# Azure Blob Storage > Microsoft Azure's object storage for files, backups and application data. Agents call a REST API or the Azure SDKs on a storage account, signing in with Microsoft Entra ID, an account key or a shared access signature. - Canonical: https://www.anchorterminal.com/tools/azure-blob-storage - Markdown: https://www.anchorterminal.com/tools/azure-blob-storage.md (~10,700 tokens) - Slim: https://www.anchorterminal.com/tools/azure-blob-storage.min.md (~1,930 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/azure-blob-storage.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 ## Overview **Grade BB · 75.7/100 · rank #40 of 842 · #4 in File storage & sharing · agent-ready · confidence medium** More from Microsoft Corporation, listed separately because each is its own product: [Microsoft Foundry fine-tuning (Azure OpenAI)](https://www.anchorterminal.com/tools/azure-foundry-fine-tuning.md) (Fine-tuning), [Azure AI Content Safety (Prompt Shields)](https://www.anchorterminal.com/tools/azure-ai-content-safety.md) (Guardrails & safety filters), [Azure AI Speech speech-to-text](https://www.anchorterminal.com/tools/azure-speech-to-text.md) (Speech-to-text), [Azure AI Speech text-to-speech](https://www.anchorterminal.com/tools/azure-text-to-speech.md) (Text-to-speech), [Microsoft Agent Framework](https://www.anchorterminal.com/tools/microsoft-agent-framework.md) (Agent frameworks & SDKs), [Microsoft Execution Containers](https://www.anchorterminal.com/tools/microsoft-execution-containers.md) (Code execution sandboxes), [Microsoft Entra Agent ID](https://www.anchorterminal.com/tools/microsoft-entra-agent-id.md) (Agent auth & delegated access), [Azure Key Vault](https://www.anchorterminal.com/tools/azure-key-vault.md) (Secrets & credential vaults), [Azure Document Intelligence](https://www.anchorterminal.com/tools/azure-document-intelligence.md) (Document parsing & extraction), [Azure DevOps MCP Server](https://www.anchorterminal.com/tools/azure-devops-mcp.md) (Code & developer platforms), [Microsoft Learn MCP Server](https://www.anchorterminal.com/tools/microsoft-learn-mcp.md) (Code & developer platforms), [Playwright MCP](https://www.anchorterminal.com/tools/playwright-mcp.md) (Browser automation), [Azure MCP Server](https://www.anchorterminal.com/tools/azure-mcp.md) (Cloud & infrastructure), [Azure Maps](https://www.anchorterminal.com/tools/azure-maps.md) (Maps, geocoding & places), [Azure Translator](https://www.anchorterminal.com/tools/azure-translator.md) (Translation), [Microsoft Graph Calendar API](https://www.anchorterminal.com/tools/microsoft-graph-calendar.md) (Calendars & scheduling), [OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/tools/onedrive-sharepoint.md) (File storage & sharing), [Microsoft Teams (Microsoft Graph)](https://www.anchorterminal.com/tools/microsoft-teams.md) (Work & productivity), [Microsoft Dynamics 365 Sales](https://www.anchorterminal.com/tools/dynamics-365-sales.md) (CRM & customer platforms), [Microsoft Power Automate](https://www.anchorterminal.com/tools/power-automate.md) (Workflow automation), [Foundry Local](https://www.anchorterminal.com/tools/foundry-local.md) (Local AI), [Microsoft Advertising API](https://www.anchorterminal.com/tools/microsoft-advertising-api.md) (Advertising & campaign operations), [Microsoft Excel (Microsoft Graph workbook API)](https://www.anchorterminal.com/tools/microsoft-excel-graph.md) (Spreadsheets & operational tables), [Outlook Mail (Microsoft Graph)](https://www.anchorterminal.com/tools/outlook-mail-graph.md) (Mailbox access). ## Assessment Microsoft Entra ID roles can be scoped to one container, and a user delegation signature hands out a link that expires within seven days. Account keys with full access stay enabled until the owner turns them off, request logs are off until configured, and an Azure account needs a person, a phone number and a payment card. ## Facts | Field | Value | | --- | --- | | Vendor | Microsoft Corporation (https://azure.microsoft.com/en-us/products/storage/blobs) | | Kind | HTTP API | | Category | File storage & sharing (https://www.anchorterminal.com/categories/file-storage) | | Transport | HTTP | | Endpoint | `https://.blob.core.windows.net` | | Auth | OAuth or key · Three routes. Microsoft Entra ID OAuth 2.0 bearer tokens, authorised by Azure roles assigned on a container, account, resource group or subscription, which Microsoft recommends. Shared Key, an HMAC signature made with one of the account's access keys, which carry