Azure Blob Storage

by Microsoft Corporation HTTP API in File storage & sharing

Hosted Agent-ready

Microsoft Corporation · microsoft.com since 1991 · status page · who's behind it

Microsoft Azure's object storage for files, backups and application data. Agents call a REST API or the Azure SDKs on a storage account, signing in with Microsoft Entra ID, an account key or a shared access signature.

Good for Agents and runtimes already on Azure, where a managed identity writes to one container with no stored key, and jobs that need tiers, immutability or geo-redundant copies.

Is this your product? Claim this listing or verify it

More from Microsoft Corporation Microsoft Foundry fine-tuning (Azure OpenAI) (Fine-tuning) · Azure AI Content Safety (Prompt Shields) (Guardrails) · Azure AI Speech speech-to-text (STT) · Azure AI Speech text-to-speech (TTS) · Microsoft Agent Framework (Frameworks) · Microsoft Execution Containers (Sandboxes) · Microsoft Entra Agent ID (Agent auth) · Azure Key Vault (Secrets) · Azure Document Intelligence (Documents) · Azure DevOps MCP Server (Code) · Microsoft Learn MCP Server (Code) · Playwright MCP (Browser) · Azure MCP Server (Infra) · Azure Maps (Maps) · Azure Translator (Translation) · Microsoft Graph Calendar API (Scheduling) · OneDrive and SharePoint files (Microsoft Graph) (Storage) · Microsoft Teams (Microsoft Graph) (Work) · Microsoft Dynamics 365 Sales (CRM) · Microsoft Power Automate (Workflows) · Foundry Local (Local AI) · Microsoft Advertising API (Advertising) · Microsoft Excel (Microsoft Graph workbook API) (Spreadsheets) · Outlook Mail (Microsoft Graph) (Mailboxes)

Assessment. Microsoft Entra ID roles can be scoped to one container, and a user delegation signature hands out a link that expires within seven days. Account keys with full access stay enabled until the owner turns them off, request logs are off until configured, and an Azure account needs a person, a phone number and a payment card.

Facts

Transport
HTTP
Endpoint
https://<account>.blob.core.windows.net
Auth
OAuth or key
Pricing
Pay per use · $0.005 / 1k req
x402
No
Licence
Proprietary service under Microsoft's Product Terms. The Azure SDK client libraries are MIT
Packages
pypi azure-storage-blob
npm @azure/storage-blob
llms.txt
not found
Last release
npm / week
12.5M
PyPI / week
22.6M
API
REST at https://<account>.blob.core.windows.net, 42 documented operations on accounts, containers and blobs, XML bodies and x-ms- headers. Newest service version 2026-10-06, sent in x-ms-version. Accounts are created through Azure Resource Manager
Credentials
Microsoft Entra ID bearer tokens with Azure roles, Shared Key with one of the account's access keys, or a shared access signature in the URL. Anonymous read is possible where the owner enables it
Roles
Storage Blob Data Reader, Contributor and Owner, and Storage Blob Delegator for the user delegation key, assignable on a container, account, resource group or subscription. Attribute-based conditions narrow them further
Expiring links
User delegation SAS signed with a key from Get User Delegation Key, valid at most seven days, limited by sp permissions, sip address range and spr protocol. A service SAS tied to a stored access policy can be revoked, with five policies a container
Request rates
20,000 requests a second per standard account by default, 40,000 in 29 named regions, 3,000 a second on one block blob. 503 Server Busy or 500 Operation Timeout past a partition's limit
Object limits
Block blob about 190.7 TiB (50,000 blocks of up to 4,000 MiB), 5,000 MiB in one Put Blob, append blob about 195 GiB, page blob 8 TiB
Listing
List Blobs returns up to 5,000 items a page with prefix, delimiter, marker and optional include datasets. Find Blobs by Tags queries index tags. Arrow output from version 2026-06-06
Deletion
Blob soft delete keeps deleted or overwritten data for 1 to 365 days once enabled, and Undelete Blob restores it. Time-based retention and legal holds make blobs write-once
Audit
Azure Monitor resource logs in the StorageRead, StorageWrite and StorageDelete categories, with caller IP address. Not collected until a diagnostic setting is created
SLA
Hot tier, 99.9% for reads and writes and 99.99% for reads on RA-GRS and RA-GZRS accounts. Cool, cold and archive, 99% for writes and 99.9% for reads. Credits of 10% and 25%
Tiers and redundancy
Hot, cool, cold and archive tiers. LRS, ZRS, GRS, GZRS and the read-access forms of the last two. LRS keeps replicas inside one region
SDKs
Python azure-storage-blob 12.31.0 (30 September 2026, Python 3.10 or later) and JavaScript @azure/storage-blob 12.34.0 (Node 22 or later), both MIT. The Python client retries with exponential backoff by default, three times from 15 seconds
MCP server
None dedicated. The Azure MCP Server, listed separately, has four Blob tools for containers, blob properties and upload

Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • Microsoft Entra ID roles such as Storage Blob Data Reader can be assigned on one container, with no stored key for workloads on Azure
  • A user delegation shared access signature is signed with Entra credentials, lasts at most seven days and can be limited by permission, IP address and protocol
  • SLA of 99.9 per cent on the hot tier, 99.99 per cent for reads on RA-GRS accounts, in the 1 October 2026 SLA document
  • Public OpenAPI 2.0 contract with 69 operations for service version 2026-10-06, and Learn pages returned as Markdown on request
  • Conditional headers, leases, soft delete of 1 to 365 days and immutability policies protect against a wrong overwrite or delete

Weaknesses

  • Shared Key authorisation with the account's access keys is allowed until the owner sets AllowSharedKeyAccess to false
  • Request logs are not collected until a diagnostic setting routes the StorageRead, StorageWrite and StorageDelete categories somewhere
  • Requests and responses use headers and XML, and every authorised call must carry x-ms-version
  • The pricing page draws its numbers by script, so an agent reading it sees no price. The Retail Prices API has them
  • An Azure account needs a phone number and a credit or debit card, and no free Blob Storage allowance could be read

Before you call it notes for agents

  1. Request an Entra ID token for https://storage.azure.com/ and send it as a Bearer header with x-ms-version and x-ms-date. Put Blob also needs x-ms-blob-type: BlockBlob
  2. Ask for a Storage Blob Data role on the one container. Role changes can take up to 10 minutes to apply
  3. To share a file, call Get User Delegation Key, then sign a SAS with sp=r, spr=https and a short expiry. Treat the URL as a secret
  4. Send If-None-Match: * on Put Blob so a retry can't overwrite a blob another call wrote
  5. On 503 ServerBusy back off exponentially. After 500 OperationTimedOut check the blob's state before retrying, since the write may have succeeded

Who's behind it provenance 86/100

  • Legal entity namedMicrosoft Corporation20/20
  • Domain agemicrosoft.com, registered 1991-05-02 (35 years)15/15
  • Endpoint on the vendor's domain<account>.blob.core.windows.net15/15
  • Terms of serviceread, states 4 of the 7 things a reader expects, and has 2 clauses that cost points3.4/10
  • Privacy policyread, states 8 of the 8 things a reader expects, and has 1 clause that costs points8/10
  • Status pageazure.status.microsoft/en-us/status10/10
  • Changelogpublished10/10
  • security.txtpublished but past its Expires date5/10

Terms and privacy, as read

Terms of service gives no date, states 4 of 7, 2 to know

TL;DR Gives no date. States 4 of the 7 things a reader expects, and we didn't find the governing law or how changes are announced. To know before relying on it, limits on automated access and limits on benchmarking.

Restricts automated accesscosts points
Customer may not use web scraping, web harvesting, or other data extraction methods to extract data from a Microsoft Generative AI Service.

A rule against bots, scrapers or automated means can cover an agent, depending on how the vendor reads it.

Restricts benchmarking or competitive usecosts points
If Customer offers a product or service competitive to an Online Service, by using the Online Service, Customer waives any restrictions on competitive use and benchmark testing in the terms governing its competitive products and services.

A clause against publishing test results or using the service to build something that competes.

Gives the date it was last updated

Not found in the text.

Without a date nobody can tell which version they agreed to.

Names the governing law or courts

Not found in the text.

Says where a dispute would be heard and under whose law.

States a limit on its liability
…no responsibility or liability for any losses or damages due to performance issues (including but not limited to security vulnerabilities, data loss, or service interruptions) of a Product that customer uses after the end of the applicable support period as provided in the Product Support Lifecycle [https://learn.micr…

Says the most the vendor would owe if the service causes a loss.

Says how the agreement or account can be ended
If Microsoft suspends the Online Service, Microsoft will suspend only to the extent reasonably necessary.

Says when the vendor can cut off access and what notice it gives.

Says how changes to the terms are announced

Not found in the text.

Says whether a customer hears about a change before it binds them.

Lists what users may not do
Except as permitted in this paragraph or in the Online Service-specific Terms, Customer may not reassign an SL on a short-term basis (i.e., within 90 days of the last assignment).

The acceptable-use rules an agent acting for a user has to stay inside.

Refers to a service level or uptime commitment
Many Online Services offer a Service Level Agreement (SLA).

Says whether availability is promised and where the promise is written.

A subscription that is not renewed can continue month by month, and Microsoft may invoice that period at the monthly price plus a three per cent uplift for certain Products.
Microsoft reserves the right to invoice Customer for the Extended Term at the then-current published price for a monthly subscription plus a three (3) percent uplift for certain Products.

Noted by a second reader on 2026-10-08.

After an account is disabled, the customer has 90 days to extract Customer Data and the subscription cannot be reactivated.
Customer will have 90 days to extract Customer Data from a disabled account, but the Subscription cannot be reactivated.

Noted by a second reader on 2026-10-08.

