VPS Snaps

How to use a Hetzner Storage Box for server backups

A Hetzner Storage Box is a file server you rent by size, from 1 TB for €3.20 a month as of October 2026 (excluding VAT), with unlimited traffic. It speaks SFTP, SCP, rsync, BorgBackup, FTP, SMB and WebDAV, but not S3. For server backups, give each server its own sub-account and SSH key on port 23, back up with Borg or restic, and turn on automatic snapshots so files a server deletes stay recoverable.

11 min readUpdated Checked against official documentation

What a Storage Box is, and what it speaks

A Storage Box is space on one Hetzner host server, in Falkenstein (FSN1) or Helsinki (HEL1). The disks sit in a RAID array with checksums that catch bit errors, and Hetzner says the data is not mirrored onto other servers. There is no web interface for files: you manage the box in Hetzner Console or the Hetzner API, and reach the data at u123456.your-storagebox.de (your username replaces u123456) over these protocols:

ProtocolPortFor backups
SSH: rsync, BorgBackup, restic and rclone over SFTP, SCP23, once SSH support is onUse this one. Keys in OpenSSH format; single commands, no full shell
SFTP and SCP22, always onWorks, but keys must be in RFC4716 format
FTP and FTPS21, always onPlain FTP is unencrypted; avoid it
SMB/CIFS445, when turned onMounting as a drive; add seal to encrypt
HTTPS/WebDAV443, when turned onMounting with davfs2

A Storage Box has no S3 endpoint. As of October 2026, Hetzner's Storage Box documentation lists only the protocols above, so a tool that can only write to an S3 bucket can't use one. Hetzner's S3-compatible service is a separate product, Hetzner Object Storage.

Plans and prices

As of October 2026, excluding VAT, billed by the hour up to a monthly cap, with no minimum contract:

PlanStoragePer month (cap)Snapshots
BX111 TB€3.20 ($4.00)10
BX215 TB€10.90 ($13.00)20
BX3110 TB€20.80 ($24.00)30
BX4120 TB€40.60 ($46.00)40

Every plan has unlimited traffic, up to 100 sub-accounts and 10 simultaneous connections, and shares its host's 1 to 10 Gbit/s with other customers. The snapshot count applies to manual snapshots and, separately, to automatic snapshot slots. You can rescale at any time; a downgrade works only if your data fits the smaller plan.

Hetzner Object Storage costs €6.49 a month with 1 TB of storage and 1 TB of egress included, then €0.0087 per TB-hour. For data stored all month (744 hours):

StoredStorage BoxObject Storage
1 TBBX11: €3.20€6.49
5 TBBX21: €10.90€6.49 + (3,720 − 744 TB-hours) × €0.0087 = €32.38

For Borg, restic and rsync, the Storage Box is the cheaper target. Object Storage is the one for tools that need S3, and it adds lifecycle rules and Object Lock.

Create the Storage Box

  1. In Hetzner Console, open a project, click Storage Boxes, then Create Storage Box.
  2. Location: Falkenstein or Helsinki, whichever your servers are not in. Type: the plan.
  3. Access: select an SSH key and set a password. Hetzner Console adds a key only at creation; later you add keys on the box itself. Password login can't be turned off, so use a long random password: 12 to 128 characters with upper and lower case, a digit and a special character.
  4. Additional settings: turn on SSH Support (port 23), and External Reachability if any server outside Hetzner's network will connect. Leave SMB and WebDAV off.
  5. Enter a Name and click Create & Buy now. The box is available at once.

Give each server its own sub-account

The main account can read and delete everything on the box. A sub-account sees only its own home directory, so a server that is broken into reaches its own backups and nobody else's. In Hetzner Console, add a sub-account for each server:

  • Home directory: such as web-01. It is created if missing, and can be nested, like servers/web-01.
  • SSH on, and external reachability on if the server is outside Hetzner. Samba and WebDAV off.
  • Read-only off. A read-only sub-account can download but not upload or delete, which suits a restore-only login.

The sub-account gets a username like u123456-sub1 and its own host, u123456-sub1.your-storagebox.de. It uses the box's space and keeps its own .ssh/authorized_keys in its directory.

Add the server's SSH key

On the server, make a key used only for the Storage Box (more in SSH key authentication):

Terminal
ssh-keygen -t ed25519 -f /root/.ssh/storagebox_ed25519 -N '' -C 'web-01-storagebox'

Check the box's host key before trusting it. Hetzner publishes one ED25519 fingerprint for all Storage Box hosts, SHA256:XqONwb1S0zuj5A1CDxpOSuD2hnAArV1A3wKY7Z3sdgM; this prints the one you are about to accept:

Terminal
ssh-keyscan -p 23 -t ed25519 u123456-sub1.your-storagebox.de 2>/dev/null | ssh-keygen -lf -

Then install the public key with Hetzner's install-ssh-key command. It asks for the sub-account's password once and adds the key in both formats, OpenSSH for port 23 and RFC4716 for port 22, without removing existing keys:

Terminal
cat /root/.ssh/storagebox_ed25519.pub | ssh -p23 [email protected] install-ssh-key

Hetzner's other methods, ssh-copy-id -s and uploading with scp, overwrite the whole authorized_keys file, deleting the keys already in it, and set up only one port.

