[{"data":1,"prerenderedAt":75},["ShallowReactive",2],{"help-article-connect-minio-storage":3},{"data":4},{"title":5,"excerpt":6,"content":7,"help_category":8,"seo":11},"Where Your Files Live","Where your uploaded and generated files live: S3-compatible storage isolated per workspace by bucket. Most users configure nothing; self-hosters set server env","\u003Cp>\u003Cstrong>What you&#39;ll learn\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Where your uploaded and generated files actually live, and how workspaces stay isolated.\u003C\u002Fli>\n\u003Cli>Why most users don&#39;t configure storage at all today.\u003C\u002Fli>\n\u003Cli>What self-hosters set, and what&#39;s still on the roadmap.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Chr>\n\u003Ch2>The concept: S3-compatible object storage, isolated by bucket\u003C\u002Fh2>\n\u003Cp>When you upload an image to a content piece, or the \u003Ca href=\"\u002Fhelp\u002Fthe-graphics-generator\">Graphics Generator\u003C\u002Fa> produces one, the file has to live somewhere. m18t doesn&#39;t keep media on the app server — it uses S3-compatible object storage. Each workspace gets its own isolated bucket. That bucket boundary is how one workspace&#39;s files stay separate from another&#39;s.\u003C\u002Fp>\n\u003Cp>Here&#39;s the honest state of things, and it differs from AI or CMS keys: \u003Cstrong>storage credentials are not in the \u003Ca href=\"\u002Fhelp\u002Fthe-secret-vault\">Vault\u003C\u002Fa> today.\u003C\u002Fstrong> Unlike OpenAI or Strapi tokens — which you bring per brand and store encrypted — storage is configured once at the server-environment level. Per-workspace bring-your-own storage (S3 \u002F R2 \u002F GCS) is on the roadmap, not shipped. Until it lands, isolation is enforced by the per-workspace bucket name, not by per-workspace credentials.\u003C\u002Fp>\n\u003Ch2>If you&#39;re on a hosted\u002Fmanaged m18t (most beta users)\u003C\u002Fh2>\n\u003Cp>You don&#39;t configure storage at all. The server already has S3 credentials in its environment. The first time you upload a file or generate an image, m18t uses those credentials to create your workspace bucket and writes there. Nothing is required on your end — there&#39;s no storage connection to add in the Vault or the Connections page.\u003C\u002Fp>\n\u003Ch2>If you&#39;re self-hosting m18t\u003C\u002Fh2>\n\u003Cp>You set the storage target through environment variables on the m18t server, not through any in-app screen. In your m18t server environment (e.g. its \u003Ccode>.env\u003C\u002Fcode> file), point at your MinIO (or other S3-compatible) instance:\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-env\">S3_ENDPOINT=&quot;http:\u002F\u002Flocalhost:9000&quot;\nS3_REGION=&quot;us-east-1&quot;\nS3_ACCESS_KEY=&quot;your_minio_access_key&quot;\nS3_SECRET_KEY=&quot;your_minio_secret_key&quot;\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Restart the server process. m18t uses these administrative credentials to create workspace buckets as workspaces upload or generate files. Because this is a server-level setting, it applies across the whole instance — there is no per-workspace or per-brand storage override in the UI yet.\u003C\u002Fp>\n\u003Ch2>What the Storage page in Studio actually does\u003C\u002Fh2>\n\u003Cp>If you open the storage area under Configuration (\u003Ccode>\u002Fstudio\u002Fconfig\u002Fstorage\u003C\u002Fcode>), you&#39;ll find a page titled \u003Cstrong>Export Your Data\u003C\u002Fstrong>, not a storage connection manager. Its one action is \u003Cstrong>Download database snapshot\u003C\u002Fstrong> — a consistent export of your workspace database as a standard database file you can keep as a personal backup.\u003C\u002Fp>\n\u003Cp>The page itself states the rest plainly: storage BYOK (S3 \u002F R2 \u002F GCS) is on the roadmap, and when it ships, this page is where a fuller storage manager (scheduled backups, integrity checks, per-asset control) will live. For now, the export is what&#39;s here.\u003C\u002Fp>\n\u003Ch2>FAQ\u003C\u002Fh2>\n\u003Cp>\u003Cstrong>Where do I paste my S3 \u002F MinIO keys in the app?\u003C\u002Fstrong>\nNowhere, today. Storage isn&#39;t a Vault connection yet. Hosted users need nothing; self-hosters set server environment variables. Per-workspace storage BYOK is roadmap.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Are my files isolated from other workspaces?\u003C\u002Fstrong>\nYes — each workspace writes to its own isolated bucket. Isolation is at the bucket level. (Per-workspace \u003Cem>credentials\u003C\u002Fem> are the roadmap addition, not the isolation itself.)