{
  "data": {
    "category": {
      "area": "everyday",
      "capabilities": [
        "storage.object",
        "storage.s3",
        "storage.share",
        "storage.drive",
        "storage.presigned"
      ],
      "description": "Object storage and file services an agent can put files in and share them from: S3-compatible buckets, and drives with folders, permissions and share links. Compared on price per gigabyte, egress fees, access controls and S3 compatibility.",
      "indexed": [
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/dbconvert-streams.json",
          "kind": "mcp",
          "name": "DBConvert Streams (Federated SQL)",
          "slug": "dbconvert-streams",
          "url": "https://www.anchorterminal.com/tools/dbconvert-streams"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/gitkraken-gk-cli.json",
          "kind": "mcp",
          "name": "gk-cli",
          "slug": "gitkraken-gk-cli",
          "url": "https://www.anchorterminal.com/tools/gitkraken-gk-cli"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/objekt-mcp-upload.json",
          "kind": "mcp",
          "name": "mcp-upload",
          "slug": "objekt-mcp-upload",
          "url": "https://www.anchorterminal.com/tools/objekt-mcp-upload"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/obsideo-mcp.json",
          "kind": "mcp",
          "name": "obsideo.io MCP server",
          "slug": "obsideo-mcp",
          "url": "https://www.anchorterminal.com/tools/obsideo-mcp"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/wowsql-mcp.json",
          "kind": "mcp",
          "name": "WoWSQL",
          "slug": "wowsql-mcp",
          "url": "https://www.anchorterminal.com/tools/wowsql-mcp"
        }
      ],
      "indexedCount": 5,
      "json": "https://www.anchorterminal.com/categories/file-storage.json",
      "name": "File storage \u0026 sharing",
      "slug": "file-storage",
      "test": "An agent uploads a large file, lists a folder, shares a link that expires and deletes the file. We check the upload path, access controls, link expiry, and the storage and egress costs.",
      "title": "File storage and sharing APIs for AI agents",
      "toolCount": 14,
      "tools": [
        "google-drive-api",
        "amazon-s3",
        "cloudflare-r2",
        "azure-blob-storage",
        "supabase-mcp",
        "backblaze-b2",
        "box-api",
        "dropbox-api",
        "onedrive-sharepoint",
        "digitalocean-spaces",
        "wasabi-hot-cloud-storage",
        "bunny-storage",
        "fast-io",
        "tigris"
      ],
      "url": "https://www.anchorterminal.com/categories/file-storage"
    },
    "faq": [
      {
        "answer": "Google Drive API + MCP has the highest benchmark score of the 14 ranked file storage and sharing APIs, 79.6 (A). Amazon S3 is second with 77.9 (BB).",
        "question": "What are the highest-rated file storage and sharing APIs for AI agents?"
      },
      {
        "answer": "6 of the 14 ranked here grade BB or better, the bar for agent-ready on the Anchor benchmark.",
        "question": "How many file storage and sharing APIs are agent-ready?"
      },
      {
        "answer": "None of the ranked listings here accepts x402 for its main call yet.",
        "question": "Which file storage and sharing APIs accept x402 payments?"
      },
      {
        "answer": "By published paid prices, Bunny Storage, at $0.005 per GB, the lowest of the 6 listings here with a paid price in this unit (free allowances aside). Plans, volume tiers and free allowances change the sum, so check the listing's price table.",
        "question": "Which of these file storage and sharing APIs is cheapest?"
      },
      {
        "answer": "By the Anchor benchmark score out of 100, a weighted mean of the scored categories minus deductions for negative events, from public evidence re-checked as vendors change. Listings cannot pay for a place. The latest assessment behind this page is from 9 October 2026.",
        "question": "How is this list ranked?"
      }
    ],
    "howToChoose": [
      {
        "label": "Egress fees on downloads",
        "detail": "Estimate the egress charge for the downloads the agent will make, because storage that is cheap to keep can cost more once files are read back out."
      },
      {
        "label": "Expiring share link behaviour",
        "detail": "Test that a share link stops working at its expiry time, since an agent that sends a link to someone else depends on the expiry being enforced."
      },
      {
        "label": "Access controls and deletion",
        "detail": "Check who can delete or list files under each credential, because an agent given write access to a bucket can remove files it was never meant to touch."
      },
      {
        "label": "Jurisdiction and legal entity",
        "detail": "Read which legal entity and jurisdiction hold the stored files, since the location of the data can shape which rules apply to what the agent uploads."
