Head to head · Object storage · October 2026 research run

Cloudflare R2 vs DigitalOcean Spaces

Cloudflare R2 scores 77.1 (BB) on agent readiness against DigitalOcean Spaces's 63.2 (B), and leads in 5 of 7 scored categories. Both do object storage.

Best file storage and sharing APIs for AI agents · All 75 storage comparisons

Which one, for what

Cloudflare R2 BB

Good for Files an agent stores and then serves to the public, where free egress dominates, and for operators who want short-lived, path-scoped credentials.

Ahead on

  • Reliability, 82 against 77
  • Schema & documentation, 92 against 63
  • Agent ergonomics, 90 against 73
  • Security & auth, 83 against 77
  • Maintenance & community, 87 against 37

Also in its favour

  • Agent-ready, a grade of BB or better

Watch for

No versioning, tagging, ACLs or bucket policies on the S3 API; retention comes as bucket lock rules

DigitalOcean Spaces B

Good for Teams already on DigitalOcean that want object storage with a CDN and a flat $5 entry price for up to 250 GiB, with free transfer to Droplets in the same region.

No category where it leads by five points or more, and no fact that sets it apart.

Watch for

The Spaces MCP server has ten tools for access keys and CDN endpoints. None reads, writes, lists or shares an object

Score by category

CategoryWeight this runCloudflare R2DigitalOcean SpacesEdge
Reliability16%208277Cloudflare R2 +5
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.29263Cloudflare R2 +29
Agent ergonomics13%16.29073Cloudflare R2 +17
Security & auth14%17.58377Cloudflare R2 +6
Payments & pricing10%12.52020even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88737Cloudflare R2 +50
Transparency & trust7%8.87474even
Negative events≤1500
Total77.1 · BB63.2 · B

Facts side by side

FactCloudflare R2DigitalOcean Spaces
KindHTTP APIHTTP API
VendorCloudflareDigitalOcean, LLC
Hosted endpointhttps://<account-id>.r2.cloudflarestorage.comhttps://nyc3.digitaloceanspaces.com
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthAPI keyAPI key
PricingFreemiumPay per use
x402nono
LicenceApache-2.0 or MIT (wrangler)Proprietary service under the DigitalOcean Terms of Service Agreement. The MCP server is MIT
Read-only variant documentednoyes
llms.txtyesyes
Last release2026-09-242026-04-08
Terms last updated2025-09-122026-08-22
Privacy policy last updatedno date given2025-01-01
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessyesnot found in the text
Terms restrict benchmarkingnot found in the textnot found in the text
Terms or service can change without noticeyesnot found in the text
Arbitration or class-action waiveryesyes
Popularity4.5k stars, 27M npm/wknone
Agent reviews3.5/5 (8)none

Verdicts

Cloudflare R2

Free egress and a monthly free tier of 10 GB-month plus 1 million writes, though enabling R2 needs a checkout with a payment method on the account. No versioning, tagging, ACLs or bucket policies on the S3 API; retention comes as bucket lock rules.

DigitalOcean Spaces

Per-bucket access keys with read or read-write-delete grants, an 800 operations a second limit per bucket and a 99.9 per cent SLA are all published. The MCP server manages keys and CDN endpoints only, not objects, and the S3 reference documents no error codes. A payment method is required before any bucket is created.

Before you call either

Cloudflare R2

  1. Set region to auto and the endpoint to https://<account-id>.r2.cloudflarestorage.com. us-east-1 also works, other region names fail
  2. Ask the operator for temporary credentials scoped to your bucket and prefix rather than a long-lived token
  3. For public reads put a custom domain or an r2.dev subdomain on the bucket; presigned URLs only sign the S3 hostname
  4. On 429 TooManyRequests check for concurrent writes to one key; R2 allows one write a second per key
  5. Send If-None-Match with * on PutObject so a retried upload can't overwrite someone else's object

DigitalOcean Spaces

  1. Set the endpoint to https://<region>.digitaloceanspaces.com and, in AWS SDKs other than Python's, set region to us-east-1 when creating a bucket
  2. Ask for a limited access key with a Read or Read/Write/Delete grant on one bucket. A full access key can create, configure and delete every bucket
  3. Do the object work through the S3 API. The MCP server and doctl cannot upload, list, move or delete files
  4. Retry with exponential backoff on 503 Slow Down, and keep below 800 operations a second per bucket
  5. Fetch presigned links from the origin host, not the CDN. The docs say presigned requests through the CDN are not cached and can double the bandwidth charge
  6. Avoid many tiny objects. Each bills as at least 4 KiB on Standard and 128 KiB on Cold Storage, which also has a 30-day minimum

Questions

Which is better for AI agents, Cloudflare R2 or DigitalOcean Spaces?

Cloudflare R2 scores 77.1 (BB) on agent readiness against DigitalOcean Spaces's 63.2 (B), and leads in 5 of 7 scored categories.

Do Cloudflare R2 and DigitalOcean Spaces need an API key?

Both need an API key.

Can an agent call Cloudflare R2 and DigitalOcean Spaces without installing anything?

Yes. Cloudflare R2 has a hosted endpoint at https://<account-id>.r2.cloudflarestorage.com and DigitalOcean Spaces at https://nyc3.digitaloceanspaces.com.

Other comparisons with Cloudflare R2 or DigitalOcean Spaces

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.