The customer is responsible for any application or AI agent it creates with Microsoft AI Services, including legal, regulatory and licensing compliance.
Customer is responsible for the design, development and use of any application or AI agent it creates using or for use with Microsoft AI Services, including complying with any legal, regulatory, or licensing requirements applicable to the resulting application or AI agent or its use.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 5,677 words

Privacy policy dated 2026-09-01, states 8 of 8, 2 to know

TL;DR Dated 2026-09-01. States all 8 things a reader expects. To know before relying on it, model training with no opt-out found and selling or sharing data for advertising.

Says it may use customer content to train or improve models, and no opt-out was foundcosts points
As part of our efforts to improve and develop our products, we may use your data to develop and train our AI models.

Content an agent sends could end up in a model. An opt-out, where the document gives one, is shown instead.

Says it sells personal data or shares it for advertising
We also disclose personal data for digital advertising purposes.

Personal data is passed to advertising partners, or the document says its sharing may count as a sale under privacy law.

Gives the date it was last updated Last updated 2026-09-01
Last Updated: September 2026

Without a date nobody can tell which version applied when data was collected.

Says what personal data is collected
The data we collect depends on the context of your interactions with Microsoft and the choices you make, including your privacy settings and the products and features you use.

The basic statement a privacy policy exists to make.

Says how long data is kept Names a period of 7 days
When you delete an email or item from a mailbox in Outlook.com, the item generally goes into your Deleted Items folder where it remains for approximately 7 days unless you move it back to your inbox, you empty the folder, or the service empties the folder automatically, whichever comes first.

Says when data sent to the service is deleted.

Says who else receives the data
Service providers that help us determine your device’s location.

Names the sub-processors or service providers the data is passed to, or where they are listed.

Says whether personal data is sold or shared for advertising
not use or share student personal data for advertising or similar commercial purposes, such as providing personalized advertising to students;

A plain statement either way.

Says what rights people have over their data
State Data Privacy Notice (including notice at collection details) and the Consumer Health Data Privacy Policy for additional information about your rights and the processing of your personal data.

Access, correction, deletion and objection, and how to use them.

Gives a privacy contact Names a data protection officer
If you have a privacy concern, complaint, or question for the Microsoft privacy team or Data Protection Officer, please visit our privacy support and requests page and click on “Contact the Microsoft privacy team or the Microsoft Data Protection Officer” menu.

An address or officer to send a request to.

Says where data is transferred or stored Relies on standard contractual clauses
In such cases, we implement legal safeguards-such as standard contractual clauses approved by the European Commission – to help protect your rights and ensure your data remains protected.

The countries data goes to and the safeguard used.

For enterprise and developer products, the customer's agreement with Microsoft takes precedence over this privacy statement where the two conflict.
In the event of a conflict between our privacy statement and the terms of any agreement(s) between a customer and Microsoft for Enterprise and Developer Products, the terms of those agreement(s) will control.

Noted by a second reader on 2026-10-08.

Prompts and related data sent to the consumer Microsoft Copilot are used to improve services and for relevant advertising.
Microsoft Copilot also uses prompts and related data to provide and improve services, including relevant advertising.

Noted by a second reader on 2026-10-08.

Microsoft staff manually review some results of its automated systems, including AI, against the source data.
For example, to build, train, and improve the accuracy of our automated systems – such as AI - we manually review some of the results against the underlying data.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 33,580 words

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

Accounts answer at <account>.blob.core.windows.net, as Microsoft's REST reference gives it. RDAP shows windows.net registered on 1995-08-10. Docs are on learn.microsoft.com.

The Product Terms for Online Services cover Microsoft Azure, carry an acceptable use policy and a competitive benchmarking clause, and point to the Data Protection Addendum. The page showed no effective date when read on 8 October 2026.

Self-serve Azure accounts also accept the Microsoft Online Subscription Agreement (last updated March 2019, Microsoft Corporation, Washington law) at https://azure.microsoft.com/en-us/support/legal/subscription-agreement/, which incorporates the Online Services Terms and the SLAs.

The privacy statement (last updated September 2026) names Microsoft Corporation, One Microsoft Way, Redmond, Washington 98052, and Microsoft Ireland Operations Limited. It lists Microsoft Azure among the enterprise online services covered by the Product Terms.

The Data Protection Addendum read is the English edition of 22 May 2026, a Word file linked from https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA.

https://www.microsoft.com/.well-known/security.txt shows Expires 2026-09-23T16:00:00.000Z. It points to the MSRC researcher portal, the bounty policy and the coordinated disclosure policy.

RDAP gives 1991-05-02 for microsoft.com and 1995-08-10 for windows.net. The registry record does not name a registrant.

The versioning page is dated 23 September 2026 and each service version has its own page of changes.

Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-09 08:59 UTC

Right nowDownn/a · 6 minutes ago
Uptime 24h0.0%15 probes
Uptime 30 days0.0%15 probes
p50 24hn/aget
p95 24hn/aopen endpoint

Probed every five minutes at https://<account>.blob.core.windows.net. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials. Last note, DNS lookup failed.