      }
    ],
    "picks": [
      {
        "also": {
          "name": "Amazon S3",
          "slug": "amazon-s3",
          "why": "BB, 77.9/100"
        },
        "name": "Google Drive API + MCP",
        "need": "Highest score overall",
        "slug": "google-drive-api",
        "why": "A, 79.6/100 on the benchmark"
      },
      {
        "name": "Amazon S3",
        "need": "Schema \u0026 documentation",
        "slug": "amazon-s3",
        "why": "92/100 on schema \u0026 documentation, against 83 for the overall leader"
      },
      {
        "name": "Cloudflare R2",
        "need": "Agent ergonomics",
        "slug": "cloudflare-r2",
        "why": "90/100 on agent ergonomics, against 85 for the overall leader"
      },
      {
        "name": "Supabase API + MCP",
        "need": "Maintenance \u0026 community",
        "slug": "supabase-mcp",
        "why": "90/100 on maintenance \u0026 community, against 85 for the overall leader"
      },
      {
        "name": "Supabase API + MCP",
        "need": "Transparency \u0026 trust",
        "slug": "supabase-mcp",
        "why": "90/100 on transparency \u0026 trust, against 75 for the overall leader"
      },
      {
        "also": {
          "name": "Cloudflare R2",
          "slug": "cloudflare-r2",
          "why": "$0.01 per GB"
        },
        "name": "Bunny Storage",
        "need": "Lowest paid price per GB",
        "slug": "bunny-storage",
        "why": "$0.005 per GB, the lowest of the 6 listings here with a paid price in this unit (free allowances aside)"
      },
      {
        "also": {
          "name": "Backblaze B2",
          "slug": "backblaze-b2",
          "why": "self-hosted, MIT licence"
        },
        "name": "Supabase API + MCP",
        "need": "Self-hosting under an open licence",
        "slug": "supabase-mcp",
        "why": "self-hosted, Apache-2 licence"
      },
      {
        "name": "Backblaze B2",
        "need": "The review panel's favourite",
        "slug": "backblaze-b2",
        "why": "3.8/5 from 8 panel reviews"
      }
    ],
    "ranked": 14,
    "shortlist": [
      {
        "bestFor": "Agents working on files that people already keep in Drive, inside a Workspace organisation with admin controls.",
        "grade": "A",
        "name": "Google Drive API + MCP",
        "position": 1,
        "price": "Free",
        "score": 79.6,
        "slug": "google-drive-api",
        "strengths": [
          "No charge for API calls within quota, counted in quota units per minute per project and per user",
          "Public discovery document, refreshed three times in September 2026, and 40-odd documented error reasons with backoff advice",
          "Official MCP server with eight tools, none that delete or share, and a setup page that warns about prompt injection"
        ],
        "url": "https://www.anchorterminal.com/tools/google-drive-api",
        "verdict": "No charge for API calls within quota, counted in quota units per minute per project and per user. OAuth consent, scope verification and a Cloud project before an agent can list a folder.",
        "weaknesses": [
          "OAuth consent, scope verification and a Cloud project before an agent can list a folder",
          "The MCP server is Developer Preview and needs your own OAuth client and programme membership",
          "expirationTime can't be set on domain or anyone shares, so a public link never expires on its own"
        ],
        "where": "hosted",
        "x402": "no"
      },
      {
        "bestFor": "Best when the rest of the stack is on AWS or the job needs versioning, Object Lock, replication or event notifications, and when an operator wants per-prefix, per-hour credentials for an agent.",
        "grade": "BB",
        "name": "Amazon S3",
        "position": 2,
        "price": "$0.005 / 1k req",
        "score": 77.9,
        "slug": "amazon-s3",
        "strengths": [
          "STS session credentials with session policies, so an agent can hold one prefix for an hour",
          "SLA of 99.9 per cent a month on Standard, and documented rates of 3,500 writes and 5,500 reads a second per prefix",
          "Conditional writes, and conditional deletes since 16 September 2025, make retried calls safe"
        ],
        "url": "https://www.anchorterminal.com/tools/amazon-s3",
        "verdict": "STS session credentials with session policies, so an agent can hold one prefix for an hour. Egress to the internet is billed per GB after 100 GB a month.",
        "weaknesses": [
          "Egress to the internet is billed per GB after 100 GB a month",
          "The pricing page renders the Standard table by script, so an agent reading it sees no Standard rate",
          "Signup needs a person in a browser, though since October 2026 most new accounts aren't asked for a payment card"
        ],
        "where": "hosted",
        "x402": "no"
      },
      {
        "bestFor": "Files an agent stores and then serves to the public, where free egress dominates, and for operators who want short-lived, path-scoped credentials.",
        "grade": "BB",
        "name": "Cloudflare R2",
        "position": 3,
        "price": "$0.0045 / 1k req",
        "score": 77.1,
        "slug": "cloudflare-r2",
        "strengths": [
          "Free egress and a free tier of 10 GB-month plus 1 million writes a month",
          "Temporary credentials bound to a bucket, operations and paths that expire on their own",
          "An error table of 29 codes, each with an HTTP status and a recommended fix"
        ],
        "url": "https://www.anchorterminal.com/tools/cloudflare-r2",
        "verdict": "Free egress and a monthly free tier of 10 GB-month plus 1 million writes, though enabling R2 needs a checkout with a payment method on the account. No versioning, tagging, ACLs or bucket policies on the S3 API; retention comes as bucket lock rules.",
        "weaknesses": [
          "No versioning, tagging, ACLs or bucket policies on the S3 API; retention comes as bucket lock rules",