full access and are accepted until the owner sets `AllowSharedKeyAccess` to false. A shared access signature (SAS), a signed query string that grants chosen permissions on a resource until an expiry time. A user delegation SAS is signed with a key obtained through Entra ID and lasts at most seven days. Access is self-serve inside an Azure subscription (https://learn.microsoft.com/en-us/rest/api/storageservices/authorize-requests-to-azure-storage, https://learn.microsoft.com/en-us/azure/storage/blobs/authorize-access-azure-active-directory). | | Pricing | Pay per use ($0.005 / 1k req) · Hot tier LRS storage is $0.0208 a GB-month for the first 50 TB in East US, cool $0.0152, cold $0.0036 and archive $0.00099. Hot write operations cost $0.05 per 10,000, list and create container operations $0.05, read and other operations $0.004. Cool and cold reads add a retrieval charge of $0.01 and $0.03 a GB. The pricing page draws its numbers by script and showed none, so these come from the Azure Retail Prices API (https://prices.azure.com/api/retail/prices?$filter=serviceName%20eq%20%27Storage%27%20and%20armRegionName%20eq%20%27eastus%27%20and%20productName%20eq%20%27General%20Block%20Blob%20v2%27). Internet egress is billed separately as bandwidth and its rate was not read. No free allowance for Blob Storage could be read, because the free services page lists its services by script. A new Azure account gets $200 of credit for 30 days and needs a phone number and a credit or debit card (https://azure.microsoft.com/en-us/pricing/purchase-options/azure-account). | | x402 | No · No x402, MPP or L402 in the Blob Storage REST reference, the storage docs read or the pricing page (checked 2026-10-08). | | Licence | Proprietary service under Microsoft's Product Terms. The Azure SDK client libraries are MIT | | Packages | pypi: `azure-storage-blob`; npm: `@azure/storage-blob` | | Source | https://github.com/Azure/azure-rest-api-specs | | Docs | https://learn.microsoft.com/en-us/rest/api/storageservices/blob-service-rest-api | | llms.txt | not found | | Last release | 2026-09-30 | | npm downloads / week | 12,530,696 | | PyPI downloads / week | 22,597,364 | | API | REST at https://.blob.core.windows.net, 42 documented operations on accounts, containers and blobs, XML bodies and `x-ms-` headers. Newest service version 2026-10-06, sent in `x-ms-version`. Accounts are created through Azure Resource Manager | | Credentials | Microsoft Entra ID bearer tokens with Azure roles, Shared Key with one of the account's access keys, or a shared access signature in the URL. Anonymous read is possible where the owner enables it | | Roles | Storage Blob Data Reader, Contributor and Owner, and Storage Blob Delegator for the user delegation key, assignable on a container, account, resource group or subscription. Attribute-based conditions narrow them further | | Expiring links | User delegation SAS signed with a key from Get User Delegation Key, valid at most seven days, limited by `sp` permissions, `sip` address range and `spr` protocol. A service SAS tied to a stored access policy can be revoked, with five policies a container | | Request rates | 20,000 requests a second per standard account by default, 40,000 in 29 named regions, 3,000 a second on one block blob. 503 Server Busy or 500 Operation Timeout past a partition's limit | | Object limits | Block blob about 190.7 TiB (50,000 blocks of up to 4,000 MiB), 5,000 MiB in one Put Blob, append blob about 195 GiB, page blob 8 TiB | | Listing | List Blobs returns up to 5,000 items a page with `prefix`, `delimiter`, `marker` and optional `include` datasets. Find Blobs by Tags queries index tags. Arrow output from version 2026-06-06 | | Deletion | Blob soft delete keeps deleted or overwritten data for 1 to 365 days once enabled, and Undelete Blob restores it. Time-based retention and legal holds make blobs write-once | | Audit | Azure Monitor resource logs in the StorageRead, StorageWrite and StorageDelete categories, with caller IP address. Not collected until a diagnostic setting is created | | SLA | Hot tier, 99.9% for reads and writes and 99.99% for reads on RA-GRS and RA-GZRS accounts. Cool, cold and archive, 99% for writes and 99.9% for reads. Credits of 10% and 25% | | Tiers and redundancy | Hot, cool, cold and archive tiers. LRS, ZRS, GRS, GZRS and the read-access forms of the last two. LRS keeps replicas inside one region | | SDKs | Python azure-storage-blob 12.31.0 (30 September 2026, Python 3.10 or later) and JavaScript @azure/storage-blob 12.34.0 (Node 22 or later), both MIT. The Python client retries with exponential backoff by default, three times from 15 seconds | | MCP server | None dedicated. The Azure MCP Server, listed separately, has four Blob tools for containers, blob properties and upload | | Capabilities | storage.object, storage.presigned, storage.share, infra.azure | | Tags | hosted, closed-source, usage-priced, card-required, openapi, oauth, python, typescript, enterprise, sla, eu | | JSON | https://www.anchorterminal.com/api/v1/tools/azure-blob-storage.