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/azure-blob-storage.json

Notable

  • The Blob REST API lists 42 operation pages on accounts, containers and blobs, and the OpenAPI 2.0 document for service version 2026-10-06 has 69 operations source source 2
  • As of 23 September 2026 the latest fully deployed service version is 2026-04-06, with 2026-06-06 and 2026-10-06 enabled in almost every region. The newest SDKs default to 2026-10-06 source
  • A standard account has a default target of 20,000 requests a second, 40,000 in 29 named regions, and a single block blob up to 3,000 a second. Past a partition's limit the service answers 503 Server Busy or 500 Operation Timeout source source 2
  • A block blob can reach about 190.7 TiB (50,000 blocks of 4,000 MiB). One Put Blob call takes up to 5,000 MiB source
  • Get User Delegation Key returns a key valid for at most seven days, and a user delegation SAS grants the intersection of its sp permissions and the signer's role source source 2
  • The AllowSharedKeyAccess property is not set by default, and the account accepts Shared Key requests while it is null or true source
  • General-purpose v1 accounts retire in October 2026. Microsoft announced it in September 2025, stopped new v1 accounts in September 2026 and migrates the rest to v2 itself source
  • Microsoft's Azure MCP Server, listed separately, has four Blob tools (container create, container get, blob get, blob upload), each marked read-only or destructive source
  • https://www.microsoft.com/.well-known/security.txt shows Expires 2026-09-23T16:00:00.000Z, which had passed on 8 October 2026
  • The Product Terms' competitive benchmarking clause asks a customer that sells a competing service and publishes a benchmark of an Online Service to give Microsoft the information needed to replicate it source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 17.6
Hosted reading. Azure status page with a history of post-incident reviews (20). The history lists three incidents in the last 90 days, West US network connectivity on 23 July 2026 (14:44 to 19:41 UTC), Azure OpenAI and Cognitive Services on 29 September, and gateway services in several regions from 30 September to 1 October. None names Storage. The page lists only broad incidents and the West US fault blocked traffic entering or leaving that region, so we count the record as minor (20 of 30). Targets published with numbers, 20,000 requests a second per standard account, 40,000 in 29 named regions, and 3,000 a second on one block blob (15). 503 Server Busy and 500 Operation Timeout are documented with advice to back off exponentially, the Python client retries three times by default, and If-None-Match: * makes a retried write safe. No Retry-After header was found in the pages read (13 of 15). The SLA document of 1 October 2026 commits to 99.9 per cent on the hot tier, 99.99 per cent for reads on RA-GRS accounts, with 10 and 25 per cent credits (10). Generally available (10).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 13.8
A public OpenAPI 2.0 document for service version 2026-10-06 with 69 operations, each with a description (25). learn.microsoft.com/llms.txt returns 404, but every Learn page we asked for with Accept: text/markdown came back as Markdown, so half (5 of 10). Reference pages state each operation's purpose, permissions, limits by version and billing category, and seldom say when not to use one. Several are dated 2023 (15 of 20). The contract types 117 parameters, 15 with enums, but most inputs travel as headers or XML and metadata is free-form (12 of 15). Sample requests and responses on the reference pages, a table of 70-odd Blob error codes with HTTP status and message, and a 114-value error code enum in the contract. The contract carries no examples (13 of 15). Dated x-ms-version values, a versioning page updated 23 September 2026 with deployment by region, and a page of changes for each version (15).
Agent ergonomics 13%16.2 13.7
API reading, since Blob Storage has no MCP server of its own. List Blobs caps a page at 5,000 items, returns metadata, tags, versions and snapshots only when include asks, and Get Blob takes a Range. Responses are XML with no field selection (20 of 25). Paging by marker and NextMarker, prefix and delimiter filters, and Find Blobs by Tags (20). Errors carry a code and a message, 70-odd Blob codes are documented, and a 503 says which account limit was passed (16 of 20). Conditional headers, leases and soft delete make retries and mistakes recoverable. x-ms-client-request-id correlates logs and is not an idempotency key. The Azure MCP Server, a separate listing, marks its four Blob tools read-only or destructive (16 of 20). Official Python and JavaScript SDKs were checked on their registries, and the Python client retries by default. A REST call needs x-ms-version, x-ms-date and, for uploads, x-ms-blob-type (12 of 15).
Security & auth 14%17.5 14.2
Microsoft Entra ID OAuth 2.0 tokens with Azure roles, managed identities on Azure, and user delegation signatures limited to seven days. Account access keys with full access are accepted until the owner disallows Shared Key. A SAS travels in the URL query string. It is a signature over stated permissions and an expiry, not the account key, so we read it as we read S3 presigned URLs and take no deduction, though Microsoft's docs say to protect a SAS like an account key (28 of 30). Storage Blob Data Reader for read-only work, roles on one container, attribute conditions, soft delete of 1 to 365 days, immutability policies and legal holds. Nothing asks for approval on a write or delete (17 of 20). The service returns whatever bytes were stored, and no guidance on treating blob contents as untrusted was found (8 of 15). Resource logs record reads, writes and deletes with caller IP address, but only after the owner adds a diagnostic setting (12 of 15). MSRC coordinated disclosure and bounty policies and a SOC 2 Type 2 report covering Azure. The microsoft.com security.txt passed its Expires date on 23 September 2026, and the audit scope page we loaded did not name services (16 of 20).
Payments & pricing 10%12.5 2.5
No x402, MPP or L402 (0). Per-GB and per-operation prices are public through the Azure Retail Prices API, while the pricing page fills its numbers by script (20). The Azure free account needs a credit or debit card, and no free Blob Storage allowance could be read (0). A person signs up in a browser with a phone number and a card (0).
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 7.0
Read as a closed service with official SDKs. azure-storage-blob 12.31.0 reached PyPI on 30 September 2026, and the versioning page was updated on 23 September (30). Four Python releases in the last 90 days, 12.30.1 on 27 August, 12.30.2 on 16 September, 12.30.3 on 22 September and 12.31.0 on 30 September (20). A versioning page and per-version change pages, Microsoft Q&A and the SDK issue trackers on GitHub, which we did not read (10 of 15). Official SDKs current in Python (12.31.0) and JavaScript (12.34.0) (15). The SDKs are released from the azure-sdk monorepos, CI not checked (5 of 10).
Transparency & trusteditorial 73, provenance 86 7%8.8 7.0
Closed service under Microsoft's Product Terms, with MIT client libraries and a public API contract (15 of 30). The privacy statement, last updated September 2026, sends Azure customer data to the Product Terms and the Data Protection Addendum. The addendum of 22 May 2026 keeps customer data for 90 days after a subscription ends and deletes it within a further 90, and the redundancy docs say LRS replicates only inside the chosen region. These agree (26 of 30). The Modern Lifecycle Policy promises 12 months' notice before support ends, and the general-purpose v1 account retirement was announced in September 2025 for October 2026 (18 of 20). The addendum promises six months' notice of a new sub-processor, and data location follows the region and redundancy option chosen. The sub-processor list sits on the Service Trust Portal, a script-drawn page we could not read (14 of 20).
Negative events≤15None recorded0
Total75.7 · BB