          "Presigned URLs don't work on custom domains and can't do POST form uploads",
          "One write a second to the same object key, with a 429 above that"
        ],
        "where": "hosted",
        "x402": "no"
      },
      {
        "bestFor": "Agents and runtimes already on Azure, where a managed identity writes to one container with no stored key, and jobs that need tiers, immutability or geo-redundant copies.",
        "grade": "BB",
        "name": "Azure Blob Storage",
        "position": 4,
        "price": "$0.005 / 1k req",
        "score": 75.7,
        "slug": "azure-blob-storage",
        "strengths": [
          "Microsoft Entra ID roles such as Storage Blob Data Reader can be assigned on one container, with no stored key for workloads on Azure",
          "A user delegation shared access signature is signed with Entra credentials, lasts at most seven days and can be limited by permission, IP address and protocol",
          "SLA of 99.9 per cent on the hot tier, 99.99 per cent for reads on RA-GRS accounts, in the 1 October 2026 SLA document"
        ],
        "url": "https://www.anchorterminal.com/tools/azure-blob-storage",
        "verdict": "Microsoft Entra ID roles can be scoped to one container, and a user delegation signature hands out a link that expires within seven days. Account keys with full access stay enabled until the owner turns them off, request logs are off until configured, and an Azure account needs a person, a phone number and a payment card.",
        "weaknesses": [
          "Shared Key authorisation with the account's access keys is allowed until the owner sets `AllowSharedKeyAccess` to false",
          "Request logs are not collected until a diagnostic setting routes the StorageRead, StorageWrite and StorageDelete categories somewhere",
          "Requests and responses use headers and XML, and every authorised call must carry `x-ms-version`"
        ],
        "where": "hosted",
        "x402": "no"
      },
      {
        "bestFor": "Agents building on or administering Supabase projects, and for retrieval that wants vectors, full-text and SQL filters in one database.",
        "grade": "BB",
        "name": "Supabase API + MCP",
        "position": 5,
        "price": "$25 / mo",
        "score": 75.6,
        "slug": "supabase-mcp",
        "strengths": [
          "OAuth 2.1 with dynamic client registration, plus personal access tokens scoped to chosen projects and permissions",
          "`read_only`, `project_ref` and `features` cut the server from 34 tools to as few as 6 and run SQL as a read-only role",
          "Destructive SQL and cost-bearing creates ask for confirmation through elicitation since v0.13.0"
        ],
        "url": "https://www.anchorterminal.com/tools/supabase-mcp",
        "verdict": "OAuth 2.1 with dynamic client registration, plus personal access tokens scoped to chosen projects and permissions. Several multi-hour platform incidents between 27 August and 30 September.",
        "weaknesses": [
          "Several multi-hour platform incidents between 27 August and 30 September",
          "Read-write with seven feature groups is the default, and the agent plugin has no read-only option",
          "Untrusted data in tables can still steer an agent that reads it, as Supabase says itself"
        ],
        "where": "both",
        "x402": "no"
      },
      {
        "bestFor": "Cheap bulk storage that an agent writes and a CDN serves, and for operators who want an MCP server with real guardrails.",
        "grade": "BB",
        "name": "Backblaze B2",
        "position": 6,
        "price": "$0.01 / GB",
        "score": 75.3,
        "slug": "backblaze-b2",
        "strengths": [
          "$6.95 a TB-month, first 10 GB free, Class A, B and C API calls free, and no card at signup",
          "Egress free up to 3x storage and always free to Cloudflare, Fastly, bunny.net and other partners",
          "Official MCP server with 40 annotated tools, capability-aware registration and a confirm or block gate on destructive tools"
        ],
        "url": "https://www.anchorterminal.com/tools/backblaze-b2",
        "verdict": "$6.95 a TB-month, first 10 GB free, Class A, B and C API calls free, and no card at signup. No rate limits published with numbers; the docs say only that B2 may throttle per account.",
        "weaknesses": [
          "No rate limits published with numbers; the docs say only that B2 may throttle per account",
          "status.backblaze.com renders only with JavaScript, so its incident history can't be read by a script",
          "STS temporary credentials are in Limited Availability for Enterprise customers only, from 30 September 2026"
        ],
        "where": "both",
        "x402": "no"
      },
      {
        "bestFor": "Agents working inside an enterprise's existing Box content with admin oversight, Box AI extraction and audit needs.",
        "grade": "B",
        "name": "Box API + MCP",
        "position": 7,
        "price": "Your plan",
        "score": 69.4,
        "slug": "box-api",
        "strengths": [
          "Public OpenAPI 3.0 spec with 297 operations, year-based API versions and an llms.txt of Markdown pages",
          "At least 24 months between deprecation and retirement of an API version, with Deprecation response headers",
          "Official remote MCP server with OAuth, 57 tools and 22 riskier ones off until an admin enables them"
        ],
        "url": "https://www.anchorterminal.com/tools/box-api",
        "verdict": "Public OpenAPI 3.0 spec with 297 operations, year-based API versions and an llms.txt of Markdown pages. 20 status-feed entries between 7 July and 1 October 2026, two of them over two hours on uploads or multiple services.",
        "weaknesses": [
          "20 status-feed entries between 7 July and 1 October 2026, two of them over two hours on uploads or multiple services",