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 88 | 17.6 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 85 | 13.8 | | Agent ergonomics | 13% | 16.2 | 84 | 13.7 | | Security & auth | 14% | 17.5 | 81 | 14.2 | | Payments & pricing | 10% | 12.5 | 20 | 2.5 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 80 | 7.0 | | Transparency & trust (editorial 73, provenance 86) | 7% | 8.8 | 80 | 7.0 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **75.7 → BB** | ### Why each score - Reliability 88: Hosted reading. Azure status page with a history of post-incident reviews (20). The history lists three incidents in the last 90 days, West US network connectivity on 23 July 2026 (14:44 to 19:41 UTC), Azure OpenAI and Cognitive Services on 29 September, and gateway services in several regions from 30 September to 1 October. None names Storage. The page lists only broad incidents and the West US fault blocked traffic entering or leaving that region, so we count the record as minor (20 of 30). Targets published with numbers, 20,000 requests a second per standard account, 40,000 in 29 named regions, and 3,000 a second on one block blob (15). 503 Server Busy and 500 Operation Timeout are documented with advice to back off exponentially, the Python client retries three times by default, and `If-None-Match: *` makes a retried write safe. No Retry-After header was found in the pages read (13 of 15). The SLA document of 1 October 2026 commits to 99.9 per cent on the hot tier, 99.99 per cent for reads on RA-GRS accounts, with 10 and 25 per cent credits (10). Generally available (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 85: A public OpenAPI 2.0 document for service version 2026-10-06 with 69 operations, each with a description (25). learn.microsoft.com/llms.txt returns 404, but every Learn page we asked for with `Accept: text/markdown` came back as Markdown, so half (5 of 10). Reference pages state each operation's purpose, permissions, limits by version and billing category, and seldom say when not to use one. Several are dated 2023 (15 of 20). The contract types 117 parameters, 15 with enums, but most inputs travel as headers or XML and metadata is free-form (12 of 15). Sample requests and responses on the reference pages, a table of 70-odd Blob error codes with HTTP status and message, and a 114-value error code enum in the contract. The contract carries no examples (13 of 15). Dated `x-ms-version` values, a versioning page updated 23 September 2026 with deployment by region, and a page of changes for each version (15). - Agent ergonomics 84: API reading, since Blob Storage has no MCP server of its own. List Blobs caps a page at 5,000 items, returns metadata, tags, versions and snapshots only when `include` asks, and Get Blob takes a `Range`. Responses are XML with no field selection (20 of 25). Paging by `marker` and `NextMarker`, `prefix` and `delimiter` filters, and Find Blobs by Tags (20). Errors carry a code and a message, 70-odd Blob codes are documented, and a 503 says which account limit was passed (16 of 20). Conditional headers, leases and soft delete make retries and mistakes recoverable. `x-ms-client-request-id` correlates logs and is not an idempotency key. The Azure MCP Server, a separate listing, marks its four Blob tools read-only or destructive (16 of 20). Official Python and JavaScript SDKs were checked on their registries, and the Python client retries by default. A REST call needs `x-ms-version`, `x-ms-date` and, for uploads, `x-ms-blob-type` (12 of 15). - Security & auth 81: Microsoft Entra ID OAuth 2.0 tokens with Azure roles, managed identities on Azure, and user delegation signatures limited to seven days. Account access keys with full access are accepted until the owner disallows Shared Key. A SAS travels in the URL query string. It is a signature over stated permissions and an expiry, not the account key, so we read it as we read S3 presigned URLs and take no