Three lines

Uber

Developers

Data Hosting

To leverage Uber AI Solutions, we need customers to upload data to our platform so we can process it.

Example Data Annotation Workflow

  1. An API call is submitted to Uber AI Solutions referencing the data/attachment that needs to be processed. The data/attachments need to be made accessible to Uber AI Solutions through any of the multiple ways (see below).
  2. Uber AI Solutions will make a secure copy of the customer data, for further processing.
  3. If task attachments are inaccessible by our servers, the task is moved to error state, and the processing is halted.

Ways to share data with Uber AI Solutions

Uber AI Solutions has built-in support for:

  1. Google Cloud Storage
  2. AWS S3
  3. Azure Blob Storage

Google Cloud Storage

If you use Google Cloud Storage to store data, we can fetch your data using Service Account Impersonation.

Service Account Impersonation

To access Cloud Storage data in your GCP project, Uber AI Solutions can impersonate a service account within that GCP project, which has permission to access data in Cloud Storage.

Setting Up Data Transfer Using GCP IAM Service Account Impersonation

To configure data transfer using GCP IAM Service Account Impersonation, follow these steps:

  1. Obtain the Service Account Name via Client Portal:

    • Go to Client Portal.
    • Select the workspace in which you would like to create a new cloud connection or modify an existing connection.
    • Click the Edit Workspace.
    • In the pop-up window, choose Google Cloud Platform as the cloud provider.
    • Once GCP is selected, the secret key will be displayed. Include this key in your service account naming.
  2. Create a New Service Account in GCP: In your GCP project, create a new service account. When naming the service account, include the key provided in the Client Portal as part of the service account name.

  3. Grant Impersonation Permissions: Assign the Service Account Token Creator role to Uber’s GCP service account: client-data-access@uber-scaledsolutions-775671.iam.gserviceaccount.com This will allow Uber to impersonate the newly created service account.

  4. Assign Required Bucket Permissions: Grant the newly created service account the necessary permissions for the required buckets:

    • Read Object
    • List Bucket
  5. Provide the Service Account Email in Client Portal: In the same Edit Workspace pop-up window, enter the email address of the newly created GCP service account in the GCP service account email field. Once entered, click Update to save.

Attachment URIs

To reference data stored in google cloud storage, customers can submit tasks with attachments as gs: protocol URIs.

For example, an example image URI would be gs://client/test-image-uri

AWS S3

If you use AWS S3 to store data, we can fetch your data using IAM Delegated Access.

IAM Delegated Access

To access S3 data in your AWS account, Uber AI Solutions can assume a role in your AWS account, which has permission to access data in your S3 buckets.

To set up data transfer using AWS IAM Delegate Access, the following steps need to be followed:

  1. Obtain the integration_secret via Client Portal.

    • Go to Client Portal.
    • Select the workspace in which you would like to create a new cloud connection or modify an existing connection.
    • Click the Edit Workspace.
    • In the pop-up window, choose AWS as the cloud provider.
    • Once AWS is selected, the integration secret will be displayed. Use this value as the External ID when creating your IAM role.
  2. Create a new IAM role, and provide access to Uber IAM user to assume the client role. The steps are as follows:

    1. Create a new role in AWS IAM Console.
    2. Select Trusted Entity Type as AWS Account
    3. Select Another AWS account for the Role Type.
    4. Enter 654654196884 (Uber’s Account ID) as the Account ID.
    5. Check Require external ID, and enter integration_secret you retrieved from the Client Portal.
    6. Do not check Require MFA.
    7. Edit the trust policy to provide access to Uber AWS IAM user: arn:aws:iam::654654196884:user/svc/svc-client-data-access.
  3. The final trust policy should look something like:

    {
        "Version": "2012-10-17",
        "Statement": [
            {
                "Effect": "Allow",
                "Principal": {
                    "AWS": "arn:aws:iam::654654196884:user/svc/svc-client-data-access"
                },
                "Action": "sts:AssumeRole",
                "Condition": {
                    "StringEquals": {
                        "sts:ExternalId": {integration_secret}
                    }
                }
            }
        ]
    }
    
