How to use IDrive e2 for server backups
IDrive e2 is S3-compatible object storage in 19 regions across the US, Canada, Europe and Asia. As of October 2026 it costs $0.006 per GB a month, billed on at least 1 TB ($6), and downloads of up to three times what you store each month are free. Each access key belongs to one region and can be limited to chosen buckets and to read and write without delete, so give every server its own key, point your tools at the endpoint your Dashboard shows, and let lifecycle rules and retention prune and protect the backups.
Regions and endpoints
A region must be enabled before you can use it: on the console's Dashboard, pick it from the Region drop-down and click Enable. Enabled regions then lists each one with its endpoint URL. IDrive's developer guide calls that endpoint unique to your account, and its own examples look like y7s7.da.idrivee2-28.com. For third-party tools, IDrive also publishes one service URL per region:
| Location | Region code | Service URL |
|---|---|---|
| Oregon | us-west-1 | s3.us-west-1.idrivee2.com |
| Los Angeles | us-west-2 | s3.us-west-2.idrivee2.com |
| San Jose | us-west-3 | s3.us-west-3.idrivee2.com |
| Oregon-2 | us-west-4 | s3.us-west-4.idrivee2.com |
| Phoenix | us-southwest-1 | s3.us-southwest-1.idrivee2.com |
| Chicago | us-midwest-1 | s3.us-midwest-1.idrivee2.com |
| Dallas | us-central-1 | s3.us-central-1.idrivee2.com |
| Virginia | us-east-1 | s3.us-east-1.idrivee2.com |
| Miami | us-southeast-1 | s3.us-southeast-1.idrivee2.com |
| Montreal | ca-east-1 | s3.ca-east-1.idrivee2.com |
| Ireland | eu-west-1 | s3.eu-west-1.idrivee2.com |
| London | eu-west-2 | s3.eu-west-2.idrivee2.com |
| London-2 | eu-west-3 | s3.eu-west-3.idrivee2.com |
| Paris | eu-west-4 | s3.eu-west-4.idrivee2.com |
| Frankfurt-2 | eu-central-1 | s3.eu-central-1.idrivee2.com |
| Frankfurt | eu-central-2 | s3.eu-central-2.idrivee2.com |
| Milan | eu-south-1 | s3.eu-south-1.idrivee2.com |
| Singapore | ap-southeast-1 | s3.ap-southeast-1.idrivee2.com |
| Tokyo | ap-northeast-1 | s3.ap-northeast-1.idrivee2.com |
Each also has an alias, such as s3.or-1.idrivee2.com for Oregon. Use the endpoint your Dashboard shows for the bucket's region, with https://. Pick a region away from the servers you back up. The examples use Virginia, https://s3.us-east-1.idrivee2.com, and a bucket named acme-web-01-backups.
Create the bucket
- Click Create Bucket on the Dashboard or the Buckets page, and check the region.
- Enter a name of up to 63 characters. Stick to lowercase letters, digits and hyphens; IDrive rejects emoji and other UTF-32 characters.
- Default Encryption: IDrive recommends it. rclone then needs one extra setting, shown below.
- Versioning: on, so an overwritten or deleted backup stays recoverable as an older version.
- Object Locking: on if you may want locked backups. IDrive describes turning it on while creating the bucket.
- Click Create Bucket.
Without versioning, IDrive says a deleted object is gone for good and it can't recover it. A bucket must be empty before it can be deleted.
Give each server its own key
On the Access Keys page, click Create Access Key, then:
- Name it after the server, such as
web-01, and select the bucket's region. - Set the expiry date and time, and write it down: an expired key stops the backups.
- Choose Read and write, and set the deletion preferences so it can delete neither objects nor buckets.
- Under the buckets, select only
acme-web-01-backups. - Click Create Access Key and save the Access Key ID and Secret Access Key.
By default every bucket is selected, including ones you create later. IDrive also warns that a key allowed to delete objects can bypass governance-mode retention. A server's key that can't delete and reaches one bucket can't erase other servers' backups or its own.