Give the connection a short name, so Borg, restic and rsync all pick up the user, port and key:

/root/.ssh/config
Host storagebox
    HostName u123456-sub1.your-storagebox.de
    User u123456-sub1
    Port 23
    IdentityFile /root/.ssh/storagebox_ed25519
    IdentitiesOnly yes
    ServerAliveInterval 60
    ServerAliveCountMax 240

IdentitiesOnly yes offers only this key. The two ServerAlive lines keep a long run connected while the client is busy and sends nothing, as the restic docs advise for SFTP. Port 23 runs single commands without pipes or redirects; df -h shows the space left:

Terminal
ssh storagebox df -h

Back up with BorgBackup

Borg runs borg serve on the box, so only new chunks travel, already encrypted. Hetzner keeps borg-1.1, borg-1.2 (the default) and borg-1.4 there, picked with --remote-path. Match your client's borg --version: this example assumes Borg 1.4, and Ubuntu 24.04's package, 1.2.8, needs borg-1.2. Put the settings in one root-only file:

/root/.borg-env
export BORG_REPO='ssh://storagebox/./borg'
export BORG_REMOTE_PATH='borg-1.4'
export BORG_PASSCOMMAND='cat /root/.borg-passphrase'
  • ssh://storagebox/./borg is a repository named borg in the sub-account's home; /./ makes the path relative, as in Hetzner's examples. The storagebox alias supplies user, port and key.
  • BORG_REMOTE_PATH does what --remote-path does, for every command.
  • BORG_PASSCOMMAND reads the passphrase from a file: head -c 32 /dev/urandom | base64 > /root/.borg-passphrase, then chmod 600.

As root, load the file and create the encrypted repository, then back up and prune:

Terminal
. /root/.borg-env && borg init --encryption=repokey
Terminal
borg create --stats --compression zstd,3 --one-file-system --exclude-caches ::'{hostname}-{now:%Y-%m-%d_%H%M}' /etc /var/www /root
Terminal
borg prune --list --glob-archives '{hostname}-*' --keep-daily 7 --keep-weekly 4 --keep-monthly 6 && borg compact

With repokey, the key lives in the repository on the box. Export it and keep it with the passphrase somewhere that is neither the server nor the box. The Borg guide covers the key export, a cron script, excludes and database dumps.

Or use restic over SFTP

restic reaches the box with its SFTP backend, which runs your ssh with the alias above. A scheduled run can't answer a password prompt, so it needs the key:

/root/.restic-env
export RESTIC_REPOSITORY='sftp:storagebox:restic'
export RESTIC_PASSWORD_FILE='/root/.restic-password'

A path without a leading slash, here restic, is relative to the sub-account's home; SFTP servers don't expand ~. Then:

Terminal
. /root/.restic-env && restic init
Terminal
restic backup --one-file-system /etc /var/www /root
Terminal
restic forget --prune --keep-daily 7 --keep-weekly 4 --keep-monthly 6

rsync, tar and rclone

rsync mirrors a directory; it doesn't keep history. With --delete, a file deleted on the server goes from the box at the next run. Paired with the box's snapshots below, that is enough for a web root:

Terminal
rsync -a --delete /var/www/ storagebox:www/

Hetzner doesn't let you set the owner or group of uploaded files, so ownership isn't kept, and it recommends a tool like Borg over rsync for a whole server. To send one archive without writing it to local disk first, pipe tar into dd on the box, as Hetzner shows:

Terminal
tar -cz /etc /var/www | ssh storagebox "dd of=web-01-$(date +%F).tar.gz bs=4M"

rclone uses its own SSH client, so give its SFTP backend the details directly:

/root/.config/rclone/rclone.conf
[storagebox]
type = sftp
host = u123456-sub1.your-storagebox.de
user = u123456-sub1
port = 23
key_file = /root/.ssh/storagebox_ed25519
known_hosts_file = /root/.ssh/known_hosts
  • known_hosts_file makes rclone check the host key that ssh saved; without it, rclone warns No host key validation is being performed on every run.
  • Paths take no leading slash: storagebox:dumps is dumps in the sub-account's home.
  • Checksums work, because port 23 offers md5sum and sha1sum.
Terminal
rclone copy /var/backups/dumps storagebox:dumps --checkers 4

--checkers 4, down from 8, keeps rclone under the 10-connection limit.

