A company has a central data repository in Amazon S3 that needs to be accessed by developers belonging to different AWS accounts. The required IAM role has been created with the appropriate S3 permissions. Given that the developers mostly interact with S3 via APIs, which API should the developers call to use the IAM role?