- A key's role and buckets can't be edited: delete it and create a new one. IDrive allows up to 250 keys per region.
- Upload only is stricter: it uploads, and with Allow Listing it can also list objects. For restores, create a Read only key.
- Under Enabled regions, a region's IP allowlisting tab can limit access to your servers' addresses.
Configure the AWS CLI
[profile idrive]
region = us-east-1
endpoint_url = https://s3.us-east-1.idrivee2.com
retry_mode = standard
max_attempts = 5[idrive]
aws_access_key_id = <access_key>
aws_secret_access_key = <secret_key>endpoint_urlis the bucket's region endpoint; IDrive sayshttps://is required. IDrive's own CLI examples setregion = us-east-1whatever the endpoint.retry_mode = standardretries throttling errors, timeouts and HTTP 500, 502, 503 and 504 with backoff, andmax_attempts = 5allows five attempts instead of three.
Run chmod 600 on both files. aws s3 ls s3://acme-web-01-backups/ --profile idrive then prints nothing for an empty bucket. Upload a test file with aws s3 cp /etc/hostname s3://acme-web-01-backups/web-01/test.txt --profile idrive; aws s3 rm on it should be refused. General bucket concepts are in the S3 backup bucket guide.
Upload backups on a schedule
Name each backup by date, under the server's prefix, with a checksum beside it. This archives two directories with tar:
#!/bin/sh
set -eu
NAME="web-01-$(date +%F).tar.gz"
cd /var/backups
tar -czf "$NAME" /etc /var/www
sha256sum "$NAME" > "$NAME.sha256"
for f in "$NAME" "$NAME.sha256"; do
aws s3 cp "$f" "s3://acme-web-01-backups/web-01/$f" --profile idrive --only-show-errors
done
rm "$NAME" "$NAME.sha256"set -eu stops at the first error, so a failed upload never reaches the rm. Make it executable with chmod 700 and schedule it; the PATH line lets cron find aws (see scheduling backups with cron):
PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
30 3 * * * root /usr/local/bin/idrive-backup.shrclone has had an IDrive provider since 1.59. Run interactively, rclone config fills in the endpoint itself: it sends the access key ID to IDrive's API and saves the endpoint IDrive returns. Written by hand:
[idrive]
type = s3
provider = IDrive
access_key_id = <access_key>
secret_access_key = <secret_key>
endpoint = s3.us-east-1.idrivee2.com
no_check_bucket = trueno_check_bucket = truestops rclone trying to create the bucket. IDrive says it's required for any key without access to all buckets.- There's no
aclline: IDrive doesn't support ACLs, and with none rclone sends no ACL header. - On a bucket with Default Encryption, IDrive says uploads can fail with MD5 errors; add
server_side_encryption = aws:kms.
Upload with rclone copy, not rclone sync, which deletes remote files that are gone locally and fails with this key.
Expire old backups with lifecycle rules
With the server unable to delete, IDrive prunes. In the console, open the bucket's settings, go to Object Lifecycle and click Add Rule:
- Prefix:
web-01/, so the rule covers only this server's backups. - Delete current versions 30 days after upload.
- Delete older versions 7 days after they become older versions.
- Remove expired delete markers, and click Add Rule.
As on S3, expiring the current version of a versioned object adds a delete marker and keeps the data as an older version, which the older-versions setting removes 7 days later, so each backup lives about 37 days. A rule can also use a fixed date, and IDrive says lifecycle rules can be set through the S3 API too. Check that versioning is on:
aws s3api get-bucket-versioning --bucket acme-web-01-backups --profile idriveIt should print "Status": "Enabled". IDrive doesn't document a rule for unfinished multipart uploads, so list them now and then with aws s3api list-multipart-uploads --bucket acme-web-01-backups --profile idrive.
Lock backups with retention
On a bucket created with Object Locking, IDrive's Retention setting locks every new upload for a set time. Open the bucket's settings, and on Bucket Summary turn on Retention, choose the mode, duration and validity, and click Update Bucket.