deduction, though Microsoft's docs say to protect a SAS like an account key (28 of 30). Storage Blob Data Reader for read-only work, roles on one container, attribute conditions, soft delete of 1 to 365 days, immutability policies and legal holds. Nothing asks for approval on a write or delete (17 of 20). The service returns whatever bytes were stored, and no guidance on treating blob contents as untrusted was found (8 of 15). Resource logs record reads, writes and deletes with caller IP address, but only after the owner adds a diagnostic setting (12 of 15). MSRC coordinated disclosure and bounty policies and a SOC 2 Type 2 report covering Azure. The microsoft.com security.txt passed its Expires date on 23 September 2026, and the audit scope page we loaded did not name services (16 of 20). - Payments & pricing 20: No x402, MPP or L402 (0). Per-GB and per-operation prices are public through the Azure Retail Prices API, while the pricing page fills its numbers by script (20). The Azure free account needs a credit or debit card, and no free Blob Storage allowance could be read (0). A person signs up in a browser with a phone number and a card (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 80: Read as a closed service with official SDKs. azure-storage-blob 12.31.0 reached PyPI on 30 September 2026, and the versioning page was updated on 23 September (30). Four Python releases in the last 90 days, 12.30.1 on 27 August, 12.30.2 on 16 September, 12.30.3 on 22 September and 12.31.0 on 30 September (20). A versioning page and per-version change pages, Microsoft Q&A and the SDK issue trackers on GitHub, which we did not read (10 of 15). Official SDKs current in Python (12.31.0) and JavaScript (12.34.0) (15). The SDKs are released from the azure-sdk monorepos, CI not checked (5 of 10). - Transparency & trust 80: Closed service under Microsoft's Product Terms, with MIT client libraries and a public API contract (15 of 30). The privacy statement, last updated September 2026, sends Azure customer data to the Product Terms and the Data Protection Addendum. The addendum of 22 May 2026 keeps customer data for 90 days after a subscription ends and deletes it within a further 90, and the redundancy docs say LRS replicates only inside the chosen region. These agree (26 of 30). The Modern Lifecycle Policy promises 12 months' notice before support ends, and the general-purpose v1 account retirement was announced in September 2025 for October 2026 (18 of 20). The addendum promises six months' notice of a new sub-processor, and data location follows the region and redundancy option chosen. The sub-processor list sits on the Service Trust Portal, a script-drawn page we could not read (14 of 20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (22 items): https://www.anchorterminal.com/fixes/azure-blob-storage.md (JSON https://www.anchorterminal.com/fixes/azure-blob-storage.json) ### What we couldn't check - The lead was right on the interface and the docs. Its URL redirects to https://azure.microsoft.com/en-us/products/storage/blobs, and the contracting entity is Microsoft Corporation. - unchecked: a free Blob Storage allowance. The free services page lists its services by script and the free account page names none for Blob Storage. - unchecked: the internet egress (bandwidth) rate, which is a separate Azure meter and was not read. - unchecked: whether Storage is on Azure's SOC 2 audit scope list. The scope page we loaded did not name services, and the reports sit on the Service Trust Portal. - unchecked: the Microsoft sub-processor list. The Service Trust Portal page is drawn by script. - unchecked: incidents limited to one region or to Storage alone, since the public status history lists only broad incidents. - unchecked: MSRC advisories for Azure Storage in the last 12 months, and CI and open issues for the azure-sdk repositories. - unchecked: the .NET, Java and Go client libraries, which were not looked up on their registries. - Not established: whether 503 responses carry a Retry-After header, whether throttled or failed calls are billed, and whether new accounts have blob soft delete on by default. - The specs repository has a stable folder named 2026-12-06 whose document still gives its version as 2026-10-06. The versioning page does not mention 2026-12-06. - A judgement call. We took no deduction for SAS tokens in the URL query string, to match the Amazon S3 reading of presigned URLs. Microsoft's docs tell users to protect a SAS like an account key, so a