How to use Wasabi for server backups: private bucket, scoped key and the 90-day rule
Wasabi is S3-compatible object storage with one price for storage and no fees for egress or API requests. For server backups, create a private bucket, give the server a key whose policy covers only that bucket, and point the AWS CLI at your region's endpoint with --endpoint-url. Plan retention around the minimum storage duration: as of October 2026, on Pay as You Go pricing, an object deleted before 90 days is still billed for 90.
Create a private bucket
The region decides the endpoint every tool will use. Wasabi charges the same rate in every region, so pick the one closest to the server.
- Sign in to the Wasabi Console, click Buckets, then Create Bucket.
- Enter a name of 3 to 63 lowercase letters, numbers, periods or dashes. It must begin with a letter or number, can't contain underscores, end with a dash or have two periods in a row, and can't look like an IP address.
- Select the region where the bucket will live.
- On Set Properties, turn on Bucket Versioning, then Object Lock, if you want backups that can't be deleted early. Object Lock can only be turned on now, at creation, and once on it can't be turned off.
- Skip Replication and Logging & More, check the Review step, and click Create Bucket.
New buckets are private: in the bucket list, a public access status of Default means private. Leave it that way.
Your region's S3 endpoint
Every Wasabi region has its own S3 endpoint, and Wasabi says to use the one that matches the bucket's location.
| Region code | Location | Endpoint |
|---|---|---|
| us-east-1 | N. Virginia | s3.us-east-1.wasabisys.com or s3.wasabisys.com |
| us-east-2 | N. Virginia | s3.us-east-2.wasabisys.com |
| us-central-1 | Texas | s3.us-central-1.wasabisys.com |
| us-west-1 | Oregon | s3.us-west-1.wasabisys.com |
| us-west-2 | San Jose | s3.us-west-2.wasabisys.com |
| ca-central-1 | Toronto | s3.ca-central-1.wasabisys.com |
| eu-central-1 | Amsterdam | s3.eu-central-1.wasabisys.com |
| eu-central-2 | Frankfurt | s3.eu-central-2.wasabisys.com |
| eu-west-1 | United Kingdom | s3.eu-west-1.wasabisys.com |
| eu-west-2 | Paris | s3.eu-west-2.wasabisys.com |
| eu-west-3 | United Kingdom | s3.eu-west-3.wasabisys.com |
| eu-south-1 | Milan | s3.eu-south-1.wasabisys.com |
| ap-northeast-1 | Tokyo | s3.ap-northeast-1.wasabisys.com |
| ap-northeast-2 | Osaka | s3.ap-northeast-2.wasabisys.com |
| ap-southeast-1 | Singapore | s3.ap-southeast-1.wasabisys.com |
| ap-southeast-2 | Sydney | s3.ap-southeast-2.wasabisys.com |
Create a key limited to one bucket
Never put the root account's keys on a server. Create a policy that covers one bucket, then a user that has only that policy. Wasabi's own example grants s3:* on the bucket plus s3:ListAllMyBuckets, so the user can browse in the console. A server needs less:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "s3:ListBucket",
"Resource": "arn:aws:s3:::web-01-backups"
},
{
"Effect": "Allow",
"Action": ["s3:PutObject", "s3:GetObject"],
"Resource": "arn:aws:s3:::web-01-backups/*"
}
]
}s3:ListBucketon the bucket lets the key list its objects.s3:PutObjectands3:GetObjectonweb-01-backups/*allow uploads and downloads in that bucket only.- There is no delete permission, so a compromised server can't erase its own history. A lifecycle rule, which Wasabi runs itself, removes old backups.
- In the Wasabi Console, click Policies, then Create Policy. Enter a name, paste the JSON, and click Create Policy once the editor reports the policy is valid.
- Click Users, then Create User. Enter a name, tick Programmatic access, and click Next.
- Skip the group step. On the policies step, select the policy you just created, click Next, review, and click Create User.
- Copy the access key and secret key when Wasabi shows them, and store them in a password manager.
Wasabi allows two access keys per user. One user per server lets you revoke a server without touching the rest.