- Governance: a locked object can't be changed or deleted, except by a user or key allowed to bypass governance, which IDrive says includes any key that can delete objects.
- Compliance: nobody can change or delete the object until the retention period ends.
- Legal hold: an on/off lock on one object, with no end date, that overrides both modes until removed.
Set governance for 14 days, upload a test file with the server's key, then check both with read-only calls:
aws s3api get-object-lock-configuration --bucket acme-web-01-backups --profile idriveaws s3api get-object-retention --bucket acme-web-01-backups --key web-01/test.txt --profile idriveThe second should show GOVERNANCE and a RetainUntilDate 14 days out. Deleting a locked object only hides it from the default view; the locked version stays, and is billed, until its date. Keep the lock shorter than the lifecycle window, as here: locked 14 days, removed after about 37.
Don't turn on MFA Delete for a bucket a backup tool prunes: IDrive notes that backup applications may then fail to delete objects.
Verify and restore a backup
aws s3 ls s3://acme-web-01-backups/web-01/ --human-readable --summarize --profile idriveTo prove a backup restores, download it with its checksum file and check both:
mkdir -p /tmp/restore-test && cd /tmp/restore-test && aws s3 cp s3://acme-web-01-backups/web-01/ . --recursive --exclude "*" --include "web-01-2026-10-04.tar.gz*" --profile idrivesha256sum -c web-01-2026-10-04.tar.gz.sha256 && tar -tzf web-01-2026-10-04.tar.gz > /dev/null && echo OKsha256sum -c compares the download with the hash taken before upload, and tar -tzf reads the whole archive. Then extract it and check the files, as in testing a restore. For an overwritten or expired backup, aws s3api list-object-versions --bucket acme-web-01-backups --prefix web-01/ lists its versions, and aws s3api get-object with --version-id fetches one; the console's Versions tab can restore one too.
What it costs
As of October 2026, from IDrive's pricing page:
| Item | Price |
|---|---|
| Pay as you go | $0.006 per GB a month ($6 per TB), billed on at least 1 TB: $6 a month even for 100 GB |
| Yearly plan, 1 TB | $59.50 a year; $29.75 for the first year while IDrive's 50% offer lasts |
| Yearly plan, 5 TB | $297.50 a year; $148.75 for the first year |
| Storage over a yearly plan | $0.006 per GB a month |
| Downloads | Free up to 3 times your stored volume a month, then $0.01 per GB |
| Uploads, API requests, deletions | Free; no minimum storage duration |
Pay-as-you-go accounts are billed every 30 days, with an interim charge if usage jumps mid-cycle. A free trial covers 10 GB. IDrive bills total storage used, so older versions you keep add to it.
| Usage | Working | Cost |
|---|---|---|
| 30 nightly 20 GB archives, about 600 GB | Under the 1 TB minimum | $6.00 a month, or $59.50 a year |
| 2.5 TB stored, pay as you go | 2,500 GB × $0.006 | $15.00 a month |
| Restoring all 2.5 TB to a new server | Under 3 × 2.5 TB of free downloads | $0 extra |
Limits and common errors
- Objects up to 50 TB, in up to 10,000 parts of 5 MB to 5 GB. No limit on buckets or objects per bucket; listings return up to 1,000 objects per request.
- Up to 1,000 concurrent HTTP connections from S3 tools, and 250 access keys per region.
- Not supported: bucket and object ACLs, bucket analytics and metrics, and requester pays.
- IDrive blocks access from Russia, China and Ukraine; paid users there can ask support to allow IP addresses. A trial account's region with no data for 30 days is removed.
InvalidAccessKeyIdwithThe Access Key Id you provided does not exist in our records.: the key is mistyped, or the endpoint isn't the one your Dashboard lists for the key's region.- rclone logs
Resolving service "s3" region "us-east-1"with-vv, then hangs: the endpoint hostname is wrong or mistyped. - rclone fails with
AccessDenied: Access Denied.(status 403) before anything uploads: the key doesn't reach all buckets, so addno_check_bucket = true. - MD5 errors from rclone on an encrypted bucket: add
server_side_encryption = aws:kms. - Checksum errors from a recent AWS CLI: newer versions add checksums by default, which not every S3-compatible service accepts. Add
request_checksum_calculation = when_requiredandresponse_checksum_validation = when_requiredto the profile.
