_key
Typical credentials for cloud services.
When the service type is "aws", the key always names a region: the one the resources it covers are in. It is not inferred from the ApertureDB container's own surroundings, which say where the caller is configured rather than where the bucket is, and a request signed for the wrong region is refused rather than redirected. Resources in more than one region need a credential each.
The key also carries an access key id and a secret access key, given as access_key and secret_access_key. Both are required. session_token may be given alongside them, and has to be when the pair is a temporary one issued by STS. A session_token on its own is not a credential and is refused: it only accompanies an access key pair, never replaces one.
The key may not set use_default_credentials. That asks for the identity the ApertureDB server itself runs under, and only the server's own storage credentials may ask for it; a credential registered with CreateCredential or UpdateCredential has to carry an identity of its own, and one that sets it is refused whatever its value.
When the service type is "gcp", the content should be a json key generated for a user or a service account.