Upload with the AWS CLI
Save the Wasabi key in its own profile so it never mixes with AWS credentials:
aws configure --profile wasabiEnter the access key and secret key. For Default region name, enter the bucket's region code, such as us-east-2. Leave the output format blank. Then upload:
aws s3 cp /var/backups/web-01-2026-10-03.tar.gz s3://web-01-backups/web-01/ --endpoint-url https://s3.us-east-2.wasabisys.com --profile wasabi --checksum-algorithm CRC32s3://web-01-backups/web-01/is the bucket and a key prefix. The trailing slash keeps the file's name.--endpoint-urlsends the request to Wasabi instead of AWS. It must be the endpoint of the bucket's region.--profile wasabiuses the keys you just saved.--checksum-algorithm CRC32avoids a known failure: Wasabi's docs say AWS CLI v2 now defaults to the CRC64NVME checksum, which Wasabi doesn't accept yet.
To stop typing the endpoint, set endpoint_url in the profile. A --endpoint-url on the command line still overrides it.
[profile wasabi]
region = us-east-2
endpoint_url = https://s3.us-east-2.wasabisys.comLock backups with Object Lock
Object Lock makes each object version unchangeable until a retention date. It needs versioning and is enabled only at bucket creation. It has two modes:
- Governance mode: nobody can change or delete the object before the date, except the root user or a user with the
s3:BypassGovernanceRetentionpermission. - Compliance mode: no user can change or delete the object before the date, whatever their permissions, and this can't be reversed.
Set a default so every new upload is locked:
- On the Buckets list, open the bucket's menu and click Settings.
- Open the Object Lock tab and turn on Default Object Retention.
- Choose Governance Mode or Compliance Mode, set Retention Time in days or years, and click Apply.
- Type
CONFIRMand click Confirm.
The default applies to objects uploaded after you set it, not to existing ones. The server's key can't read bucket settings, so check from a workstation with an admin profile:
aws s3api get-object-lock-configuration --bucket web-01-backups --endpoint-url https://s3.us-east-2.wasabisys.com --profile wasabi-adminTest with Governance mode and a short retention first. In Compliance mode a mistake, such as a one-year default, can't be undone, and every locked object stays on the bill until its date passes.
Retention and the 90-day minimum
As of October 2026, on Pay as You Go pricing, an object deleted before it has been stored for 90 days is charged for the remaining days as Timed Deleted Storage, at the storage rate. Wasabi's own example: an object stored on day 1 and deleted on day 16 is billed for 15 days of active storage plus 75 days of deleted storage. Overwriting a file in a bucket without versioning counts as deleting the old copy.
So short retention saves nothing. Upload a 50 GB archive nightly and keep 7: the bucket holds 350 GB, but each archive is billed for 90 days, so you pay for roughly 4.5 TB (50 GB × 90), about $36 a month at $7.99 per TB. Keep 90 archives and the bill is the same, with 13 times the history.
A lifecycle rule does the deleting. For a versioned bucket, which Object Lock requires, expire objects at 90 days and remove the old versions a day later:
{
"Rules": [
{
"ID": "expire-backups-after-90-days",
"Filter": {},
"Status": "Enabled",
"Expiration": { "Days": 90 },
"NoncurrentVersionExpiration": { "NoncurrentDays": 1 }
}
]
}aws s3api put-bucket-lifecycle-configuration --bucket web-01-backups --lifecycle-configuration file://lifecycle.json --endpoint-url https://s3.us-east-2.wasabisys.com --profile wasabi-admin"Filter": {}applies the rule to the whole bucket, so keep one bucket per purpose.ExpirationwithDays: 90: in a versioned bucket, an object gets a delete marker 90 days after upload, and its data becomes a noncurrent version.NoncurrentVersionExpirationwithNoncurrentDays: 1deletes that version for good one day later.
In the console, the bucket's Settings, Lifecycle tab, Create New Rule sets the same rule and also offers Delete incomplete multipart uploads, for parts left by crashed uploads.
Keep the Object Lock retention shorter than the lifecycle expiration, such as 30 days locked and 90 days kept, so each version is unlocked by the time the rule removes it.