          "MCP server needs Business or above, a three-seat minimum, and admin enablement per tool group",
          "The MCP server asks for root_readwrite, so a connected agent can write wherever its user can once tools are on"
        ],
        "where": "hosted",
        "x402": "no"
      },
      {
        "bestFor": "An agent acting on a person's or team's existing Dropbox files, especially a solo user on the free plan.",
        "grade": "B",
        "name": "Dropbox API + MCP",
        "position": 8,
        "price": "Your plan",
        "score": 68.2,
        "slug": "dropbox-api",
        "strengths": [
          "Typed Stone spec of 281 routes with per-route OAuth scopes and error unions, updated 1 October 2026",
          "Granular OAuth scopes and App folder apps that see one folder",
          "Official hosted MCP server with OAuth and dynamic client registration, no app to register"
        ],
        "url": "https://www.anchorterminal.com/tools/dropbox-api",
        "verdict": "Typed Stone spec of 281 routes with per-route OAuth scopes and error unions, updated 1 October 2026. MCP server is beta, extracts at most 5 MB per file and can be blocked by team admins.",
        "weaknesses": [
          "MCP server is beta, extracts at most 5 MB per file and can be blocked by team admins",
          "Link expiry and passwords aren't available to Basic accounts",
          "No numeric rate limits published; the developer terms let Dropbox cap calls at its discretion"
        ],
        "where": "hosted",
        "x402": "no"
      },
      {
        "bestFor": "Agents working on files that already live in a Microsoft 365 tenant or a personal OneDrive, where sharing has to follow the tenant's own policy.",
        "grade": "B",
        "name": "OneDrive and SharePoint files (Microsoft Graph)",
        "position": 9,
        "price": "Your plan",
        "score": 65.3,
        "slug": "onedrive-sharepoint",
        "strengths": [
          "Upload sessions resume after a dropped connection, report `nextExpectedRanges`, and accept `If-Match` and `@microsoft.graph.conflictBehavior` (fail by default)",
          "`createLink` takes `expirationDateTime` and a scope of `anonymous`, `organization` or `users`, and returns the existing link when one of that type exists",
          "Selected scopes limit an application to chosen sites, lists, folders or files, each with a read, write, owner or fullcontrol role"
        ],
        "url": "https://www.anchorterminal.com/tools/onedrive-sharepoint",
        "verdict": "One REST surface covers personal OneDrive, work OneDrive and SharePoint libraries, with resumable uploads, sharing links that take an expiry date and per-file Selected permissions. The status page needs JavaScript, an app must be registered and consented to by a person, and the JavaScript client on npm lacks a token-leak fix merged in June 2026.",
        "weaknesses": [
          "Link and scope types are plain strings in the OpenAPI, and path addressing such as `/root:/folder/file.txt:` is absent from it",
          "Password-protected links and `embed` links work only on personal OneDrive, and an administrator can switch anonymous links off",
          "The status page at status.cloud.microsoft shows nothing without JavaScript, so no incident history could be read"
        ],
        "where": "hosted",
        "x402": "no"
      },
      {
        "bestFor": "Teams already on DigitalOcean that want object storage with a CDN and a flat $5 entry price for up to 250 GiB, with free transfer to Droplets in the same region.",
        "grade": "B",
        "name": "DigitalOcean Spaces",
        "position": 10,
        "price": "$5 / mo",
        "score": 63.2,
        "slug": "digitalocean-spaces",
        "strengths": [
          "Spaces access keys can be limited to named buckets with read or read-write-delete grants, and are created through `/v2/spaces/keys` or the control panel",
          "Limits are published with numbers, 800 operations a second per new bucket, with exponential backoff advised on `503 Slow Down`",
          "The Spaces SLA of 2 December 2025 gives 99.9 per cent monthly uptime per bucket, with credits of 10, 25 and 100 per cent"
        ],
        "url": "https://www.anchorterminal.com/tools/digitalocean-spaces",
        "verdict": "Per-bucket access keys with read or read-write-delete grants, an 800 operations a second limit per bucket and a 99.9 per cent SLA are all published. The MCP server manages keys and CDN endpoints only, not objects, and the S3 reference documents no error codes. A payment method is required before any bucket is created.",
        "weaknesses": [
          "The Spaces MCP server has ten tools for access keys and CDN endpoints. None reads, writes, lists or shares an object",
          "The access guide and the limits page say keys cannot be created through the API, while the API reference documents `POST /v2/spaces/keys`",
          "The limits page lists `list-objects-v2` pagination as unsupported, and the compatibility page says to use `ListObjectsV2` for new applications"
        ],
        "where": "hosted",
        "x402": "no"
      }
    ],
    "updated": "2026-10-09"
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/best/file-storage/",
    "json": "https://www.anchorterminal.com/best/file-storage/index.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/best/file-storage/index.md",
    "slim": "https://www.anchorterminal.com/best/file-storage/index.min.md"
  },