stricter reading takes 10 off Security. - The Product Terms page showed no effective date when read. Its competitive benchmarking clause is recorded as a fact with no deduction. ### Sources - Blob Storage REST API index: (seen 2026-10-08) - versioning and deployed service versions: (seen 2026-10-08) - previous service versions: (seen 2026-10-08) - authorisation options: (seen 2026-10-08) - Entra ID roles and scopes: (seen 2026-10-08) - preventing Shared Key authorisation: (seen 2026-10-08) - Get User Delegation Key: (seen 2026-10-08) - user delegation SAS: (seen 2026-10-08) - SAS overview and practices: (seen 2026-10-08) - Put Blob: (seen 2026-10-08) - Get Blob: (seen 2026-10-08) - List Blobs: (seen 2026-10-08) - Blob Batch: (seen 2026-10-08) - conditional headers: (seen 2026-10-08) - Blob error codes: (seen 2026-10-08) - common error codes: (seen 2026-10-08) - Blob scalability targets: (seen 2026-10-08) - standard account scalability targets: (seen 2026-10-08) - Python retry policy: (seen 2026-10-08) - soft delete: (seen 2026-10-08) - immutable storage: (seen 2026-10-08) - monitoring and resource logs: (seen 2026-10-08) - resource log reference: (seen 2026-10-08) - security recommendations: (seen 2026-10-08) - redundancy options: (seen 2026-10-08) - general-purpose v1 retirement: (seen 2026-10-08) - OpenAPI document, Blob 2026-10-06: (seen 2026-10-08) - retail prices, East US: (seen 2026-10-08) - pricing page: (seen 2026-10-08) - product page: (seen 2026-10-08) - Azure free account: (seen 2026-10-08) - free services: (seen 2026-10-08) - SLA for Online Services, 1 October 2026: (seen 2026-10-08) - status history: (seen 2026-10-08) - security.txt: (seen 2026-10-08) - Product Terms for Online Services: (seen 2026-10-08) - Online Subscription Agreement: (seen 2026-10-08) - privacy statement: (seen 2026-10-08) - Data Protection Addendum, 22 May 2026: (seen 2026-10-08) - Modern Lifecycle Policy: (seen 2026-10-08) - SOC 2 Type 2 page: (seen 2026-10-08) - Python SDK on PyPI: (seen 2026-10-08) - JavaScript SDK on npm: (seen 2026-10-08) - Azure MCP Server commands: (seen 2026-10-08) - authorising with Microsoft Entra ID: (seen 2026-10-08) - RDAP, windows.net: (seen 2026-10-08) ## Who's behind it (provenance 86/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Microsoft Corporation | 20/20 | | Domain age | microsoft.com, registered 1991-05-02 (35 years) | 15/15 | | Endpoint on the vendor's domain | .blob.core.windows.net | 15/15 | | Terms of service | read, states 4 of the 7 things a reader expects, and has 2 clauses that cost points | 3.4/10 | | Privacy policy | read, states 8 of the 8 things a reader expects, and has 1 clause that costs points | 8/10 | | Status page | azure.status.microsoft/en-us/status | 10/10 | | Changelog | published | 10/10 | | security.txt | published but past its Expires date | 5/10 | Accounts answer at .blob.core.windows.net, as Microsoft's REST reference gives it. RDAP shows windows.net registered on 1995-08-10. Docs are on learn.microsoft.com. The Product Terms for Online Services cover Microsoft Azure, carry an acceptable use policy and a competitive benchmarking clause, and point to the Data Protection Addendum. The page showed no effective date when read on 8 October 2026. Self-serve Azure accounts also accept the Microsoft Online Subscription Agreement (last updated March 2019, Microsoft Corporation, Washington law) at https://azure.microsoft.com/en-us/support/legal/subscription-agreement/, which incorporates the Online Services Terms and the SLAs. The privacy statement (last updated September 2026) names Microsoft Corporation, One Microsoft Way, Redmond, Washington 98052, and Microsoft Ireland Operations Limited. It lists Microsoft Azure among the enterprise online services covered by the Product Terms. The Data Protection Addendum read is the English edition of 22 May 2026, a Word file linked from https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA. https://www.microsoft.com/.well-known/security.txt shows Expires 2026-09-23T16:00:00.000Z. It points to the MSRC researcher portal, the bounty policy and the coordinated disclosure policy. RDAP gives 1991-05-02 for microsoft.com and 1995-08-10 for windows.net. The registry record does not name a registrant. The versioning page is dated 23 September 2026 and each service version has its own page of changes. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://www.microsoft.com/licensing/terms/product/ForOnlineServices/all), read 2026-10-08, gives no date, states 4 of the 7 things a reader expects. - To know. Restricts automated access (costs points). "Customer may not use web scraping, web harvesting, or other data extraction methods to extract data from a Microsoft Generative AI Service." - To know. Restricts benchmarking or competitive use (costs points). "If Customer offers a product or service competitive to an Online Service, by using the Online Service, Customer waives any restrictions on competitive use and benchmark testing in the terms governing its competitive products and services." - Not found in the text. Gives the date it was last updated. - Not found in the text. Names the governing law or courts. - Not found in the text. Says how changes to the terms are announced. - Also in the text (2026-10-08). A subscription that is not renewed can continue month by month, and Microsoft may invoice that period at the monthly price plus a three per cent uplift for certain Products. "Microsoft reserves the right to invoice Customer for the Extended Term at the then-current published price for a monthly subscription plus a three (3) percent uplift for certain Products." - Also in the text (2026-10-08). After an account is disabled, the customer has 90 days to extract Customer Data and the subscription cannot be reactivated. "Customer will have 90 days to extract Customer Data from a disabled account, but the Subscription cannot be reactivated." - Also in the text (2026-10-08). The customer is responsible for any application or AI agent it creates with Microsoft AI Services, including legal, regulatory and licensing compliance. "Customer is responsible for the design, development and use of any application or AI agent it creates using or for use with Microsoft AI Services, including complying with any legal, regulatory, or licensing requirements applicable to the resulting application or AI agent or its use." **Privacy policy** (https://www.microsoft.com/en-us/privacy/privacystatement), read 2026-10-08, dated 2026-09-01, states 8 of the 8 things a reader expects. - To know. Says it may use customer content to train or improve models, and no opt-out was found (costs points). "As part of our efforts to improve and develop our products, we may use your data to develop and train our AI models." - To know. Says it sells personal data or shares it for advertising. "We also disclose personal data for digital advertising purposes." - Gives the date it was last updated. Last updated 2026-09-01. - Says how long data is kept. Names a period of 7 days. - Gives a privacy contact. Names a data protection officer. - Says where data is transferred or stored. Relies on standard contractual clauses. - Also in the text (2026-10-08). For enterprise and developer products, the customer's agreement with Microsoft takes precedence over this privacy statement where the two conflict. "In the event of a conflict between our privacy statement and the terms of any agreement(s) between a customer and Microsoft for Enterprise and Developer Products, the terms of those agreement(s) will control." - Also in the text (2026-10-08). Prompts and related data sent to the consumer Microsoft Copilot are used to improve services and for relevant advertising. "Microsoft Copilot also uses prompts and related data to provide and improve services, including relevant advertising." - Also in the text (2026-10-08). Microsoft staff manually review some results of its automated systems, including AI, against the source data. "For example, to build, train, and improve the accuracy of our automated systems – such as AI - we manually review some of the results against the underlying data." ## Live (updated 2026-10-09 10:42 UTC) - Right now: down, n/a, checked 2026-10-09 10:42 UTC (get on `https://.blob.core.windows.net`) - Uptime 24h 0.0% (33 probes) · 30 days 0.0% (33 probes) · p50 n/a · p95 n/a - Always current: https://www.anchorterminal.com/api/v1/live/azure-blob-storage.