Where IDrive e2 fits
A bucket at IDrive is off-site for a server at any other provider, which is the point of the 3-2-1 rule. For a second region, Object Replication copies a bucket to one in another region; both need the same versioning state, and leaving Sync deleted objects off keeps a deletion in one from following to the other. Both copies still share one account and one bill, so the backup key's limits and the retention lock matter more than the region count; see protecting backups from ransomware.
IDrive encrypts transfers with TLS and encourages you to encrypt files before upload; encrypt backups if only you should be able to read them. For the same job on other providers, compare Wasabi and Backblaze B2.
Frequently asked questions
- What is the S3 endpoint for IDrive e2?
- The one listed for your region under Enabled regions on the Dashboard. IDrive also publishes a service URL per region in the form
s3.<region>.idrivee2.com, such ashttps://s3.us-east-1.idrivee2.comfor Virginia. - Can I limit an IDrive e2 access key to one bucket?
- Yes. When you create the key, choose its buckets and its permission: Read and write (with or without delete), Read only or Upload only. A key's role and buckets can't be edited later; create a new key instead.
- Does IDrive e2 charge for egress?
- Not up to three times your stored volume each month, as of October 2026. Beyond that, downloads cost $0.01 per GB.
- Does IDrive e2 support Object Lock?
- Yes, with governance and compliance retention and legal hold, on buckets created with Object Locking. A key allowed to delete objects can bypass governance mode.
- Why does rclone say Access Denied when uploading to IDrive e2?
- A key limited to some buckets can't create buckets, and rclone checks first. Add
no_check_bucket = trueto the remote, or pass--s3-no-check-bucket.
How this was checked
Commands, limits and prices were checked against these official pages, on October 4, 2026:
- IDrive e2: Endpoint URLs (regions, region codes, service URLs)
- IDrive e2: A guide for developers (regions, per-account endpoint, keys can't be edited)
- IDrive e2 FAQ: General (unsupported S3 APIs)
- IDrive e2 FAQ: Buckets (creating buckets, lifecycle rules, IP allowlisting)
- IDrive e2 FAQ: Objects (deletion, versioning, Object Lock, retention, legal hold)
- IDrive e2 FAQ: Access keys (permissions, buckets, Allow Listing, 250 keys per region)
- IDrive e2 FAQ: Account management (API limits, inactive trial regions)
- IDrive e2 FAQ: Security (MFA delete, blocked countries, encryption)
- IDrive e2 FAQ: Object replication
- IDrive e2: Pricing page
- IDrive e2 FAQ: Pricing (minimum fee, overuse, free egress policy)
- IDrive e2 FAQ: Billing (30-day cycle, interim charges)
- IDrive e2 developer guide: Operations (AWS CLI configuration)
- IDrive e2 developer guide: Bucket versioning
- IDrive e2 developer guide: Get region endpoint
- IDrive e2: Rclone guide (no_check_bucket, server_side_encryption)
- rclone docs: Amazon S3 (IDrive e2 provider, acl, no_check_bucket)
- rclone v1.75.1 source: IDrive e2 endpoint lookup in rclone config
- rclone forum: IDrive upload fails with a key limited to some buckets (log with the error)
- rclone forum: IDrive e2 can't access new bucket/region (logs for a wrong endpoint)
- AWS CLI User Guide: Configuration and credential file settings
- AWS CLI User Guide: Retries
- AWS SDKs and Tools Reference Guide: Data integrity protections for Amazon S3
- AWS CLI reference: s3api get-bucket-versioning
- AWS CLI reference: s3api get-object-lock-configuration
- AWS CLI reference: s3api get-object-retention
- AWS CLI reference: s3api list-multipart-uploads
- AWS CLI reference: s3api list-object-versions
- AWS CLI reference: s3 cp
- AWS CLI reference: s3 ls