  "markdown": "The 10 highest-scoring of 14 file storage and sharing APIs on the Anchor benchmark, with a pick for each need and where each one falls short. Scores come from public evidence, re-checked as vendors change.\n\n- Ranked: 14 · agent-ready (BB or better): 6 · accept x402: 0 · hosted endpoints: 14\n- Full ranked table: https://www.anchorterminal.com/categories/file-storage.md\n- Head-to-head comparisons: https://www.anchorterminal.com/compare/file-storage/index.md (75)\n- Methodology: https://www.anchorterminal.com/benchmark/index.md\n\n## The shortlist\n\n| # | Tool | Grade | Score | Best for | Price | Where |\n| --- | --- | --- | --- | --- | --- | --- |\n| 1 | [Google Drive API + MCP](https://www.anchorterminal.com/tools/google-drive-api.md) | A | 79.6 | Agents working on files that people already keep in Drive, inside a Workspace organisation with admin controls. | Free | hosted |\n| 2 | [Amazon S3](https://www.anchorterminal.com/tools/amazon-s3.md) | BB | 77.9 | Best when the rest of the stack is on AWS or the job needs versioning, Object Lock, replication or event notifications, and when an operator wants per-prefix, per-hour credentials for an agent. | $0.005 / 1k req | hosted |\n| 3 | [Cloudflare R2](https://www.anchorterminal.com/tools/cloudflare-r2.md) | BB | 77.1 | Files an agent stores and then serves to the public, where free egress dominates, and for operators who want short-lived, path-scoped credentials. | $0.0045 / 1k req | hosted |\n| 4 | [Azure Blob Storage](https://www.anchorterminal.com/tools/azure-blob-storage.md) | BB | 75.7 | Agents and runtimes already on Azure, where a managed identity writes to one container with no stored key, and jobs that need tiers, immutability or geo-redundant copies. | $0.005 / 1k req | hosted |\n| 5 | [Supabase API + MCP](https://www.anchorterminal.com/tools/supabase-mcp.md) | BB | 75.6 | Agents building on or administering Supabase projects, and for retrieval that wants vectors, full-text and SQL filters in one database. | $25 / mo | hosted and local |\n| 6 | [Backblaze B2](https://www.anchorterminal.com/tools/backblaze-b2.md) | BB | 75.3 | Cheap bulk storage that an agent writes and a CDN serves, and for operators who want an MCP server with real guardrails. | $0.01 / GB | hosted and local |\n| 7 | [Box API + MCP](https://www.anchorterminal.com/tools/box-api.md) | B | 69.4 | Agents working inside an enterprise's existing Box content with admin oversight, Box AI extraction and audit needs. | Your plan | hosted |\n| 8 | [Dropbox API + MCP](https://www.anchorterminal.com/tools/dropbox-api.md) | B | 68.2 | An agent acting on a person's or team's existing Dropbox files, especially a solo user on the free plan. | Your plan | hosted |\n| 9 | [OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/tools/onedrive-sharepoint.md) | B | 65.3 | Agents working on files that already live in a Microsoft 365 tenant or a personal OneDrive, where sharing has to follow the tenant's own policy. | Your plan | hosted |\n| 10 | [DigitalOcean Spaces](https://www.anchorterminal.com/tools/digitalocean-spaces.md) | B | 63.2 | Teams already on DigitalOcean that want object storage with a CDN and a flat $5 entry price for up to 250 GiB, with free transfer to Droplets in the same region. | $5 / mo | hosted |\n\n## Picks by need\n\n- Highest score overall: [Google Drive API + MCP](https://www.anchorterminal.com/tools/google-drive-api.md), A, 79.6/100 on the benchmark. Also [Amazon S3](https://www.anchorterminal.com/tools/amazon-s3.md), BB, 77.9/100.\n- Schema \u0026 documentation: [Amazon S3](https://www.anchorterminal.com/tools/amazon-s3.md), 92/100 on schema \u0026 documentation, against 83 for the overall leader.\n- Agent ergonomics: [Cloudflare R2](https://www.anchorterminal.com/tools/cloudflare-r2.md), 90/100 on agent ergonomics, against 85 for the overall leader.\n- Maintenance \u0026 community: [Supabase API + MCP](https://www.anchorterminal.com/tools/supabase-mcp.md), 90/100 on maintenance \u0026 community, against 85 for the overall leader.\n- Transparency \u0026 trust: [Supabase API + MCP](https://www.anchorterminal.com/tools/supabase-mcp.md), 90/100 on transparency \u0026 trust, against 75 for the overall leader.\n- Lowest paid price per GB: [Bunny Storage](https://www.anchorterminal.com/tools/bunny-storage.md), $0.005 per GB, the lowest of the 6 listings here with a paid price in this unit (free allowances aside). Also [Cloudflare R2](https://www.anchorterminal.com/tools/cloudflare-r2.md), $0.01 per GB.\n- Self-hosting under an open licence: [Supabase API + MCP](https://www.anchorterminal.com/tools/supabase-mcp.md), self-hosted, Apache-2 licence. Also [Backblaze B2](https://www.anchorterminal.com/tools/backblaze-b2.md), self-hosted, MIT licence.\n- The review panel's favourite: [Backblaze B2](https://www.anchorterminal.com/tools/backblaze-b2.md), 3.8/5 from 8 panel reviews.\n\n## How to choose\n\n- Egress fees on downloads: Estimate the egress charge for the downloads the agent will make, because storage that is cheap to keep can cost more once files are read back out.\n- Expiring share link behaviour: Test that a share link stops working at its expiry time, since an agent that sends a link to someone else depends on the expiry being enforced.\n- Access controls and deletion: Check who can delete or list files under each credential, because an agent given write access to a bucket can remove files it was never meant to touch.\n- Jurisdiction and legal entity: Read which legal entity and jurisdiction hold the stored files, since the location of the data can shape which rules apply to what the agent uploads.\n\n- How the benchmark tests this category: An agent uploads a large file, lists a folder, shares a link that expires and deletes the file. We check the upload path, access controls, link expiry, and the storage and egress costs.\n\n## Each one in detail\n\n### 1. Google Drive API + MCP, A 79.6/100\n\nREST API for a user's or a Workspace organisation's Drive, files, folders, permissions and share links, with resumable uploads and change feeds.\n\n- Verdict: No charge for API calls within quota, counted in quota units per minute per project and per user. OAuth consent, scope verification and a Cloud project before an agent can list a folder.\n- Choose it for: Agents working on files that people already keep in Drive, inside a Workspace organisation with admin controls.