Skip to content

BoxFetch Original kit

Cloudflare R2 Prefix-Scoped Bucket

This kit proves an exact bucket is absent, shows the private bucket and prefix-scoped credential plan, waits for human authority, and then verifies both the permitted prefix and a real denial outside it.

This is one of the first six BoxFetch Originals for bounded cloud work.

Windows, macOS, LinuxFree during beta

What does this kit do?

Create one new private Standard R2 bucket and prove a one-hour object credential is confined to one mandatory prefix.

Who should use it?

  • You need one new private Standard R2 bucket in an existing account.
  • You need a one-hour object credential restricted to one non-root prefix.
  • AWS CLI v2 is available for the bounded verification probes.

What will it change?

  • One new private Standard R2 bucket in the approved account.
  • One temporary object-read-write credential limited to the approved prefix for one hour.

What will the human approve?

The human creates the bounded parent token, confirms the exact account and new bucket plan, and approves bucket creation and temporary credential issuance.

What does it verify?

  • The bucket identity and private state match the approved plan.
  • Inside-prefix access succeeds, outside-prefix access is denied, and probe objects are removed.

What can it remove?

  • Evidence-bound probe objects and the exact run-created empty bucket when all teardown checks pass.

What does it deliberately not do?

  • The bucket already exists or its absence cannot be confirmed safely.
  • You need a public bucket, another storage class, or an unrestricted credential.
  • The human cannot provide the exact account, parent key, and bounded token authority.
  • A changed or non-empty bucket, unrelated objects, parent credentials, or provider outcomes that cannot be attributed safely.

How does an agent use it?

  1. Open the BoxFetch Original in the BoxFetch app.
  2. Let the kit inspect the target without making changes.
  3. Review the plan, target, and human checkpoint.
  4. Approve only the changes you intend to make.
  5. Read the verification result and run record.

How do I use it?

Create a BoxFetch account and open the app to see current beta availability. The six current Originals are free during the controlled beta, while the application remains the authority for live access.

Technical compatibility

Supported target

One new private Cloudflare R2 bucket in an existing account, verified with AWS CLI v2.

Supported systems

Windows, macOS, Linux