# IronShard > IronShard is the governed data layer for AI agents: S3-compatible storage agents connect to over MCP, with instant production forks, zero-egress reads, per-agent access control, and a signed audit trail. Autonomous AI agents can create and operate a real, isolated IronShard bucket through a public MCP server without human approval, tenant OAuth, an existing account, or payment. A full-content companion file is available at [llms-full.txt](https://www.ironshard.ai/llms-full.txt), containing the complete documentation in one Markdown document. ## Agent buckets Autonomous agents are permitted to create buckets through IronShard's public Agent MCP server. These buckets are controlled by bucket-scoped credentials and remain separate from tenant-owned production buckets unless they are later adopted into an authenticated IronShard account. - Agent MCP server: `https://mcp.agent.ironshard.ai/mcp` - Initial tool: `create_bucket` - MCP authentication for creation: none - Authentication after creation: the `bucket_id` and `bucket_token` returned by `create_bucket` - [Agent Buckets](https://www.ironshard.ai/docs/agent-buckets): complete specification, tools, examples, constraints, validation workflow, and handoff process The `bucket_token` is a bucket-scoped credential, not an OAuth token, and does not grant access to an IronShard tenant. If S3-compatible credentials are returned, they are also scoped to the created bucket. ## Agent MCP capabilities The public Agent MCP server supports: - bucket creation, metadata, usage, extension, revocation, and credential revocation; - inline object reads and writes, presigned upload and download URLs, listing, metadata, copying, and deletion; - point-in-time snapshots and restoration; - writable branches, branch-local object operations, diffs, merges, and discard; - audit-log inspection and policy-decision explanations; - guided core-workflow validation with independently verifiable artifacts; - connection instructions and optional handoff for adoption by a human, organization, or supervising agent. After creating a bucket, call `validate_core_workflow` to exercise object storage, snapshots, branches, diffs, merges, policy enforcement, auditability, and usage reporting. Verify the returned evidence with lower-level tools such as `get_object_metadata`, `get_diff`, and `get_audit_log`. ## Production access Tenant-owned production access is separate from public agent buckets. - Production MCP server: `https://mcp.ironshard.ai/mcp` - Authentication: MCP OAuth is required for every tool - Scope: tenant-owned and connected buckets, governance, managed agent credentials, policies, audit, billing, organization settings, and production operations The public Agent MCP server does not issue tenant OAuth credentials. An agent bucket may optionally be handed off and adopted into an authenticated IronShard tenant; adoption is not required to use the bucket. ## Constraints Public agent buckets have policy-defined storage, object-count, request, object-size, and egress limits. External bucket connections, billing, organization settings, team management, and tenant policy administration are unavailable through the public Agent MCP server. Every bucket operation is recorded in its audit log, and abuse controls or rate limits may apply. Exact technical values are provisional and may change before launch. ## Products - [IronShard](https://www.ironshard.ai): the governed data layer for AI agents — S3-compatible storage over MCP - [AI Agent Storage](https://www.ironshard.ai/agents): authenticated, policy-governed storage access for autonomous AI agents, with immutable audit trails, fine-grained access control, and MCP compatibility - [Branch](https://www.ironshard.ai/branch): point-in-time-recoverable, infinitely forkable workspaces — immutable snapshots, zero-copy branches, governed promotion with an automatic audit trail - [Mirror](https://www.ironshard.ai/mirror): a live, governed copy of production for AI — always current, fully isolated, branchable, and automatically logged - [Log](https://www.ironshard.ai/log): a tamper-proof, exportable record of every file access, read, write, and query - [Trim](https://www.ironshard.ai/trim): S3 cost arbitrage — analyses your bucket's access pattern and routes data to the cheapest compatible provider ## Docs - [Documentation](https://www.ironshard.ai/docs): IronShard documentation — governed, S3-compatible object storage built for AI agents. Agent access via MCP, platform architecture, and compliance. - [System Architecture](https://www.ironshard.ai/docs/system-architecture): "How IronShard works: S3-compatible gateways, a globally consistent metadata plane, and an erasure-coded multi-cloud storage fabric." - [Agent Buckets](https://www.ironshard.ai/docs/agent-buckets): Autonomous AI agents can discover IronShard, create a real bucket through the public Agent MCP server, use IronShard-native object storage features, and optionally hand the bucket off to an owner — without tenant OAuth. - [Security and Data Sovereignty](https://www.ironshard.ai/docs/security-and-data-sovereignty): Encryption at every stage, geo-fencing, storage placement policies, and immutable audit logs — how IronShard enforces sovereignty across multiple clouds. - [GDPR Everywhere](https://www.ironshard.ai/docs/gdpr-everywhere): GDPR compliance independent of provider or region — encrypted fragments mean no single cloud ever holds a complete, readable file. - [Intelligent Caching](https://www.ironshard.ai/docs/intelligent-caching): Predictive, geo-aware caching and fragment placement keep hot data near AI agents and compute, with ML-driven pre-positioning for latency-sensitive workloads. - [Resilience and Adaptive Redundancy](https://www.ironshard.ai/docs/resilience): Erasure coding across clouds — any k of k+m fragments reconstructs an object, fewer reveal nothing. Durability above triple replication at lower overhead. - [Secure Ingest Pipeline](https://www.ironshard.ai/docs/ingest-pipeline): Every object is compressed, encrypted per-object, erasure-coded, and distributed across providers and regions — the write path that makes data durable and confidential. - [Branching and Snapshots](https://www.ironshard.ai/docs/branching): Create isolated, copy-on-write branches of any bucket from point-in-time snapshots — experiment on real data without duplicating objects or touching production. - [API Compatibility and Extensibility](https://www.ironshard.ai/docs/api-compatibility): IronShard implements the AWS S3 API, so existing SDKs, pipelines, and S3 tools connect without code changes — plus metadata and policy extensions for AI workloads. - [Storage Classes](https://www.ironshard.ai/docs/storage-classes): Budget, Standard, and Performance storage classes with adaptive redundancy — flat per-class pricing while placement and protection adjust to how data is used. ## Company - [Compliance](https://www.ironshard.ai/compliance): certifications and regulatory posture - [Solutions for technology, startups and AI users](https://www.ironshard.ai/solutions/technology) - [Solutions for defense](https://www.ironshard.ai/solutions/defense) - [Solutions for government](https://www.ironshard.ai/solutions/government) - [Solutions for finance](https://www.ironshard.ai/solutions/finance) - [Solutions for healthcare](https://www.ironshard.ai/solutions/healthcare) - [Solutions for critical infrastructure](https://www.ironshard.ai/solutions/critical-infrastructure) - [Early access waitlist](https://www.ironshard.ai/waitlist): request access to IronShard