\n- Strength: No charge for API calls within quota, counted in quota units per minute per project and per user\n- Strength: Public discovery document, refreshed three times in September 2026, and 40-odd documented error reasons with backoff advice\n- Strength: Official MCP server with eight tools, none that delete or share, and a setup page that warns about prompt injection\n- Weakness: OAuth consent, scope verification and a Cloud project before an agent can list a folder\n- Weakness: The MCP server is Developer Preview and needs your own OAuth client and programme membership\n- Weakness: expirationTime can't be set on domain or anyone shares, so a public link never expires on its own\n- Price: Free · Auth: OAuth · x402: no · Where: hosted\n- Full assessment: https://www.anchorterminal.com/tools/google-drive-api.md\n\n### 2. Amazon S3, BB 77.9/100\n\nAWS object storage for files, backups and application data, accessed through an API.\n\n- Verdict: STS session credentials with session policies, so an agent can hold one prefix for an hour. Egress to the internet is billed per GB after 100 GB a month.\n- Choose it for: Best when the rest of the stack is on AWS or the job needs versioning, Object Lock, replication or event notifications, and when an operator wants per-prefix, per-hour credentials for an agent.\n- Strength: STS session credentials with session policies, so an agent can hold one prefix for an hour\n- Strength: SLA of 99.9 per cent a month on Standard, and documented rates of 3,500 writes and 5,500 reads a second per prefix\n- Strength: Conditional writes, and conditional deletes since 16 September 2025, make retried calls safe\n- Weakness: Egress to the internet is billed per GB after 100 GB a month\n- Weakness: The pricing page renders the Standard table by script, so an agent reading it sees no Standard rate\n- Weakness: Signup needs a person in a browser, though since October 2026 most new accounts aren't asked for a payment card\n- Price: $0.005 / 1k req · Auth: API key · x402: no · Where: hosted\n- Full assessment: https://www.anchorterminal.com/tools/amazon-s3.md\n- Against #1: https://www.anchorterminal.com/compare/amazon-s3-vs-google-drive-api.md\n\n### 3. Cloudflare R2, BB 77.1/100\n\nS3-compatible object storage with no egress fees.\n\n- Verdict: Free egress and a monthly free tier of 10 GB-month plus 1 million writes, though enabling R2 needs a checkout with a payment method on the account. No versioning, tagging, ACLs or bucket policies on the S3 API; retention comes as bucket lock rules.\n- Choose it for: Files an agent stores and then serves to the public, where free egress dominates, and for operators who want short-lived, path-scoped credentials.\n- Strength: Free egress and a free tier of 10 GB-month plus 1 million writes a month\n- Strength: Temporary credentials bound to a bucket, operations and paths that expire on their own\n- Strength: An error table of 29 codes, each with an HTTP status and a recommended fix\n- Weakness: No versioning, tagging, ACLs or bucket policies on the S3 API; retention comes as bucket lock rules\n- Weakness: Presigned URLs don't work on custom domains and can't do POST form uploads\n- Weakness: One write a second to the same object key, with a 429 above that\n- Price: $0.0045 / 1k req · Auth: API key · x402: no · Where: hosted\n- Full assessment: https://www.anchorterminal.com/tools/cloudflare-r2.md\n- Against #1: https://www.anchorterminal.com/compare/cloudflare-r2-vs-google-drive-api.md\n\n### 4. Azure Blob Storage, BB 75.7/100\n\nMicrosoft Azure's object storage for files, backups and application data. Agents call a REST API or the Azure SDKs on a storage account, signing in with Microsoft Entra ID, an account key or a shared access signature.\n\n- Verdict: Microsoft Entra ID roles can be scoped to one container, and a user delegation signature hands out a link that expires within seven days. Account keys with full access stay enabled until the owner turns them off, request logs are off until configured, and an Azure account needs a person, a phone number and a payment card.\n- Choose it for: Agents and runtimes already on Azure, where a managed identity writes to one container with no stored key, and jobs that need tiers, immutability or geo-redundant copies.\n- Strength: Microsoft Entra ID roles such as Storage Blob Data Reader can be assigned on one container, with no stored key for workloads on Azure\n- Strength: A user delegation shared access signature is signed with Entra credentials, lasts at most seven days and can be limited by permission, IP address and protocol\n- Strength: SLA of 99.9 per cent on the hot tier, 99.99 per cent for reads on RA-GRS accounts, in the 1 October 2026 SLA document\n- Weakness: Shared Key authorisation with the account's access keys is allowed until the owner sets `AllowSharedKeyAccess` to false\n- Weakness: Request logs are not collected until a diagnostic setting routes the StorageRead, StorageWrite and StorageDelete categories somewhere\n- Weakness: Requests and responses use headers and XML, and every authorised call must carry `x-ms-version`\n- Price: $0.005 / 1k req · Auth: OAuth or key · x402: no · Where: hosted\n- Full assessment: https://www.anchorterminal.com/tools/azure-blob-storage.md\n- Against #1: https://www.anchorterminal.com/compare/azure-blob-storage-vs-google-drive-api.md\n\n### 5. Supabase API + MCP, BB 75.6/100\n\nHosted Postgres with an auto-generated REST API (PostgREST), GraphQL, auth, storage, realtime and Edge Functions, plus a Management API and an official MCP server.\n\n- Verdict: OAuth 2.1 with dynamic client registration, plus personal access tokens scoped to chosen projects and permissions. Several multi-hour platform incidents between 27 August and 30 September.\n- Choose it for: Agents building on or administering Supabase projects, and for retrieval that wants vectors, full-text and SQL filters in one database.