Shared Access Signature
A Shared Access Signature (SAS) is a URI-based token that grants time-limited, scoped access to Azure Storage resources — blobs, queues, tables, or files — without sharing the storage account's master key. It encodes the permissions (read, write, delete), start and expiry times, and allowed IP ranges directly in the signed token, letting you hand out narrow, revocable access to a specific container or file.
Shared Access Signature
A SAS token encodes permissions, an expiry time, and a signature directly into a URL, letting you hand out time-limited access without exposing the account key.
Why It Matters in Production
Razorpay generates a SAS token valid for 15 minutes when a merchant needs to download a settlement report, rather than exposing the storage account key in the frontend.
az storage blob generate-sas --account-name razorpayprodstorage
--container-name settlements --name report-aug-2026.csv
--permissions r --expiry 2026-08-20T18:00:00Z --https-only
SecurityA leaked account access key grants full control forever until rotated. A leaked SAS token only grants the specific permission until it expires.
Frequently Asked Questions
How does a Shared Access Signature differ from an Azure Storage account key?
A storage account key grants full, unrestricted access to every container, blob, and service in that account and doesn't expire until you rotate it. A SAS token is scoped: you define exactly which permissions (read, write, list, delete), which resource, what IP range, and an expiry timestamp — all encoded into the query-string signature. This lets you hand a SAS URL to a third-party app or user without exposing the master key.
What's a common SAS token mistake that leads to a security incident?
Setting an expiry far in the future (or none) and embedding the SAS URL in client-side JavaScript or a public repo, effectively making it a permanent, unrevoked credential. Because a SAS signed with the account key can't be individually revoked before expiry (only by rotating the key, which breaks all SAS tokens signed with it), best practice is short expiries plus using a Stored Access Policy so you can revoke specific SAS grants without rotating the whole key.