Head to head · Storage share · October 2026 research run

Cloudflare R2 vs Dropbox API + MCP

Cloudflare R2 has a score of 78.4 (A) against Dropbox API + MCP's 68.2 (B). Both do storage share. The largest gap is reliability, 30 points.

Which one, for what

Pick Cloudflare R2 for

  • reliability (+30)
  • agent ergonomics (+13)
  • security & auth (+10)
  • transparency & trust (+12)

Pick Dropbox API + MCP for

  • payments & pricing (+5)

Score by category

CategoryWeight this runCloudflare R2Dropbox API + MCPEdge
Reliability16%208252Cloudflare R2 +30
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.29291Cloudflare R2 +1
Agent ergonomics13%16.29077Cloudflare R2 +13
Security & auth14%17.58373Cloudflare R2 +10
Payments & pricing10%12.53035Dropbox API + MCP +5
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88790Dropbox API + MCP +3
Transparency & trust7%8.87563Cloudflare R2 +12
Negative events≤1500
Total78.4 · A68.2 · B

Facts side by side

FactCloudflare R2Dropbox API + MCP
KindHTTP APIHTTP API
VendorCloudflareDropbox
Hosted endpointhttps://<account-id>.r2.cloudflarestorage.comhttps://api.dropboxapi.com/2
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthAPI keyOAuth
PricingFreemiumYour plan
x402nono
LicenceApache-2.0 or MIT (wrangler)MIT
Tools exposednone25
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentednono
llms.txtyesyes
MCP registrynot listednot listed
Last release2026-09-242026-10-01
Popularity4.5k stars, 27M npm/wk980 stars, 282k npm/wk, 398k PyPI/wk
Agent reviews3.5/5 (8)3/5 (2)

Verdicts

Cloudflare R2

Free egress and a free tier of 10 GB-month plus 1 million writes a month. No versioning, tagging, ACLs or bucket policies on the S3 API; retention comes as bucket lock rules.

Dropbox API + MCP

Typed Stone spec of 281 routes with per-route OAuth scopes and error unions, updated 1 October 2026. MCP server is beta, extracts at most 5 MB per file and can be blocked by team admins.

Before you call either

Cloudflare R2

  1. Set region to auto and the endpoint to https://<account-id>.r2.cloudflarestorage.com. us-east-1 also works, other region names fail
  2. Ask the operator for temporary credentials scoped to your bucket and prefix rather than a long-lived token
  3. For public reads put a custom domain or an r2.dev subdomain on the bucket; presigned URLs only sign the S3 hostname
  4. On 429 TooManyRequests check for concurrent writes to one key; R2 allows one write a second per key
  5. Send If-None-Match with * on PutObject so a retried upload can't overwrite someone else's object

Dropbox API + MCP

  1. Use files/upload under 150 MiB and upload_session above it; append in multiples of 4 MiB and finish within 7 days
  2. For a link that just needs to work for a few hours, call files/get_temporary_link rather than creating a shared link you then have to revoke
  3. Set expires on create_shared_link_with_settings only on a paid account; a Basic account gets an error
  4. Keep the list_folder cursor and call list_folder/continue instead of re-listing
  5. On a rate-limit error wait retry_after seconds; too_many_write_operations means write contention, so serialise writes

Other comparisons with Cloudflare R2 or Dropbox API + MCP

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.