Setting Up Your Delivery Channel

Team
Utilities Team
Last Updated
September 3, 2026

Setting up your delivery channel

Before creating your credential in the dashboard, you need to set up storage in your cloud provider and generate the access credentials. This document walks you through each of the three supported delivery channels: AWS S3, Azure Blob Storage, and Google Cloud Storage.

The bucket/container name must be between 3 and 63 characters and use only lowercase letters, numbers, dots, hyphens, and underscores, starting and ending with a letter or number.

AWS S3

Creating the bucket

  1. Go to AWS at https://aws.amazon.com and log in to the console.
  2. In the search bar, search for Amazon S3 and select S3 under Services.
  3. If needed, change the region in the top right corner. Note the region you chose — you'll need it when creating the credential.
  4. Click Create bucket.
  5. Give the bucket a name (the name is unique across AWS's global namespace).
  6. At the bottom of the page, click Create bucket.

Creating the user and access keys

  1. In the top right corner, click your AWS user name and then Security Credentials.
  2. In the left menu, click Users and, on the page that opens, click Create user.
  3. Give the user a name, for example Grouplink — this is the user that will be used to save files in your bucket.
  4. Click Next and, under Set permissions, click Attach policies directly.
  5. Search for s3 and add the AmazonS3FullAccess permission.
  6. Click Next and then Create user.
  7. In the user list, click the user you created and go to the Security Credentials section.
  8. In the Access Keys box, click Create access key.
  9. On the next screen, select Third-party service and check I understand the above recommendation.
  10. Give the description tag a name, for example Grouplink, and click Create access key.
  11. Copy the Access key and the Secret access key. The secret access key is shown only once.

Values for the credential

Dashboard fieldValue
Access keyAccess key generated in the previous step
Secret keySecret access key generated in the previous step
Endpoint`https://s3.<region>.amazonaws.com` — for example, `https://s3.us-east-1.amazonaws.com`
RegionThe bucket's region — for example, `us-east-1`
Container / Bucket nameName of the bucket you created

The endpoint must include https:// and must not contain the bucket name. The region you enter must match the bucket's region.

Azure Blob Storage

Creating the Storage Account

  1. Go to https://portal.azure.com and log in to the console.
  2. In the top bar, search for Storage Accounts and select it.
  3. Click Create.
  4. Under Subscription, select your subscription.
  5. Under Resource Group, select an existing one or create a new one.
  6. Under Storage Account Name, set a unique name (lowercase letters and numbers only). Note this name — it will be used in the connection string.
  7. Under Region, select the region you want.
  8. Under Performance, select Standard.
  9. Under Redundancy, select LRS or another option as needed.
  10. Click Review + Create and then Create.
  11. Wait for it to be created and click Go to resource.

Creating the container

  1. In the Storage Account's side menu, click Containers.
  2. Click + Container.
  3. Under Name, set the container name, for example grouplink.
  4. Under Public access level, select Private (no anonymous access).
  5. Click Create.

Creating the Service Principal

The Service Principal is the equivalent of the AWS IAM user — it's what authorizes the file uploads.

  1. In the Azure portal, search for Microsoft Entra ID.
  2. In the side menu, click App registrations.
  3. Click New registration.
  4. Under Name, enter Grouplink.
  5. Keep the remaining options at their defaults and click Register.
  6. On the App Registration's main screen, copy the Application (client) ID and the Directory (tenant) ID.

Creating the Client Secret

  1. In the App Registration's side menu, click Certificates & secrets.
  2. Click + New client secret.
  3. Under Description, enter Grouplink.
  4. Choose the expiration period.
  5. Click Add.
  6. Copy the Value immediately — it won't be shown again.

Granting permissions

  1. Go back to the Storage Account you created.
  2. In the side menu, click Access Control (IAM).
  3. Click + Add and then Add role assignment.
  4. Under Role, search for and select Storage Blob Data Contributor.
  5. Click Next.
  6. Under Members, click + Select members.
  7. Search for the Grouplink App Registration, select it, and click Select.
  8. Click Review + Assign.

Values for the credential

Dashboard fieldValue
Tenant IDThe App Registration's Directory (tenant) ID
Client IDThe App Registration's Application (client) ID
Client secretThe client secret's Value
Connection string`https://<StorageAccountName>.blob.core.windows.net`
Container / Bucket nameName of the container you created

The connection string is only the storage account's URL: do not include the container name in it, since the container goes in its own field. If your account has hierarchical namespace enabled (Data Lake Storage Gen2), use https://<StorageAccountName>.dfs.core.windows.net.

Google Cloud Storage

Creating the bucket

  1. Go to https://console.cloud.google.com and log in.
  2. Select or create the project that will receive the files. Note the Project ID — it appears in the project selector and is different from the project name.
  3. In the side menu, go to Cloud Storage and then Buckets.
  4. Click Create.
  5. Under Name your bucket, set a globally unique name.
  6. Under Choose where to store your data, select the region you want.
  7. Under Choose a storage class for your data, keep Standard.
  8. Under Choose how to control access to objects, keep Uniform and public access prevention enabled.
  9. Click Create.

Creating the service account

The service account is the equivalent of the AWS IAM user.

  1. In the side menu, go to IAM & Admin and then Service Accounts.
  2. Click Create service account.
  3. Under Service account name, enter Grouplink.
  4. Click Create and continue.
  5. Skip the project-level access step — the permission will be granted directly on the bucket. Click Done.
  6. Copy the created service account's email, in the format grouplink@<project-id>.iam.gserviceaccount.com.

Granting permissions on the bucket

  1. Go back to Cloud Storage and then Buckets, and click the bucket you created.
  2. Open the Permissions tab.
  3. Click Grant access.
  4. Under New principals, paste the service account's email.
  5. Under Role, select Storage Admin.
  6. Click Save.

A permission granted this way applies only to that bucket, not to the entire project.

Generating the JSON key

  1. Go back to IAM & Admin and then Service Accounts, and click the Grouplink service account.
  2. Open the Keys tab.
  3. Click Add key and then Create new key.
  4. Select the JSON format and click Create. The file is downloaded automatically.
  5. Open the downloaded file and copy its entire contents — this is what goes in the Credentials JSON field.

Values for the credential

Dashboard fieldValue
Project IDThe project's Project ID
Credentials JSONThe full contents of the downloaded `.json` file
Container / Bucket nameName of the bucket you created

After setting up

With these values in hand, go to Credential Creation in the dashboard.

In the Validation step, use the Test credential button: it uploads a test file named Teste de credenciais GroupLinkOne.csv to your bucket. If the upload succeeds, your permissions are correct.

Technical Support

If you have any questions or technical issues during the process, our technical support team is available. You can reach us by email at [email protected] or via WhatsApp at (11) 91162-6684.