Turn on automatic snapshots

A snapshot records the whole box, then keeps copies of files as they change or are deleted. Snapshots are free, but those copies use the box's space. In Hetzner Console, open the box, go to Snapshots and choose Enable automatic snapshots: set when they run and how many slots to keep. When the slots are full, the oldest is deleted; manual snapshots stay until you delete them.

This protects backups from a server that is broken into. Its sub-account can delete its own files, but Hetzner documents the snapshot directory as read-only, and snapshots are made and deleted only in Hetzner Console or the API, out of the SSH key's reach. Through the API, with a token from Security, then API Tokens:

Terminal
curl -X POST -H "Authorization: Bearer $HETZNER_API_TOKEN" -H "Content-Type: application/json" -d '{"max_snapshots":10,"minute":30,"hour":5}' https://api.hetzner.com/v1/storage_boxes/<id>/actions/enable_snapshot_plan

That takes a snapshot every day at 05:30 UTC, after the night's backups, and keeps 10, the most a BX11 allows. Add day_of_week (1 for Monday to 7 for Sunday) or day_of_month for a weekly or monthly plan. A box has one plan; a new one replaces it.

Snapshots appear under /home/.zfs/snapshot/<name>/ for the main account on port 23, sub-account directories included; if you can't see them, turn on Display snapshot directory under Snapshots. To bring back a whole Borg or restic repository, copy it down to a server with the main account:

Terminal
rsync -a -e 'ssh -p23' [email protected]:/home/.zfs/snapshot/<name>/web-01/ /srv/web-01-recovered/

Restoring a snapshot in Hetzner Console rolls back the whole box, every sub-account included: changed files are replaced, newer files are deleted, and so are newer snapshots. Copy what you need out of the snapshot directory instead.

Hetzner says snapshots are not full backups: they live on the same box and can only restore that box.

Verify and restore

With Borg, borg list shows the archives, borg check checks the repository, and borg extract writes an archive into the current directory, so use an empty one:

Terminal
mkdir -p /srv/restore && cd /srv/restore && borg extract ::web-01-2026-10-04_0230 var/www

With restic, restic check --read-data-subset=5% downloads and verifies a random 5% of the data, and restic restore latest --target /srv/restore brings back the newest snapshot. Then prove the files work, as in testing a restore.

Where the box should be

Put the box in the other location from your servers: Helsinki for servers in Falkenstein or Nuremberg, Falkenstein for Helsinki. Servers at other providers can use it with External Reachability on, and restores cost no traffic fees.

Unlike Hetzner's server snapshots, files on the box restore anywhere, but server and box share one login and one bill, and the box is one RAID array on one host. Keep a further copy with another provider, per the 3-2-1 rule. Borg and restic encrypt before upload; for rsync and tar, encrypt backups yourself.

Common errors

  • Port 23 refuses the connection or times out: turn on SSH support for the box or sub-account, and External Reachability if the server is outside Hetzner. Hetzner says a change can take a few minutes.
  • 11: Application Error on SFTP or SCP: SSH agent forwarding is on. Hetzner says to turn it off.
  • A password prompt despite the key: the key is in the wrong format for the port, an scp or ssh-copy-id upload overwrote authorized_keys, or the home directory is writable by group or others, which Hetzner says breaks key login.
  • Connection closed by remote host. Is borg working on the server?: SSH or the Borg on the box failed to start. The Remote: lines above it carry the cause; check that SSH support is on and that BORG_REMOTE_PATH is borg-1.1, borg-1.2 or borg-1.4.
  • Repository <path> does not exist. from Borg, or Fatal: repository does not exist: unable to open config file and Is there a repository at the following location? from restic: the repository isn't initialized, or the path is wrong. Use a relative path, without a leading slash.
  • md5 checksum errors from rclone on a large copy: Hetzner says that usually means the 10-connection limit; lower --checkers.

Frequently asked questions

Does a Hetzner Storage Box support S3?
No. As of October 2026 a Storage Box speaks FTP, FTPS, SFTP, SCP, SMB, WebDAV and SSH on port 23, not S3. Hetzner's S3-compatible storage is Hetzner Object Storage, a separate product.
What port does a Hetzner Storage Box use for SSH?
Port 23 for rsync, BorgBackup, restic, rclone and single commands, once SSH support is on. Port 22 is always open for SFTP and SCP only, with keys in RFC4716 format.
How do I add an SSH key to a Hetzner Storage Box?
Pipe the public key into ssh -p23 [email protected] install-ssh-key. It asks for the password once and installs the key for both ports without removing other keys.
Are Storage Box snapshots a backup?
Not on their own. They can't be deleted over SSH, so they guard against a server deleting its backups, but they live on the same host as the data.

How this was checked

Commands, limits and prices were checked against these official pages, on October 4, 2026: