How to use Backblaze B2 for server backups
Backblaze B2 works as an S3-compatible backup target. Create a private bucket, create an application key restricted to that bucket and a file name prefix, and point the AWS CLI at the bucket's S3 endpoint, such as https://s3.us-west-004.backblazeb2.com. B2 keeps every version of every file by default, so set a lifecycle rule or old backups pile up on your bill. As of October 2026, storage costs $6.95 per TB per month, and egress is free up to three times the data you store.
Pick the region before you sign up
A B2 account lives in one region, chosen when the account is created: US West, US East, EU Central or CA East. All of that account's data stays there, and the region can't be changed later. Storage costs the same in every region. To keep data in a second region, you need a second account.
Create a private bucket
- Sign in to the Backblaze web console. Under B2 Cloud Storage in the left menu, click Buckets, then Create a Bucket.
- Enter a name. Bucket names are unique across all B2 accounts and can't be renamed. For the S3 API, Backblaze recommends 6 to 63 characters of lowercase letters, numbers and hyphens, starting and ending with a letter or number.
- Select Private, so every download needs authorization.
- Turn on default encryption (SSE-B2), now or later in the bucket's settings. Only files uploaded after it is on are encrypted.
- Leave Object Lock off unless you have read the Object Lock section below. It can't be disabled once enabled.
- Click Create a Bucket, then copy the value in the Endpoint field, such as
s3.us-west-004.backblazeb2.com.
An account can hold 100 buckets; Backblaze support can raise that.
Create an application key for one bucket
- Under B2 Cloud Storage, click Application Keys, then Add a New Application Key, and enter a name.
- In Allow Access to Bucket(s), select the backup bucket.
- Select Allow List All Bucket Names. Backblaze says bucket-restricted keys need it for compatibility with S3 SDKs and integrations. It exposes bucket names and creation dates, not contents.
- For the access type, choose Read and Write.
- In the file name prefix field, enter
web-01/. The key can then only touch files whose names start with it. - Optionally, set a lifetime in seconds, under 1,000 days. An expired key stops working, so note when to replace it.
- Click Create New Key and copy the keyID and applicationKey. The applicationKey is shown once.
Never put the master application key on a server. It has full access to the account, and the S3-compatible API doesn't accept it anyway.
With a prefix-restricted key, list requests must use a prefix at least as narrow as the key's: s3://acme-server-backups/web-01/ works, the bucket root is denied. A Write Only key can upload but can't read back what it wrote, so checks have to run from another machine with a read key.
S3-compatible API or B2 Native API?
| S3-compatible API | B2 Native API | |
|---|---|---|
| Calls | Standard S3 operations at https://s3.<region>.backblazeb2.com | Backblaze's own b2_* operations |
| Tools | AWS CLI, rclone's S3 backend, most S3 tools | Backblaze's b2 CLI and SDKs |
| Sign-in | keyID as access key ID, applicationKey as secret; version 4 signatures over HTTPS only | b2_authorize_account turns a key into a token that expires after 24 hours |
| Master application key | Not accepted | Accepted |
For backups from a Linux server, the S3 endpoint lets you reuse the same commands as on AWS. The S3-compatible API doesn't support IAM roles, object tagging, website configuration, browser POST uploads, or ACLs beyond a bucket-level private or public-read setting.
Configure the AWS CLI
aws configure --profile b2Enter the keyID as the access key ID and the applicationKey as the secret. Backblaze says to leave the region and output format blank. To skip --endpoint-url on every command, add the endpoint to the profile:
[profile b2]
services = b2-s3
[services b2-s3]
s3 =
endpoint_url = https://s3.us-west-004.backblazeb2.comReplace us-west-004 with the region in your bucket's endpoint. The examples below pass --endpoint-url anyway, which overrides the file.
aws s3 ls s3://acme-server-backups/web-01/ --profile b2 --endpoint-url https://s3.us-west-004.backblazeb2.comUpload backups
aws s3 cp /var/backups/web-01-2026-10-03.tar.gz s3://acme-server-backups/web-01/2026-10-03.tar.gz --profile b2 --endpoint-url https://s3.us-west-004.backblazeb2.com --only-show-errorsaws s3 sync /var/backups/web-01/ s3://acme-server-backups/web-01/ --profile b2 --endpoint-url https://s3.us-west-004.backblazeb2.com --only-show-errors- Use unique, dated names. Backblaze warns that several uploads of the same name within one second may be processed out of order.
- A single upload is limited to 5 GB. Larger files go up in parts of 5 MB to 5 GB, up to 10 TB per file; the AWS CLI handles the parts.
- An S3 delete without a version ID only inserts a delete marker, B2's hide marker.
sync --deletehides files rather than removing them, and hidden files are still billed until a lifecycle rule deletes them.
Lifecycle rules: hide, then delete
Uploading a name that already exists adds a new version and hides the old one. Every version is billed. Lifecycle rules run once a day and do two things: hide files a set number of days after upload, and delete hidden files a set number of days after they were hidden.
A bucket's Lifecycle Settings offer four choices:
- Keep all versions of the file, the default: nothing is ever removed automatically.
- Keep only the last version of the file: an older version is hidden for one day, then deleted.
- Keep prior versions for this number of days: older versions are deleted after the days you set. The current version stays.
- Use custom lifecycle rules: your own prefix and day counts.
The built-in choices only remove old versions of a name. Dated backup files each have a single version, so only a custom rule expires them. These are the values, in the format of Backblaze's API:
[
{
"fileNamePrefix": "web-01/",
"daysFromUploadingToHiding": 30,
"daysFromHidingToDeleting": 1,
"daysFromStartingToCancelingUnfinishedLargeFiles": 7
}
]fileNamePrefix: the files the rule covers. An empty prefix covers the whole bucket and can delete everything in it.daysFromUploadingToHiding: 30hides every version under the prefix 30 days after its upload, current version included.daysFromHidingToDeleting: 1deletes hidden versions a day later, so a backup is gone about 31 days after upload.daysFromStartingToCancelingUnfinishedLargeFiles: 7cancels uploads that never finished.- Values must be 1 or more, or null to skip that action. Where rules overlap, the smallest value wins. A bucket can have 100 rules.
In the console, choose Use custom lifecycle rules in Lifecycle Settings and enter the same values. A rule applies at the first daily run after its days have fully passed, so expect up to a day of lag.
Object Lock
Object Lock blocks changes and deletion until a date. You can enable it when you create a bucket or later, but never disable it. Lock periods run from 1 to 3,000 days.
- Governance mode: a key with the
bypassGovernancecapability can delete locked files or shorten the lock. - Compliance mode: nobody can remove the lock; it can only be extended. Backblaze's answer to a lock set too long is closing the account.
- Legal hold: no end date, removed by hand.
- Default bucket retention locks every file uploaded from then on; existing files aren't affected.
Object Lock has no extra charge beyond storage. Lifecycle rules can't delete a locked version, so keep the lock shorter than the lifecycle window. To check a file's lock, with a key allowed to read retention settings:
aws s3api get-object-retention --bucket acme-server-backups --key web-01/2026-10-03.tar.gz --profile b2 --endpoint-url https://s3.us-west-004.backblazeb2.comVerify a backup
aws s3 ls s3://acme-server-backups/web-01/ --recursive --human-readable --summarize --profile b2 --endpoint-url https://s3.us-west-004.backblazeb2.comaws s3 cp s3://acme-server-backups/web-01/2026-10-03.tar.gz /tmp/restore-test.tar.gz --profile b2 --endpoint-url https://s3.us-west-004.backblazeb2.com && sha256sum /tmp/restore-test.tar.gz && tar -tzf /tmp/restore-test.tar.gz > /dev/null && echo OKRecord a SHA-256 before each upload and compare. B2 stores no whole-file checksum for large files unless the uploader adds one, so your own hash is the reliable check. To see hidden versions and delete markers, run aws s3api list-object-versions with --prefix web-01/. A monthly restore test usually fits inside the free egress. See testing a restore.
What it costs
As of October 2026, Backblaze lists for pay-as-you-go B2:
- Storage: $6.95 per TB per month, billed by byte-hour. The first 10 GB is free.
- No minimum file size and no minimum storage duration fees.
- Egress: free up to 3 times your average monthly storage, then $0.01 per GB. Downloads through partner CDN and compute providers, including Cloudflare, Fastly and Vultr, are free.
- API calls in Classes A, B and C are free, which covers uploads, downloads, lists and deletes. Class D, outbound event notifications, is $0.004 per 10,000 after 2,500 free a day.
- Hidden versions and duplicates are billed like any other file.
Example: 500 GB of backups is billed as 490 GB after the free 10 GB, about $3.41 a month, and you could download up to about 1.5 TB that month without egress charges.
Limits and gotchas
- One region per account, fixed at sign-up.
- 100 buckets per account by default; names are global and permanent.
- Versions accumulate by default. Backblaze warns that millions of versions of one object slow listing and deletion and can eventually block uploads.
- Server-side encryption covers file data, not names or metadata, so keep secrets out of file names.
- The S3 endpoint rejects plain HTTP and version 2 signatures.
- Keep a second copy elsewhere too; one provider is one point of failure. See the 3-2-1 rule.
A key that can upload can usually delete too. For backups an attacker cannot remove, see protecting backups from ransomware; to keep what is stored readable only by you, encrypt it before upload.
Frequently asked questions
- Does Backblaze B2 work with the AWS CLI?
- Yes. Configure a profile with an application key's keyID and applicationKey, and pass your bucket's S3 endpoint with
--endpoint-url, or set it in~/.aws/config. - Why doesn't my B2 master application key work with S3 tools?
- The S3-compatible API doesn't accept the master key. Create a standard application key, ideally restricted to one bucket.
- How do I stop B2 from keeping old file versions?
- In the bucket's Lifecycle Settings, choose Keep only the last version of the file, which hides older versions for a day and then deletes them, or set custom rules.
- Is Backblaze B2 egress free?
- Up to 3 times your average monthly storage, as of October 2026. Beyond that it is $0.01 per GB, except through Backblaze's CDN and compute partners.
- Can I enable Object Lock on an existing B2 bucket?
- Yes, but once enabled it can't be turned off. Default retention only applies to files uploaded after you set it.
How this was checked
Commands, limits and prices were checked against these official pages, on October 3, 2026:
- Backblaze docs: How to Create and Manage Buckets
- Backblaze docs: Buckets (naming rules and limits)
- Backblaze docs: Where are the Backblaze Cloud Storage Data Centers
- Backblaze docs: How to Create and Manage App Keys
- Backblaze docs: Application Keys
- Backblaze docs: How to Use Backblaze B2 S3-Compatible App Keys
- Backblaze docs: S3-Compatible API
- Backblaze docs: How to Call the Backblaze B2 S3-Compatible API
- Backblaze docs: How to Use the AWS CLI with Backblaze B2
- Backblaze docs: Automate File Deletion with Lifecycle Rules
- Backblaze docs: File Versions
- Backblaze docs: Object Lock
- Backblaze docs: Server-Side Encryption
- Backblaze docs: Large Files
- Backblaze API docs: S3 Delete Object
- Backblaze B2 Cloud Storage pricing
- Backblaze B2 transaction pricing
- AWS CLI User Guide: Using endpoints in the AWS CLI