\n- Strength: OAuth 2.1 with dynamic client registration, plus personal access tokens scoped to chosen projects and permissions\n- Strength: `read_only`, `project_ref` and `features` cut the server from 34 tools to as few as 6 and run SQL as a read-only role\n- Strength: Destructive SQL and cost-bearing creates ask for confirmation through elicitation since v0.13.0\n- Weakness: Several multi-hour platform incidents between 27 August and 30 September\n- Weakness: Read-write with seven feature groups is the default, and the agent plugin has no read-only option\n- Weakness: Untrusted data in tables can still steer an agent that reads it, as Supabase says itself\n- Price: $25 / mo · Auth: OAuth or key · x402: no · Where: hosted and local\n- Full assessment: https://www.anchorterminal.com/tools/supabase-mcp.md\n\n### 6. Backblaze B2, BB 75.3/100\n\nObject storage at $6.95 a TB-month with the first 10 GB free, egress free up to three times what you store and $0.01 a GB after, and no charge for most API calls.\n\n- Verdict: $6.95 a TB-month, first 10 GB free, Class A, B and C API calls free, and no card at signup. No rate limits published with numbers; the docs say only that B2 may throttle per account.\n- Choose it for: Cheap bulk storage that an agent writes and a CDN serves, and for operators who want an MCP server with real guardrails.\n- Strength: $6.95 a TB-month, first 10 GB free, Class A, B and C API calls free, and no card at signup\n- Strength: Egress free up to 3x storage and always free to Cloudflare, Fastly, bunny.net and other partners\n- Strength: Official MCP server with 40 annotated tools, capability-aware registration and a confirm or block gate on destructive tools\n- Weakness: No rate limits published with numbers; the docs say only that B2 may throttle per account\n- Weakness: status.backblaze.com renders only with JavaScript, so its incident history can't be read by a script\n- Weakness: STS temporary credentials are in Limited Availability for Enterprise customers only, from 30 September 2026\n- Price: $0.01 / GB · Auth: API key · x402: no · Where: hosted and local\n- Full assessment: https://www.anchorterminal.com/tools/backblaze-b2.md\n- Against #1: https://www.anchorterminal.com/compare/backblaze-b2-vs-google-drive-api.md\n\n### 7. Box API + MCP, B 69.4/100\n\nEnterprise content platform with a REST API for files, folders, shared links, collaborations, metadata and Box AI, published as OpenAPI with year-based API versions.\n\n- Verdict: Public OpenAPI 3.0 spec with 297 operations, year-based API versions and an llms.txt of Markdown pages. 20 status-feed entries between 7 July and 1 October 2026, two of them over two hours on uploads or multiple services.\n- Choose it for: Agents working inside an enterprise's existing Box content with admin oversight, Box AI extraction and audit needs.\n- Strength: Public OpenAPI 3.0 spec with 297 operations, year-based API versions and an llms.txt of Markdown pages\n- Strength: At least 24 months between deprecation and retirement of an API version, with Deprecation response headers\n- Strength: Official remote MCP server with OAuth, 57 tools and 22 riskier ones off until an admin enables them\n- Weakness: 20 status-feed entries between 7 July and 1 October 2026, two of them over two hours on uploads or multiple services\n- Weakness: MCP server needs Business or above, a three-seat minimum, and admin enablement per tool group\n- Weakness: The MCP server asks for root_readwrite, so a connected agent can write wherever its user can once tools are on\n- Price: Your plan · Auth: OAuth · x402: no · Where: hosted\n- Full assessment: https://www.anchorterminal.com/tools/box-api.md\n- Against #1: https://www.anchorterminal.com/compare/box-api-vs-google-drive-api.md\n\n### 8. Dropbox API + MCP, B 68.2/100\n\nHTTP API v2 for a user's or team's Dropbox, files, folders, upload sessions to about 2 TiB, shared links with passwords and expiry, file requests and change cursors.\n\n- Verdict: Typed Stone spec of 281 routes with per-route OAuth scopes and error unions, updated 1 October 2026. MCP server is beta, extracts at most 5 MB per file and can be blocked by team admins.\n- Choose it for: An agent acting on a person's or team's existing Dropbox files, especially a solo user on the free plan.\n- Strength: Typed Stone spec of 281 routes with per-route OAuth scopes and error unions, updated 1 October 2026\n- Strength: Granular OAuth scopes and App folder apps that see one folder\n- Strength: Official hosted MCP server with OAuth and dynamic client registration, no app to register\n- Weakness: MCP server is beta, extracts at most 5 MB per file and can be blocked by team admins\n- Weakness: Link expiry and passwords aren't available to Basic accounts\n- Weakness: No numeric rate limits published; the developer terms let Dropbox cap calls at its discretion\n- Price: Your plan · Auth: OAuth · x402: no · Where: hosted\n- Full assessment: https://www.anchorterminal.com/tools/dropbox-api.md\n- Against #1: https://www.anchorterminal.com/compare/dropbox-api-vs-google-drive-api.md\n\n### 9. OneDrive and SharePoint files (Microsoft Graph), B 65.3/100\n\nDrive and driveItem endpoints of Microsoft Graph for files in OneDrive, OneDrive for work or school and SharePoint document libraries. Calls upload, download, list, search, share by link or invitation, and delete files and folders.\n\n- Verdict: One REST surface covers personal OneDrive, work OneDrive and SharePoint libraries, with resumable uploads, sharing links that take an expiry date and per-file Selected permissions. The status page needs JavaScript, an app must be registered and consented to by a person, and the JavaScript client on npm lacks a token-leak fix merged in June 2026.\n- Choose it for: Agents working on files that already live in a Microsoft 365 tenant or a personal OneDrive, where sharing has to follow the tenant's own policy.