token>',
});

const result = await truto.unifiedApi.get(
  'cloud-infrastructure',
  'objectstores',
  '<resource_id>',
  { integrated_account_id: '<integrated_account_id>' }
);

console.log(result);
```

### Truto Python SDK

```python
import asyncio
from truto_python_sdk import TrutoApi

truto_api = TrutoApi(token="<your_api_token>")

async def main():
    result = await truto_api.unified_api.get(
        "cloud-infrastructure",
        "objectstores",
        "<resource_id>",
        {"integrated_account_id": "<integrated_account_id>"}
    )
    print(result)

asyncio.run(main())
```

### curl

```bash
curl -X GET 'https://api.truto.one/unified/cloud-infrastructure/object_stores/{id}?integrated_account_id=<integrated_account_id>' \
  -H 'Authorization: Bearer <your_api_token>' \
  -H 'Content-Type: application/json'
```

### JavaScript

```javascript
const integratedAccountId = '<integrated_account_id>';

const response = await fetch(`https://api.truto.one/unified/cloud-infrastructure/object_stores/{id}?integrated_account_id=${integratedAccountId}`, {
  method: 'GET',
  headers: {
    'Authorization': 'Bearer <your_api_token>',
    'Content-Type': 'application/json',
  },
});

const data = await response.json();
console.log(data);
```

### Python

```python
import requests

url = "https://api.truto.one/unified/cloud-infrastructure/object_stores/{id}"
headers = {
    "Authorization": "Bearer <your_api_token>",
    "Content-Type": "application/json",
}
params = {
    "integrated_account_id": "<integrated_account_id>"
}

response = requests.get(url, headers=headers, params=params)
print(response.json())
```
