Command line
s3lens api calls one JSON-RPC method on a running S3 Lens server and prints its result. It is the shell form of the protocol, not an S3 client: every method in the revision 1 reference is available, with the same names and parameters.
Methods are subcommands
Section titled “Methods are subcommands”Each / in a wire method name is one subcommand level, and each parameter is a long flag in kebab case:
s3lens api provider lists3lens api object list --provider-id dev --bucket-name photos --prefix 2026/ --limit 50s3lens api object tags get --provider-id dev --bucket-name photos --key a.jpgs3lens api bucket policy status get --provider-id dev --bucket-name photoss3lens api --help lists the method groups, s3lens api object --help lists the methods in one group, and s3lens api object list --help describes every parameter. The tree is generated from the protocol schema, so it always matches the server build it ships with.
Parameter values
Section titled “Parameter values”| Parameter type | Flag value |
|---|---|
| String | Verbatim |
| Integer, number, boolean | Parsed; --limit many is a usage error |
| Enumeration | One of the values shown under [possible values: …] |
| Object, array, or free-form JSON | A JSON document: --tags '{"env":"prod"}' |
Base64 content (--content-base64) |
Base64 text, or @path to read and encode a file |
A value that starts with @ is read from that file: base64 parameters receive the file’s bytes encoded, JSON parameters receive the parsed document, and other strings receive the file’s UTF-8 text.
--input PATH supplies a complete parameters object from a file, or from standard input with --input -; flags then override individual members. This is the natural form for nested parameters such as an API Key scope:
s3lens api api-key create --input - <<'INPUT'{ "name": "media automation", "expiresAt": "2026-12-31T00:00:00Z", "scope": { "rules": [{ "actions": ["objects:list"], "resources": [{ "type": "all" }] }] }}INPUTParameters are checked against the protocol before anything is sent, so a missing or mistyped value fails locally with the server’s own wording.
Server and credential
Section titled “Server and credential”| Setting | Flag | Environment variable | Default |
|---|---|---|---|
| Server | --server URL |
S3LENS_SERVER |
http://127.0.0.1:8085 |
| Credential | --credential SECRET |
S3LENS_CREDENTIAL |
none |
--server is the server’s origin; the command calls /rpc beneath it. The credential is sent as a bearer token and may be an s3l_ak_… API Key or a native session credential. An unauthenticated server needs neither. The credential is never printed.
export S3LENS_SERVER=https://s3lens.example.comexport S3LENS_CREDENTIAL=s3l_ak_REPLACE_WITH_THE_ISSUED_SECRETs3lens api provider listOutput and exit status
Section titled “Output and exit status”Standard output carries the method result and nothing else, pretty-printed on a terminal and on one line when piped, so jq needs no unwrapping:
s3lens api provider list | jq -r '.providers[].id's3lens api object get --provider-id dev --bucket-name photos --key a.jpg | jq -r .contentBase64 | base64 -d > a.jpg| Outcome | Standard output | Standard error | Exit |
|---|---|---|---|
| Result | The result | — | 0 |
| JSON-RPC error from the server | The error object (code, message, data) |
One line | 1 |
| Usage error, invalid parameters, unreachable server, missing credential | — | One line | 2 |
--envelope prints the complete JSON-RPC response envelope instead of the bare result or error. --schema prints the method’s parameter and result JSON Schemas without calling it.
Listings and notifications
Section titled “Listings and notifications”--paginate follows nextCursor on any method with a cursor parameter and prints one result per page, newline-delimited:
s3lens api object list --provider-id dev --bucket-name photos --paginate | jq -r '.objects[].key'--notify sends the notification form of a method that has one (server/ping); nothing is printed and no result is expected. A method’s long help says whether --paginate or --notify applies.
Object bodies
Section titled “Object bodies”Revision 1 carries complete Object bodies as base64 inside the JSON-RPC response, bounded by the server’s server.max_object_body_bytes. For large Objects, create a streaming transfer ticket and move the bytes with any HTTP client:
url=$(s3lens api object transfer create --provider-id dev --bucket-name photos --key big.iso --direction download | jq -r .url)curl --fail --output big.iso "$S3LENS_SERVER$url"