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 22 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Azure Blob Storage, or have the agent fetch /fixes/azure-blob-storage.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: Azure Blob Storage

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/azure-blob-storage, the October 2026 research run, assessed 8 October 2026. Grade BB, 75.7 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on Azure Blob Storage: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Payments & pricing, 20 out of 100, up to 10 more on the total

Why it scored 20: No x402, MPP or L402 (0). Per-GB and per-operation prices are public through the Azure Retail Prices API, while the pricing page fills its numbers by script (20). The Azure free account needs a credit or debit card, and no free Blob Storage allowance could be read (0). A person signs up in a browser with a phone number and a card (0).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 2. Security & auth, 81 out of 100, up to 3.3 more on the total

Why it scored 81: Microsoft Entra ID OAuth 2.0 tokens with Azure roles, managed identities on Azure, and user delegation signatures limited to seven days. Account access keys with full access are accepted until the owner disallows Shared Key. A SAS travels in the URL query string. It is a signature over stated permissions and an expiry, not the account key, so we read it as we read S3 presigned URLs and take no deduction, though Microsoft's docs say to protect a SAS like an account key (28 of 30). Storage Blob Data Reader for read-only work, roles on one container, attribute conditions, soft delete of 1 to 365 days, immutability policies and legal holds. Nothing asks for approval on a write or delete (17 of 20). The service returns whatever bytes were stored, and no guidance on treating blob contents as untrusted was found (8 of 15). Resource logs record reads, writes and deletes with caller IP address, but only after the owner adds a diagnostic setting (12 of 15). MSRC coordinated disclosure and bounty policies and a SOC 2 Type 2 report covering Azure. The microsoft.com security.txt passed its Expires date on 23 September 2026, and the audit scope page we loaded did not name services (16 of 20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 3. Agent ergonomics, 84 out of 100, up to 2.6 more on the total

Why it scored 84: API reading, since Blob Storage has no MCP server of its own. List Blobs caps a page at 5,000 items, returns metadata, tags, versions and snapshots only when `include` asks, and Get Blob takes a `Range`. Responses are XML with no field selection (20 of 25). Paging by `marker` and `NextMarker`, `prefix` and `delimiter` filters, and Find Blobs by Tags (20). Errors carry a code and a message, 70-odd Blob codes are documented, and a 503 says which account limit was passed (16 of 20). Conditional headers, leases and soft delete make retries and mistakes recoverable. `x-ms-client-request-id` correlates logs and is not an idempotency key. The Azure MCP Server, a separate listing, marks its four Blob tools read-only or destructive (16 of 20). Official Python and JavaScript SDKs were checked on their registries, and the Python client retries by default. A REST call needs `x-ms-version`, `x-ms-date` and, for uploads, `x-ms-blob-type` (12 of 15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 4. Reliability, 88 out of 100, up to 2.4 more on the total

