What are Template Credentials?

Template Credentials are access credentials for storage providers, such as Amazon S3 or Google Cloud Storage, stored securely in a Transloadit Workspace. Multiple Templates can reference the same credential record.

Request + files
Results + status
A processing platform accepts an authenticated request, executes a workflow, and returns observable results. This diagram shows platform workflows broadly, not specifically Template Credentials.

How Template Credentials work

Template Credentials are reusable Workspace-side secret records that Templates can reference when a Robot needs to read from or write to an external storage service. The workflow stores an indirection to the credential instead of embedding provider keys in Assembly Instructions or browser code. Access still depends on the external provider’s permissions, expiration rules, and resource policies. They connect Transloadit’s execution environment to storage operations and therefore require dependency tracking, least-privilege scoping, and planned rotation.

Key facts

  1. One credential record may be shared by several Templates, which simplifies rotation but turns its deletion, expiration, or permission loss into a multi-workflow failure domain.
  2. A successful credential lookup does not guarantee an operation will succeed: bucket policy, object path, region, provider-side role, and allowed actions can independently deny access.
  3. Keeping provider secrets behind a Template reference prevents their disclosure in submitted Instructions, logs, or client bundles, but Collaborators with Workspace access still need appropriately limited privileges.

When Template Credentials matter

Reuse Template Credentials when several workflows need the same storage access, reducing duplicated secret configuration. Rotate or replace them carefully because one change may disrupt every dependent Template.

Common use cases for platform workflows

These examples cover platform workflows broadly, not specifically Template Credentials.

  • Running repeatable upload, import, processing, AI, storage, and notification pipelines.
  • Tracking long-running media work independently from an application request.
  • Referencing centrally stored credentials by name instead of sending storage secrets with each request.

Working with platform workflows

This guidance covers platform workflows broadly, not just Template Credentials.

A client authenticates and submits files or references together with workflow instructions. The platform validates the request, schedules dependent operations, records state transitions, and exposes results through a response, polling endpoint, or notification.

Platform concepts become reliable only when their lifecycle is explicit. Authentication, idempotency, retries, timeouts, observability, quotas, and terminal states should be designed together rather than added after failures occur.

What you gain

  • Reusable workflows separate application intent from processing infrastructure.
  • Stable job identifiers and lifecycle events improve observability and recovery.
  • Managed queues and workers let products scale without embedding every media tool.

What it costs

  • Synchronous responses are simple but keep connections open while long work executes.
  • Aggressive retries improve recovery from transient faults but can duplicate work or overload a dependency.
  • Higher concurrency reduces queue time until resource contention or a downstream limit becomes the bottleneck.

Before production

  1. Define authentication, authorization, idempotency, retries, and terminal error behavior.
  2. Observe queue time, execution time, callbacks, and partial results with stable identifiers.
  3. Exercise malformed, duplicate, interrupted, and unauthorized requests before launch.

Turn media knowledge into a working pipeline

Connect uploads, processing, AI, storage, and delivery through one declarative API — with the encoding stack, scaling, and format churn handled for you.

Try Transloadit for free