What it costs
As of October 2026, Wasabi's pricing pages list:
- Pay as You Go storage: $7.99 per TB per month ($0.0078 per GB) in North America, EMEA and APAC.
- A minimum monthly charge of 1 TB of active storage. Store 100 GB and you pay for 1 TB.
- No fees for egress or API requests.
- Reserved Capacity Storage, bought in 1, 3 or 5-year terms, for larger fixed amounts.
Free egress has a fair-use condition: monthly egress should not exceed your active storage. Store 2 TB and you can download up to 2 TB a month. If egress regularly exceeds storage, Wasabi reserves the right to limit or suspend the service. Backups, written often and read rarely, fit well.
Verify a backup
When you make each archive, record its checksum in /var/backups and upload the .sha256 file too:
sha256sum web-01-2026-10-03.tar.gz > web-01-2026-10-03.tar.gz.sha256These commands use the profile's endpoint_url; without it, add --endpoint-url.
aws s3 ls s3://web-01-backups/web-01/ --recursive --human-readable --summarize --profile wasabi--recursive lists every object under the prefix, --human-readable prints sizes in MiB and GiB, and --summarize adds the object count and total size. Then stream an archive back and hash it:
aws s3 cp s3://web-01-backups/web-01/web-01-2026-10-03.tar.gz - --profile wasabi | sha256sumThe - destination writes the download to standard output, so nothing lands on disk. The hash must match the .sha256 file. That proves the bytes are intact, not that the backup is complete, so extract one on a scratch machine regularly, as in how to test a backup restore.
Limits and gotchas
- Under 1 TB stored, you still pay for 1 TB.
- Deleting or overwriting within 90 days is billed as 90 days.
- Object Lock is set at bucket creation only, and can't be disabled.
- Downloading more than you store, month after month, can get the service limited.
A key that can upload can usually delete too. For backups an attacker cannot remove, see protecting backups from ransomware; to keep what is stored readable only by you, encrypt it before upload.
Frequently asked questions
- Does Wasabi charge for deleting data early?
- Yes. As of October 2026, on Pay as You Go pricing, an object deleted or overwritten before 90 days is billed for the remaining days as Timed Deleted Storage. Shorter retention costs the same, so keep backups at least 90 days.
- Is Wasabi egress really free?
- There are no egress fees, under a fair-use condition: your monthly downloads should not exceed the amount you store. If they regularly do, Wasabi may limit or suspend the service.
- What is the Wasabi S3 endpoint for my bucket?
s3.<region>.wasabisys.comfor the bucket's region, for examples3.eu-central-2.wasabisys.comfor Frankfurt.s3.wasabisys.comalso works for us-east-1.- Can I enable Object Lock on an existing Wasabi bucket?
- No. Object Lock can be turned on only when a bucket is created, with versioning on. Create a new bucket and send new backups there.
How this was checked
Commands, limits and prices were checked against these official pages, on October 3, 2026:
- Wasabi: Hot Cloud Storage pricing
- Wasabi: Pricing FAQs for the Pay as You Go pricing model
- Wasabi Docs: How does Wasabi's minimum storage duration policy work?
- Wasabi Docs: Service URLs for Wasabi's storage regions
- Wasabi Docs: Working with buckets and objects (create a bucket)
- Wasabi Docs: Bucket access restriction based on an identity policy
- Wasabi Docs: Creating a policy
- Wasabi Docs: Create a user account and access key
- Wasabi Docs: AWS CLI with Wasabi (endpoint, profile, CRC64NVME checksum workaround)
- Wasabi Docs: Object Lock: Enabling
- Wasabi Docs: Object Lock: Setting for a bucket or object
- Wasabi API Docs: Object Lock on buckets with the Wasabi S3 API
- Wasabi Docs: Lifecycle settings: creating a rule
- Wasabi Docs: Setting lifecycle policies using the AWS CLI
- AWS CLI User Guide: Using endpoints (endpoint_url in a profile)
- AWS CLI reference: s3 cp, s3 ls
- AWS CLI reference: s3api get-object-lock-configuration, put-bucket-lifecycle-configuration