Why it scored 88: Hosted reading. Azure status page with a history of post-incident reviews (20). The history lists three incidents in the last 90 days, West US network connectivity on 23 July 2026 (14:44 to 19:41 UTC), Azure OpenAI and Cognitive Services on 29 September, and gateway services in several regions from 30 September to 1 October. None names Storage. The page lists only broad incidents and the West US fault blocked traffic entering or leaving that region, so we count the record as minor (20 of 30). Targets published with numbers, 20,000 requests a second per standard account, 40,000 in 29 named regions, and 3,000 a second on one block blob (15). 503 Server Busy and 500 Operation Timeout are documented with advice to back off exponentially, the Python client retries three times by default, and `If-None-Match: *` makes a retried write safe. No Retry-After header was found in the pages read (13 of 15). The SLA document of 1 October 2026 commits to 99.9 per cent on the hot tier, 99.99 per cent for reads on RA-GRS accounts, with 10 and 25 per cent credits (10). Generally available (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## 5. Schema & documentation, 85 out of 100, up to 2.4 more on the total

Why it scored 85: A public OpenAPI 2.0 document for service version 2026-10-06 with 69 operations, each with a description (25). learn.microsoft.com/llms.txt returns 404, but every Learn page we asked for with `Accept: text/markdown` came back as Markdown, so half (5 of 10). Reference pages state each operation's purpose, permissions, limits by version and billing category, and seldom say when not to use one. Several are dated 2023 (15 of 20). The contract types 117 parameters, 15 with enums, but most inputs travel as headers or XML and metadata is free-form (12 of 15). Sample requests and responses on the reference pages, a table of 70-odd Blob error codes with HTTP status and message, and a 114-value error code enum in the contract. The contract carries no examples (13 of 15). Dated `x-ms-version` values, a versioning page updated 23 September 2026 with deployment by region, and a page of changes for each version (15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## 6. Maintenance & community, 80 out of 100, up to 1.8 more on the total

Why it scored 80: Read as a closed service with official SDKs. azure-storage-blob 12.31.0 reached PyPI on 30 September 2026, and the versioning page was updated on 23 September (30). Four Python releases in the last 90 days, 12.30.1 on 27 August, 12.30.2 on 16 September, 12.30.3 on 22 September and 12.31.0 on 30 September (20). A versioning page and per-version change pages, Microsoft Q&A and the SDK issue trackers on GitHub, which we did not read (10 of 15). Official SDKs current in Python (12.31.0) and JavaScript (12.34.0) (15). The SDKs are released from the azure-sdk monorepos, CI not checked (5 of 10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## 7. Transparency & trust, 80 out of 100, up to 1.8 more on the total

Made of editorial 73, provenance 86.

Why it scored 80: Closed service under Microsoft's Product Terms, with MIT client libraries and a public API contract (15 of 30). The privacy statement, last updated September 2026, sends Azure customer data to the Product Terms and the Data Protection Addendum. The addendum of 22 May 2026 keeps customer data for 90 days after a subscription ends and deletes it within a further 90, and the redundancy docs say LRS replicates only inside the chosen region. These agree (26 of 30). The Modern Lifecycle Policy promises 12 months' notice before support ends, and the general-purpose v1 account retirement was announced in September 2025 for October 2026 (18 of 20). The addendum promises six months' notice of a new sub-processor, and data location follows the region and redundancy option chosen. The sub-processor list sits on the Service Trust Portal, a script-drawn page we could not read (14 of 20).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- Terms of service: read, states 4 of the 7 things a reader expects, and has 2 clauses that cost points (3.4 of 10)
- Privacy policy: read, states 8 of the 8 things a reader expects, and has 1 clause that costs points (8 of 10)
- security.txt: published but past its Expires date (5 of 10)

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- The lead was right on the interface and the docs. Its URL redirects to https://azure.microsoft.com/en-us/products/storage/blobs, and the contracting entity is Microsoft Corporation.
- unchecked: a free Blob Storage allowance. The free services page lists its services by script and the free account page names none for Blob Storage.
- unchecked: the internet egress (bandwidth) rate, which is a separate Azure meter and was not read.
- unchecked: whether Storage is on Azure's SOC 2 audit scope list. The scope page we loaded did not name services, and the reports sit on the Service Trust Portal.
- unchecked: the Microsoft sub-processor list. The Service Trust Portal page is drawn by script.
- unchecked: incidents limited to one region or to Storage alone, since the public status history lists only broad incidents.
- unchecked: MSRC advisories for Azure Storage in the last 12 months, and CI and open issues for the azure-sdk repositories.
- unchecked: the .NET, Java and Go client libraries, which were not looked up on their registries.
- Not established: whether 503 responses carry a Retry-After header, whether throttled or failed calls are billed, and whether new accounts have blob soft delete on by default.
- The specs repository has a stable folder named 2026-12-06 whose document still gives its version as 2026-10-06. The versioning page does not mention 2026-12-06.
- A judgement call. We took no deduction for SAS tokens in the URL query string, to match the Amazon S3 reading of presigned URLs. Microsoft's docs tell users to protect a SAS like an account key, so a stricter reading takes 10 off Security.
- The Product Terms page showed no effective date when read. Its competitive benchmarking clause is recorded as a fact with no deduction.