    /* for multiple principals can use array */
    
    {
        "Version": "2012-10-17",
        "Statement": [
            {
                "Effect": "Allow",
                "Principal": {
                    "AWS": ["arn:aws:iam::654654196884:user/svc/svc-client-data-access", "arn:aws:iam::3453453434:user/svc/svc-client-data-access"]
                },
                "Action": "sts:AssumeRole",
                "Condition": {
                    "StringEquals": {
                        "sts:ExternalId": {integration_secret}
                    }
                }
            }
        ]
    }
    
  4. Assign the required permissions (read/list) for the requisite buckets to the newly created client IAM role.

Attachment URIs

To reference data stored in AWS S3, customers can submit tasks with attachments as s3: protocol URIs.

For example, an example image URI would be s3://client/test-image-uri

Azure Blob Storage

If you use Azure Blob Storage to store data, we can fetch your data using Azure AD Application Access.

Azure AD Application Access

To access Blob Storage data in your Azure subscription, Uber AI Solutions can utilize an Azure Active Directory (AAD) application that you create and configure with the necessary permissions. This approach uses the OAuth 2.0 Client Credentials flow for secure, server-to-server communication without user interaction.

To set up data transfer using Azure AD Application Access, the below steps need to be followed.

Setting Up Data Transfer Using Azure AD Application Access
  1. Register AAD Application: Create a new Azure Active Directory (AAD) application in your Azure subscription. This application will serve as the identity that Uber AI Solutions uses to access your Blob Storage.
    1. Navigate to the Azure portal. Search for “App registrations” and select it.
    2. Click “New registration”.
    3. Provide a meaningful name for the application (e.g., “Uber-AI-Solutions-BlobAccess”).
    4. For “Supported account types”, select “Accounts in this organizational directory only (Default Directory only - Single tenant)”.
    5. Click “Register”.
  2. Generate Client Secret: After the application is created, you must generate a client secret (sometimes referred to as an application password) for it. This secret will be used by Uber AI Solutions to authenticate with Azure AD.
    1. From the newly created application’s overview page, navigate to “Certificates & secrets” under “Manage”.
    2. Click “New client secret”.
    3. Provide a description (e.g., “Uber AI Solutions Access Secret”).
    4. Choose an appropriate expiration date (e.g., 12 months or 24 months, with a plan for rotation).
    5. Click “Add”.
    6. Crucially, copy the Value of the client secret immediately. This value will only be displayed once and cannot be retrieved later. Securely store this secret.
  3. Grant Storage Access: Assign the newly created AAD application the least privilege role required to access your Blob Storage. For read-only access, the Storage Blob Data Reader role is generally sufficient.
    1. Navigate to your Storage Account or a specific container within the storage account.
    2. Go to “Access control (IAM)”.
    3. Click “Add role assignment”.
    4. For “Role”, select Storage Blob Data Reader (or Storage Blob Data Contributor if write access is needed).
    5. For “Members”, select “Azure AD user, group, or service principal”.
    6. Search for your AAD application by the name you gave it (e.g., “Uber-AI-Solutions-BlobAccess”) and select it.
    7. Click “Review + assign”.
  4. Securely Share Information via the Client Portal: You will need to provide Uber AI Solutions with the following information to enable access
    1. Tenant ID (Directory ID): Found on the AAD application’s overview page.
    2. Application (Client) ID: Also found on the AAD application’s overview page.
    3. Client Secret: The value you securely copied in Step 2.
Attachment URIs

To reference data stored in Azure Blob Storage, customers can submit tasks using standard HTTP/HTTPS URLs that point directly to the blob.

You can find the base URL for your container on its properties tab in the Azure portal. To access a specific blob, simply append the blob’s name to this container URL.

For example, a typical blob URI would look like this: https://yourstorageaccount.blob.core.windows.net/yourcontainer/yourblobname.jpg

Uber

Developers
© 2026 Uber Technologies Inc.