Support
Last updated: September 2026
Need help with PicoOSS? Email us and we will get back to you.
Before you send anything
Never include any of the following in an email, screenshot or public issue:
- Your AccessKey ID or AccessKey secret
- An STS Security Token
- A working presigned URL (anyone holding it can read the object)
- Bucket names or object paths you consider private
If you already shared a credential, rotate it in the Alibaba Cloud console and, where relevant, update the permissions of the affected RAM user.
Frequently asked questions
Where are my credentials stored?
Each account's AccessKey ID, AccessKey secret and optional STS token are stored as separate items in the macOS Keychain. Account metadata, such as the alias, bucket, region and endpoint, is kept in the app's preferences. The secret and STS token are not written to the preferences. Secrets are used on your Mac to compute OSS V4 request signatures.
Does PicoOSS send my data anywhere other than OSS?
The app has no analytics, advertising or third-party crash-reporting SDKs and no developer-operated backend or file relay. OSS requests go directly from your Mac to the endpoint you configure. Opening a share link or an external link in your browser is a separate action you initiate. See the privacy policy for the full description.
How do I remove my account data?
Signing out keeps the local account record so you can switch back later. Deleting an account in Settings requests removal of that account's local metadata and Keychain credential. If the store reports a failure, retry rather than treating the error as a completed deletion. Deleting a local account does not delete your Alibaba Cloud account, buckets, objects, object versions, incomplete multipart uploads or already downloaded files.
Why can't I list my buckets or connect?
Check, in order: that the RAM user actually has permission for the operation you are attempting; that the region and endpoint match the bucket; that the bucket is not restricted to a single bucket with a mismatched configuration; and that the network, VPN or proxy in use allows the connection. For a custom endpoint or CNAME, the domain must be one you control and trust — format validation alone does not prove ownership.
What should a bug report include?
Your macOS version, the PicoOSS version from the About panel, what you did, what you expected and what happened instead. Redact credentials, object paths and request IDs before sending. Screenshots are helpful; make sure no secrets are visible in them.
Is PicoOSS affiliated with Alibaba Cloud?
No. PicoOSS is an independent third-party client. It is not affiliated with, endorsed by or sponsored by Alibaba Cloud. Alibaba Cloud and OSS are trademarks of their respective owners. Using the app may incur request, storage or traffic charges on your own cloud account.
Privacy policy
What is stored locally, what is sent to your OSS endpoint and how to withdraw access is described in the privacy policy.