## Weaknesses

- Shared Key authorisation with the account's access keys is allowed until the owner sets `AllowSharedKeyAccess` to false
- Request logs are not collected until a diagnostic setting routes the StorageRead, StorageWrite and StorageDelete categories somewhere
- Requests and responses use headers and XML, and every authorised call must carry `x-ms-version`
- The pricing page draws its numbers by script, so an agent reading it sees no price. The Retail Prices API has them
- An Azure account needs a phone number and a credit or debit card, and no free Blob Storage allowance could be read

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Request an Entra ID token for https://storage.azure.com/ and send it as a Bearer header with `x-ms-version` and `x-ms-date`. Put Blob also needs `x-ms-blob-type: BlockBlob`
- Ask for a Storage Blob Data role on the one container. Role changes can take up to 10 minutes to apply
- To share a file, call Get User Delegation Key, then sign a SAS with `sp=r`, `spr=https` and a short expiry. Treat the URL as a secret
- Send `If-None-Match: *` on Put Blob so a retry can't overwrite a blob another call wrote
- On 503 ServerBusy back off exponentially. After 500 OperationTimedOut check the blob's state before retrying, since the write may have succeeded

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • The lead was right on the interface and the docs. Its URL redirects to https://azure.microsoft.com/en-us/products/storage/blobs, and the contracting entity is Microsoft Corporation.
  • unchecked: a free Blob Storage allowance. The free services page lists its services by script and the free account page names none for Blob Storage.
  • unchecked: the internet egress (bandwidth) rate, which is a separate Azure meter and was not read.
  • unchecked: whether Storage is on Azure's SOC 2 audit scope list. The scope page we loaded did not name services, and the reports sit on the Service Trust Portal.
  • unchecked: the Microsoft sub-processor list. The Service Trust Portal page is drawn by script.
  • unchecked: incidents limited to one region or to Storage alone, since the public status history lists only broad incidents.
  • unchecked: MSRC advisories for Azure Storage in the last 12 months, and CI and open issues for the azure-sdk repositories.
  • unchecked: the .NET, Java and Go client libraries, which were not looked up on their registries.
  • Not established: whether 503 responses carry a Retry-After header, whether throttled or failed calls are billed, and whether new accounts have blob soft delete on by default.
  • The specs repository has a stable folder named 2026-12-06 whose document still gives its version as 2026-10-06. The versioning page does not mention 2026-12-06.
  • A judgement call. We took no deduction for SAS tokens in the URL query string, to match the Amazon S3 reading of presigned URLs. Microsoft's docs tell users to protect a SAS like an account key, so a stricter reading takes 10 off Security.
  • The Product Terms page showed no effective date when read. Its competitive benchmarking clause is recorded as a fact with no deduction.

Sources 46

  1. Blob Storage REST API index learn.microsoft.com · seen 2026-10-08
  2. versioning and deployed service versions learn.microsoft.com · seen 2026-10-08
  3. previous service versions learn.microsoft.com · seen 2026-10-08
  4. authorisation options learn.microsoft.com · seen 2026-10-08
  5. Entra ID roles and scopes learn.microsoft.com · seen 2026-10-08
  6. preventing Shared Key authorisation learn.microsoft.com · seen 2026-10-08
  7. Get User Delegation Key learn.microsoft.com · seen 2026-10-08
  8. user delegation SAS learn.microsoft.com · seen 2026-10-08
  9. SAS overview and practices learn.microsoft.com · seen 2026-10-08
  10. Put Blob learn.microsoft.com · seen 2026-10-08
  11. Get Blob learn.microsoft.com · seen 2026-10-08
  12. List Blobs learn.microsoft.com · seen 2026-10-08
  13. Blob Batch learn.microsoft.com · seen 2026-10-08
  14. conditional headers learn.microsoft.com · seen 2026-10-08
  15. Blob error codes learn.microsoft.com · seen 2026-10-08
  16. common error codes learn.microsoft.com · seen 2026-10-08
  17. Blob scalability targets learn.microsoft.com · seen 2026-10-08
  18. standard account scalability targets learn.microsoft.com · seen 2026-10-08
  19. Python retry policy learn.microsoft.com · seen 2026-10-08
  20. soft delete learn.microsoft.com · seen 2026-10-08
  21. immutable storage learn.microsoft.com · seen 2026-10-08
  22. monitoring and resource logs learn.microsoft.com · seen 2026-10-08
  23. resource log reference learn.microsoft.com · seen 2026-10-08
  24. security recommendations learn.microsoft.com · seen 2026-10-08
  25. redundancy options learn.microsoft.com · seen 2026-10-08
  26. general-purpose v1 retirement learn.microsoft.com · seen 2026-10-08
  27. OpenAPI document, Blob 2026-10-06 raw.githubusercontent.com · seen 2026-10-08
  28. retail prices, East US prices.azure.com · seen 2026-10-08
  29. pricing page azure.microsoft.com · seen 2026-10-08
  30. product page azure.microsoft.com · seen 2026-10-08
  31. Azure free account azure.microsoft.com · seen 2026-10-08
  32. free services azure.microsoft.com · seen 2026-10-08
  33. SLA for Online Services, 1 October 2026 microsoft.com · seen 2026-10-08
  34. status history azure.status.microsoft · seen 2026-10-08
  35. security.txt microsoft.com · seen 2026-10-08
  36. Product Terms for Online Services microsoft.com · seen 2026-10-08
  37. Online Subscription Agreement azure.microsoft.com · seen 2026-10-08
  38. privacy statement microsoft.com · seen 2026-10-08
  39. Data Protection Addendum, 22 May 2026 microsoft.com · seen 2026-10-08
  40. Modern Lifecycle Policy learn.microsoft.com · seen 2026-10-08
  41. SOC 2 Type 2 page learn.microsoft.com · seen 2026-10-08
  42. Python SDK on PyPI pypi.org · seen 2026-10-08
  43. JavaScript SDK on npm registry.npmjs.org · seen 2026-10-08
  44. Azure MCP Server commands github.com · seen 2026-10-08
  45. authorising with Microsoft Entra ID learn.microsoft.com · seen 2026-10-08
  46. RDAP, windows.net rdap.verisign.com · seen 2026-10-08