\n- Strength: Upload sessions resume after a dropped connection, report `nextExpectedRanges`, and accept `If-Match` and `@microsoft.graph.conflictBehavior` (fail by default)\n- Strength: `createLink` takes `expirationDateTime` and a scope of `anonymous`, `organization` or `users`, and returns the existing link when one of that type exists\n- Strength: Selected scopes limit an application to chosen sites, lists, folders or files, each with a read, write, owner or fullcontrol role\n- Weakness: Link and scope types are plain strings in the OpenAPI, and path addressing such as `/root:/folder/file.txt:` is absent from it\n- Weakness: Password-protected links and `embed` links work only on personal OneDrive, and an administrator can switch anonymous links off\n- Weakness: The status page at status.cloud.microsoft shows nothing without JavaScript, so no incident history could be read\n- Price: Your plan · Auth: OAuth · x402: no · Where: hosted\n- Full assessment: https://www.anchorterminal.com/tools/onedrive-sharepoint.md\n- Against #1: https://www.anchorterminal.com/compare/google-drive-api-vs-onedrive-sharepoint.md\n\n### 10. DigitalOcean Spaces, B 63.2/100\n\nDigitalOcean Spaces is S3-compatible object storage with a built-in CDN, sold as a $5 monthly subscription. Agents use it through AWS S3 SDKs with a Spaces access key, and manage keys through the DigitalOcean API or MCP server.\n\n- Verdict: Per-bucket access keys with read or read-write-delete grants, an 800 operations a second limit per bucket and a 99.9 per cent SLA are all published. The MCP server manages keys and CDN endpoints only, not objects, and the S3 reference documents no error codes. A payment method is required before any bucket is created.\n- Choose it for: Teams already on DigitalOcean that want object storage with a CDN and a flat $5 entry price for up to 250 GiB, with free transfer to Droplets in the same region.\n- Strength: Spaces access keys can be limited to named buckets with read or read-write-delete grants, and are created through `/v2/spaces/keys` or the control panel\n- Strength: Limits are published with numbers, 800 operations a second per new bucket, with exponential backoff advised on `503 Slow Down`\n- Strength: The Spaces SLA of 2 December 2025 gives 99.9 per cent monthly uptime per bucket, with credits of 10, 25 and 100 per cent\n- Weakness: The Spaces MCP server has ten tools for access keys and CDN endpoints. None reads, writes, lists or shares an object\n- Weakness: The access guide and the limits page say keys cannot be created through the API, while the API reference documents `POST /v2/spaces/keys`\n- Weakness: The limits page lists `list-objects-v2` pagination as unsupported, and the compatibility page says to use `ListObjectsV2` for new applications\n- Price: $5 / mo · Auth: API key · x402: no · Where: hosted\n- Full assessment: https://www.anchorterminal.com/tools/digitalocean-spaces.md\n- Against #1: https://www.anchorterminal.com/compare/digitalocean-spaces-vs-google-drive-api.md\n\n4 more are ranked in the full table: https://www.anchorterminal.com/categories/file-storage.md\n\n## Head to head\n\n- [Amazon S3 vs Google Drive API + MCP](https://www.anchorterminal.com/compare/amazon-s3-vs-google-drive-api.md)\n- [Cloudflare R2 vs Google Drive API + MCP](https://www.anchorterminal.com/compare/cloudflare-r2-vs-google-drive-api.md)\n- [Azure Blob Storage vs Google Drive API + MCP](https://www.anchorterminal.com/compare/azure-blob-storage-vs-google-drive-api.md)\n- [Amazon S3 vs Cloudflare R2](https://www.anchorterminal.com/compare/amazon-s3-vs-cloudflare-r2.md)\n- [Amazon S3 vs Azure Blob Storage](https://www.anchorterminal.com/compare/amazon-s3-vs-azure-blob-storage.md)\n- [Azure Blob Storage vs Cloudflare R2](https://www.anchorterminal.com/compare/azure-blob-storage-vs-cloudflare-r2.md)\n\n## Questions\n\n### What are the highest-rated file storage and sharing APIs for AI agents?\n\nGoogle Drive API + MCP has the highest benchmark score of the 14 ranked file storage and sharing APIs, 79.6 (A). Amazon S3 is second with 77.9 (BB).\n\n### How many file storage and sharing APIs are agent-ready?\n\n6 of the 14 ranked here grade BB or better, the bar for agent-ready on the Anchor benchmark.\n\n### Which file storage and sharing APIs accept x402 payments?\n\nNone of the ranked listings here accepts x402 for its main call yet.\n\n### Which of these file storage and sharing APIs is cheapest?\n\nBy published paid prices, Bunny Storage, at $0.005 per GB, the lowest of the 6 listings here with a paid price in this unit (free allowances aside). Plans, volume tiers and free allowances change the sum, so check the listing's price table.\n\n### How is this list ranked?\n\nBy the Anchor benchmark score out of 100, a weighted mean of the scored categories minus deductions for negative events, from public evidence re-checked as vendors change. Listings cannot pay for a place. The latest assessment behind this page is from 9 October 2026.\n\n## How this list is made\n\nThe order is the Anchor benchmark score, the same number as on each listing. Each listing is graded from public evidence against the benchmark checklist, and the picks are worked out from those grades, prices and facts. No listing pays for its place, and paid audits or listing help never change a score.\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Best of",
        "url": "https://www.anchorterminal.com/best/"
      },
      {
        "name": "File storage \u0026 sharing",
        "url": ""
      }
    ],
    "description": "Google Drive API + MCP (A), Amazon S3 (BB) and Cloudflare R2 (BB) lead the 14 ranked file storage and sharing APIs. Picks by need, strengths, weaknesses and prices from the Anchor benchmark.",
    "facts": [
      "Google Drive API + MCP A",
      "Amazon S3 BB",
      "Cloudflare R2 BB"
    ],
    "h1": "Best file storage and sharing APIs for AI agents",
    "image": "https://www.anchorterminal.com/assets/og/best-file-storage.png",
    "path": "/best/file-storage/",
    "published": "",
    "section": "tools",
    "title": "Best file storage and sharing APIs for AI agents in 2026, ranked",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/best/file-storage/"
  },
  "tokens": {
    "markdown": 6050,
    "slim": 1580
  },
  "version": 1
}
