> ## Documentation Index
> Fetch the complete documentation index at: https://docs.uplint.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Set Default Bucket

> Mark a bucket as the tenant's default (fallback) bucket. Uploads whose context has no `storage_config_id` — and downloads that cannot otherwise be resolved — use the default bucket. Exactly one bucket is the default at any time.



## OpenAPI

````yaml POST /api/v1/tenants/{tenant_id}/storage-configs/{config_id}/set-default
openapi: 3.0.3
info:
  title: Uplint API
  version: 0.1.0
  description: >-
    Uplint is a file safety and integrity platform. Upload files through
    context-aware pipelines that automatically validate integrity, detect blank
    or placeholder content, and scan for viruses — all behind a single API.


    This specification covers the core Uplint REST API:


    - **API Keys** — Create and manage scoped API keys for programmatic access.

    - **File Contexts** — Define upload pipelines with per-context rules
    (allowed extensions, size limits, blank/corrupt rejection, virus scanning,
    rate limits, and storage quotas).

    - **Files** — Upload, list, download, inspect, and delete files. Every
    upload runs through the validation pipeline configured on its context.


    All endpoints are tenant-scoped. Authenticate with an API key or JWT token
    via the `Authorization` header.
  contact:
    name: Uplint Team
    url: https://uplint.dev
  license:
    name: MIT
    url: https://opensource.org/licenses/MIT
servers:
  - url: https://api.uplint.dev
    description: Production
  - url: http://localhost:8000
    description: Local development
security:
  - BearerAuth: []
tags:
  - name: API Keys
    description: >-
      Create, list, inspect, update, and revoke API keys. Each key carries
      scoped permissions (`upload`, `download`, `metadata`, `delete`, `admin`)
      and is bound to the authenticated tenant.
  - name: File Contexts
    description: >-
      File contexts define upload pipelines. Each context specifies allowed
      extensions, max file size, whether to reject blank or corrupt files, virus
      scanning, rate limits, and storage quotas. Files are always uploaded into
      a context.
  - name: Files
    description: >-
      Upload, list, download, inspect metadata, and delete files. Every upload
      is validated against its context rules before storage.
  - name: Storage Buckets
    description: >-
      Manage the S3 buckets a tenant stores files in. Each tenant can register
      multiple buckets (bring-your-own S3 credentials); one is the **default**
      (fallback) bucket, and file contexts can be routed to any active bucket.
      All storage endpoints require an `admin`-scoped API key.
paths:
  /api/v1/tenants/{tenant_id}/storage-configs/{config_id}/set-default:
    post:
      tags:
        - Storage Buckets
      summary: Set default storage bucket
      description: >-
        Mark a bucket as the tenant's default (fallback) bucket. Uploads whose
        context has no `storage_config_id` — and downloads that cannot otherwise
        be resolved — use the default bucket. Exactly one bucket is the default
        at any time.
      operationId: setDefaultStorageBucket
      parameters:
        - $ref: '#/components/parameters/TenantId'
        - $ref: '#/components/parameters/StorageConfigId'
      responses:
        '200':
          description: Default bucket updated.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SuccessResponse_StorageConfig'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
      security:
        - BearerAuth: []
components:
  parameters:
    TenantId:
      name: tenant_id
      in: path
      required: true
      schema:
        type: string
      description: The tenant's unique identifier.
    StorageConfigId:
      name: config_id
      in: path
      required: true
      schema:
        type: string
      description: The storage configuration (bucket) identifier, e.g. `cfg_a1b2c3d4e5f6`.
  schemas:
    SuccessResponse_StorageConfig:
      type: object
      properties:
        status:
          type: string
          enum:
            - SUCCESS
        message:
          type: string
        data:
          $ref: '#/components/schemas/StorageConfigResponse'
        timestamp:
          type: string
          format: date-time
    StorageConfigResponse:
      type: object
      properties:
        config_id:
          type: string
          description: Configuration identifier.
        tenant_id:
          type: string
        name:
          type: string
          description: Human-friendly bucket label.
        provider:
          type: string
          enum:
            - aws_s3
          description: Storage provider.
        access_key_id:
          type: string
          description: AWS access key ID, masked (e.g. `AKIA...MPLE`).
        region:
          type: string
        default_bucket:
          type: string
          description: S3 bucket name.
        base_path:
          type: string
          description: Key prefix applied to objects in this bucket.
        is_active:
          type: boolean
          description: Whether this bucket is available for routing.
        is_default:
          type: boolean
          description: Whether this is the tenant's default (fallback) bucket.
        created_at:
          type: string
          format: date-time
          nullable: true
        updated_at:
          type: string
          format: date-time
          nullable: true
    ErrorResponse:
      type: object
      properties:
        status:
          type: string
          enum:
            - ERROR
        message:
          type: string
        errors:
          type: array
          items:
            type: string
        timestamp:
          type: string
          format: date-time
  responses:
    Unauthorized:
      description: Missing, invalid, or expired authentication credentials.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          example:
            status: ERROR
            message: Invalid or missing API key
            errors:
              - Authentication required
            timestamp: '2026-02-10T12:00:00Z'
    Forbidden:
      description: The API key lacks the required `admin` scope.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          example:
            status: ERROR
            message: Admin scope required
            errors:
              - Insufficient permissions
            timestamp: '2026-02-10T12:00:00Z'
    NotFound:
      description: The requested resource does not exist.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          example:
            status: ERROR
            message: Resource not found
            errors:
              - Not found
            timestamp: '2026-02-10T12:00:00Z'
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: >-
        Pass an API key or JWT token. API keys can be sent as `Authorization:
        Bearer <key>` or `Authorization: <key>`.

````