Azure SAS
If your infrastructure is hosted on Azure, please adopt this solution.
How to use SAS(Shared Access Signature), detailed documentation is here.
1. Overview
When a partner’s infrastructure is hosted on Microsoft Azure, Klavi utilizes the Azure SAS (Shared Access Signature) mechanism to perform secure file uploads.
A SAS is a URI that grants restricted access rights to Azure Storage resources. For this integration, Klavi requires a Service SAS or Account SAS with specific write permissions to your designated Blob Storage container.
2. Partner (Recipient/Azure) Configuration Guide
As the data recipient on Azure, you are responsible for provisioning the storage resource and generating the secure access token.
2.1 Create an Azure Blob Storage Container
- Navigate to your Azure Storage Account.
- Under Data storage, select Containers.
- Create a new container (e.g., klavi-data-inbound).
2.2 Generate the SAS Token
To allow Klavi to upload files, you must generate a SAS token with the following minimum requirements:
- Allowed Services: Blob.
- Allowed Resource Types: Object (and Container for directory access).
- Permissions:
- Create and Write (Required for uploading files).
- Read (Optional, recommended for automated checksum verification).
- List (Optional, required if Klavi needs to verify file existence).
- Expiry: Set an expiration date according to your internal security policy.
- Note: Please provide at least 12 hours of expiration time for this token to allow Klavi enough time for errors, repairs, and re uploads during the file generation process.
- Allowed Protocols: HTTPS only.
2.3 IP Whitelisting (Optional but Recommended)
For enhanced security, you can restrict the SAS token to only accept requests from Klavi’s outgoing infrastructure. Please request Klavi’s Static Outbound IP addresses to configure the "Allowed IP AddressedAllowed IP addresses" field during SAS generation.
3. Information Exchange Checklist
The following technical parameters must be shared to enable the integration.
3.1 From Partner to Klavi
Please provide the following details to the Klavi integration team:
Parameter | Description | Example |
|---|---|---|
Storage Account Name | The name of your Azure Storage Account. | partnerstorageprod |
Container Name | The specific container for file delivery. | klavi-inbound |
SAS Token | The generated string starting with ?sv=... | ?sv=2026-01-21&ss=b&srt=o&sp=wd... |
Blob Service Endpoint | Your custom or default Azure Blob URL. | https://<account>.blob.core.windows.net |
3.2 From Klavi to Partner
Klavi will provide the following information upon request:
Parameter | Description |
|---|---|
Static Outbound IPs | The IP addresses used by Klavi's AWS-based delivery service for whitelisting. |
4. Klavi Operational Workflow
Once the SAS credentials are provided, Klavi’s automated pipeline will:
- Construct Service URI: Combine the Blob Endpoint, Container Name, and SAS Token to create a secure target URI.
- Secure Upload: Perform an Authorized PUT request via HTTPS to your Azure container.
- Integrity Check: If Read permissions are granted, Klavi will verify the blob's properties to ensure the file was transmitted without corruption.
- Expiry Monitoring: Klavi’s system will alert our operations team 14 days before your SAS token is set to expire.
5. Security Best Practices
- Principle of Least Privilege: Do not share your Account Access Keys. Only provide a SAS token scoped to the specific container required for delivery.
- HTTPS Enforcement: All data transfers are encrypted in transit using TLS 1.2+.
- Token Rotation: We recommend rotating SAS tokens periodically (e.g., every 6 or 12 months) to maintain a high security posture.
- SAS Type: For better isolation, we prefer a Service SAS (scoped to a container) over an Account SAS.
Support: For technical assistance during setup, please contact our support team at [email protected].