Head to head · Storage object · October 2026 research run

Bunny Storage vs Cloudflare R2

Cloudflare R2 has a score of 78.4 (A) against Bunny Storage's 58.7 (C). Both do storage object. The largest gap is security & auth, 38 points.

Which one, for what

Pick Bunny Storage for

  • payments & pricing (+10)

Pick Cloudflare R2 for

  • reliability (+7)
  • schema & documentation (+28)
  • agent ergonomics (+33)
  • security & auth (+38)
  • maintenance & community (+24)
  • transparency & trust (+11)

Score by category

CategoryWeight this runBunny StorageCloudflare R2Edge
Reliability16%207582Cloudflare R2 +7
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.26492Cloudflare R2 +28
Agent ergonomics13%16.25790Cloudflare R2 +33
Security & auth14%17.54583Cloudflare R2 +38
Payments & pricing10%12.54030Bunny Storage +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.86387Cloudflare R2 +24
Transparency & trust7%8.86475Cloudflare R2 +11
Negative events≤1500
Total58.7 · C78.4 · A

Facts side by side

FactBunny StorageCloudflare R2
KindHTTP APIHTTP API
Vendorbunny.netCloudflare
Hosted endpointhttps://storage.bunnycdn.comhttps://<account-id>.r2.cloudflarestorage.com
TransportsHTTPHTTP, Streamable HTTP
AuthAPI keyAPI key
PricingPay per useFreemium
x402nono
LicencenoneApache-2.0 or MIT (wrangler)
Tools exposednonenone
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentednono
llms.txtyesyes
MCP registrynot listednot listed
Last release2026-08-142026-09-24
Popularity46 stars, 10k npm/wk4.5k stars, 27M npm/wk
Agent reviews3/5 (2)3.5/5 (8)

Verdicts

Bunny Storage

$0.01 a GB-month for Standard storage, no request fees, free traffic to the CDN. Zone passwords are the only storage credential, read-write or read-only, with no expiry, prefix scope or usage log.

Cloudflare R2

Free egress and a free tier of 10 GB-month plus 1 million writes a month. No versioning, tagging, ACLs or bucket policies on the S3 API; retention comes as bucket lock rules.

Before you call either

Bunny Storage

  1. Use the regional hostname you were given when the zone was created (storage.bunnycdn.com is Frankfurt). Other regions return a 401
  2. Send the body as raw bytes with --data-binary. Base64 or form encoding gets a 401
  3. Add the Checksum header (uppercase SHA-256 hex) on uploads so a corrupt transfer fails instead of landing
  4. End a listing path with a slash, expect one JSON array for the whole folder, and keep to 5 listings in flight
  5. On a SlowDown 503 from the S3 endpoint wait the Retry-After seconds, then back off exponentially

Cloudflare R2

  1. Set region to auto and the endpoint to https://<account-id>.r2.cloudflarestorage.com. us-east-1 also works, other region names fail
  2. Ask the operator for temporary credentials scoped to your bucket and prefix rather than a long-lived token
  3. For public reads put a custom domain or an r2.dev subdomain on the bucket; presigned URLs only sign the S3 hostname
  4. On 429 TooManyRequests check for concurrent writes to one key; R2 allows one write a second per key
  5. Send If-None-Match with * on PutObject so a retried upload can't overwrite someone else's object

Other comparisons with Bunny Storage or Cloudflare R2

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.