\u003C\u002Fp>\n\u003Cp>\u003Cstrong>My uploads or generated images are failing.\u003C\u002Fstrong>\nOn hosted m18t, that&#39;s a server-side issue — contact support. On self-hosted, check your \u003Ccode>S3_*\u003C\u002Fcode> environment variables and that your MinIO instance is reachable from the m18t server, then restart.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Can I use AWS S3, Cloudflare R2, or GCS instead of MinIO?\u003C\u002Fstrong>\nThe storage layer is S3-compatible, so an S3-compatible endpoint can work for self-hosters via the same env vars. Formal per-workspace BYOK across S3\u002FR2\u002FGCS is the roadmap item.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>How do I back up my data right now?\u003C\u002Fstrong>\nUse \u003Cstrong>Download database snapshot\u003C\u002Fstrong> on the Export Your Data page to grab your workspace database. Media lives in your bucket separately.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What&#39;s next\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>See how files are organised once stored: \u003Ca href=\"\u002Fhelp\u002Fthe-workspace-media-hub\">The Workspace Media Hub\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>Understand what \u003Cem>is\u003C\u002Fem> in the Vault (and what isn&#39;t): \u003Ca href=\"\u002Fhelp\u002Fthe-secret-vault\">The Secret Vault\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>The credential model in general: \u003Ca href=\"\u002Fhelp\u002Fbyok-why-we-do-this\">Why m18t uses BYOK\u003C\u002Fa>.\u003C\u002Fli>\n\u003C\u002Ful>\n",{"slug":9,"title":10},"connections-and-keys","Connections & API Keys",{"meta_title":12,"meta_description":6,"keywords":13,"canonical_url":14,"og_title":5,"og_description":15,"og_image":16,"robots":17,"json_ld":18},"Where Your Files Live | m18t Help","minio storage, s3-compatible, workspace bucket, object storage, self-hosted m18t, storage env vars, database snapshot backup","https:\u002F\u002Fm18t.com\u002Fhelp\u002Fconnect-minio-storage","S3-compatible storage isolated per workspace by bucket. Hosted users set nothing; self-hosters set env vars.","https:\u002F\u002Fm18t.com\u002Fog-default.png","index, follow",{"@context":19,"@graph":20},"https:\u002F\u002Fschema.org",[21,34,59],{"@type":22,"headline":5,"description":6,"articleSection":10,"inLanguage":23,"datePublished":24,"dateModified":24,"image":16,"author":25,"publisher":29,"mainEntityOfPage":32},"Article","en","2026-06-25",{"@type":26,"name":27,"url":28},"Organization","m18t","https:\u002F\u002Fm18t.com",{"@type":26,"name":27,"url":28,"logo":30},{"@type":31,"url":16},"ImageObject",{"@type":33,"@id":14},"WebPage",{"@type":35,"mainEntity":36},"FAQPage",[37,43,47,51,55],{"@type":38,"name":39,"acceptedAnswer":40},"Question","Where do I paste my S3 \u002F MinIO keys in the app?",{"@type":41,"text":42},"Answer","Nowhere, today. Storage isn't a Vault connection yet. Hosted users need nothing; self-hosters set server environment variables. Per-workspace storage BYOK is roadmap.",{"@type":38,"name":44,"acceptedAnswer":45},"Are my files isolated from other workspaces?",{"@type":41,"text":46},"Yes — each workspace writes to its own isolated bucket. Isolation is at the bucket level. Per-workspace credentials are the roadmap addition, not the isolation itself.",{"@type":38,"name":48,"acceptedAnswer":49},"My uploads or generated images are failing.",{"@type":41,"text":50},"On hosted m18t, that's a server-side issue — contact support. On self-hosted, check your S3_* environment variables and that your MinIO instance is reachable from the m18t server, then restart.",{"@type":38,"name":52,"acceptedAnswer":53},"Can I use AWS S3, Cloudflare R2, or GCS instead of MinIO?",{"@type":41,"text":54},"The storage layer is S3-compatible, so an S3-compatible endpoint can work for self-hosters via the same env vars. Formal per-workspace BYOK across S3\u002FR2\u002FGCS is the roadmap item.",{"@type":38,"name":56,"acceptedAnswer":57},"How do I back up my data right now?",{"@type":41,"text":58},"Use Download database snapshot on the Export Your Data page to grab your workspace database. Media lives in your bucket separately.",{"@type":60,"itemListElement":61},"BreadcrumbList",[62,66,70,73],{"@type":63,"position":64,"name":65,"item":28},"ListItem",1,"Home",{"@type":63,"position":67,"name":68,"item":69},2,"Help","https:\u002F\u002Fm18t.com\u002Fhelp",{"@type":63,"position":71,"name":10,"item":72},3,"https:\u002F\u002Fm18t.com\u002Fhelp\u002Fcategories\u002Fconnections-and-keys",{"@type":63,"position":74,"name":5,"item":14},4,1786312169480]