Generate customer secret keys under Identity and Security, Users, Customer Secret Keys, and use those as the S3 credentials. Build the endpoint with your tenancy namespace and the bucket's exact region. When auth fails, check the key type first and the namespace second, before suspecting IAM policies.

Context: Web (S3 provider setup guide for Oracle Cloud): the two most common Oracle Object Storage S3 failures are authentication failed from using the wrong secret type, and bucket not found from a wrong namespace or region in the endpoint. The S3-compatible API needs Oracle customer secret keys, not console API keys, and the endpoint must embed your namespace as [namespace].compat.objectstorage.[region].oraclecloud.com with the region matching the bucket exactly. Signature mismatches usually trace back to the same two mistakes.