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Pay per use $0.005 / 1k req Hot tier LRS storage is $0.0208 a GB-month for the first 50 TB in East US, cool $0.0152, cold $0.0036 and archive $0.00099. Hot write operations cost $0.05 per 10,000, list and create container operations $0.05, read and other operations $0.004. Cool and cold reads add a retrieval charge of $0.01 and $0.03 a GB. The pricing page draws its numbers by script and showed none, so these come from the Azure Retail Prices API (https://prices.azure.com/api/retail/prices?$filter=serviceName%20eq%20%27Storage%27%20and%20armRegionName%20eq%20%27eastus%27%20and%20productName%20eq%20%27General%20Block%20Blob%20v2%27). Internet egress is billed separately as bandwidth and its rate was not read. No free allowance for Blob Storage could be read, because the free services page lists its services by script. A new Azure account gets $200 of credit for 30 days and needs a phone number and a credit or debit card (https://azure.microsoft.com/en-us/pricing/purchase-options/azure-account).

Prices

ItemPriceUnitNote
Hot LRS storage, first 50 TB$0.0208per GB per monthEast US, general-purpose v2, from the Azure Retail Prices API
Cool LRS storage$0.0152per GB per monthEast US
Hot LRS write operations$0.005per 1,000 requests$0.05 per 10,000
Hot read operations$0.0004per 1,000 requests$0.004 per 10,000

Compared across listings on the price index.

Recent changes

  • Azure Blob Storage failed three probes in a row source
  • Latest release

Follow them as a feed at /feeds/tools/azure-blob-storage.xml, or this listing's score history at history.json.

Connect

Install

pip install azure-storage-blob azure-identity   # or: npm i @azure/storage-blob @azure/identity

First request

PUT https://myaccount.blob.core.windows.net/mycontainer/myblob
x-ms-version: 2026-04-06
x-ms-date: <date>
x-ms-blob-type: BlockBlob
Authorization: Bearer <Entra ID access token for https://storage.azure.com/>

Through letme picks today, calling later

GET https://letme.dev/azure-blob-storage

letme picks this listing for infra.azure, because it's the top-graded tool for the job.

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
Amazon S3 Amazon Web ServicesBB77.9storage.object storage.presigned storage.shareno
Cloudflare R2 CloudflareBB77.1storage.object storage.presigned storage.shareno
Backblaze B2 BackblazeBB75.3storage.object storage.presigned storage.shareno
Tigris Tigris DataE44.4storage.object storage.presigned storage.shareno
OneDrive and SharePoint files (Microsoft Graph) MicrosoftB65.3storage.share storage.presignedno
Bunny Storage bunny.netC58.3storage.object storage.presignedno

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    Azure Blob Storage on Anchor Terminal, BB, 75.7/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/azure-blob-storage"><img src="https://www.anchorterminal.com/badges/azure-blob-storage.svg" alt="Azure Blob Storage on Anchor Terminal" height="20"></a>
    [![Azure Blob Storage on Anchor Terminal](https://www.anchorterminal.com/badges/azure-blob-storage.svg)](https://www.anchorterminal.com/tools/azure-blob-storage)

    It counts on a page on microsoft.com or one of its subdomains, or the README of github.com/Azure/azure-rest-api-specs.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "azure-blob-storage", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.