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Hot LRS storage, first 50 TB | $0.0208 | per GB per month | East US, general-purpose v2, from the Azure Retail Prices API | | Cool LRS storage | $0.0152 | per GB per month | East US | | Hot LRS write operations | $0.005 | per 1,000 requests | $0.05 per 10,000 | | Hot read operations | $0.0004 | per 1,000 requests | $0.004 per 10,000 | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - Microsoft Entra ID roles such as Storage Blob Data Reader can be assigned on one container, with no stored key for workloads on Azure - A user delegation shared access signature is signed with Entra credentials, lasts at most seven days and can be limited by permission, IP address and protocol - SLA of 99.9 per cent on the hot tier, 99.99 per cent for reads on RA-GRS accounts, in the 1 October 2026 SLA document - Public OpenAPI 2.0 contract with 69 operations for service version 2026-10-06, and Learn pages returned as Markdown on request - Conditional headers, leases, soft delete of 1 to 365 days and immutability policies protect against a wrong overwrite or delete ## Weaknesses - Shared Key authorisation with the account's access keys is allowed until the owner sets `AllowSharedKeyAccess` to false - Request logs are not collected until a diagnostic setting routes the StorageRead, StorageWrite and StorageDelete categories somewhere - Requests and responses use headers and XML, and every authorised call must carry `x-ms-version` - The pricing page draws its numbers by script, so an agent reading it sees no price. The Retail Prices API has them - An Azure account needs a phone number and a credit or debit card, and no free Blob Storage allowance could be read ## Before you call it (notes for agents) 1. Request an Entra ID token for https://storage.azure.com/ and send it as a Bearer header with `x-ms-version` and `x-ms-date`. Put Blob also needs `x-ms-blob-type: BlockBlob` 2. Ask for a Storage Blob Data role on the one container. Role changes can take up to 10 minutes to apply 3. To share a file, call Get User Delegation Key, then sign a SAS with `sp=r`, `spr=https` and a short expiry. Treat the URL as a secret 4. Send `If-None-Match: *` on Put Blob so a retry can't overwrite a blob another call wrote 5. On 503 ServerBusy back off exponentially. After 500 OperationTimedOut check the blob's state before retrying, since the write may have succeeded ## Connect Install: ```bash pip install azure-storage-blob azure-identity # or: npm i @azure/storage-blob @azure/identity ``` First request: ```bash PUT https://myaccount.blob.core.windows.net/mycontainer/myblob x-ms-version: 2026-04-06 x-ms-date: x-ms-blob-type: BlockBlob Authorization: Bearer ``` Through letme (picks today, calling later): https://letme.dev/azure-blob-storage (letme picks it for infra.azure, the top-graded tool for the job). letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Amazon S3 | BB | 77.9 | 15 | storage.object, storage.presigned, storage.share | no | https://www.anchorterminal.com/tools/amazon-s3.md | | Cloudflare R2 | BB | 77.1 | 22 | storage.object, storage.presigned, storage.share | no | https://www.anchorterminal.com/tools/cloudflare-r2.md | | Backblaze B2 | BB | 75.3 | 48 | storage.object, storage.presigned, storage.share | no | https://www.anchorterminal.com/tools/backblaze-b2.md | | Tigris | E | 44.4 | 778 | storage.object, storage.presigned, storage.share | no | https://www.anchorterminal.com/tools/tigris.md | | OneDrive and SharePoint files (Microsoft Graph) | B | 65.3 | 296 | storage.share, storage.presigned | no | https://www.anchorterminal.com/tools/onedrive-sharepoint.md | | Bunny Storage | C | 58.3 | 525 | storage.object, storage.presigned | no | https://www.anchorterminal.com/tools/bunny-storage.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The Blob REST API lists 42 operation pages on accounts, containers and blobs, and the OpenAPI 2.0 document for service version 2026-10-06 has 69 operations (source: , ) - As of 23 September 2026 the latest fully deployed service version is 2026-04-06, with 2026-06-06 and 2026-10-06 enabled in almost every region. The newest SDKs default to 2026-10-06 (source: ) - A standard account has a default target of 20,000 requests a second, 40,000 in 29 named regions, and a single block blob up to 3,000 a second. Past a partition's limit the service answers 503 Server Busy or 500 Operation Timeout (source: , ) - A block blob can reach about 190.7 TiB (50,000 blocks of 4,000 MiB). One Put Blob call takes up to 5,000 MiB (source: ) - Get User Delegation Key returns a key valid for at most seven days, and a user delegation SAS grants the intersection of its `sp` permissions and the signer's role (source: , ) - The `AllowSharedKeyAccess` property is not set by default, and the account accepts Shared Key requests while it is null or true (source: ) - General-purpose v1 accounts retire in October 2026. Microsoft announced it in September 2025, stopped new v1 accounts in September 2026 and migrates the rest to v2 itself (source: ) - Microsoft's Azure MCP Server, listed separately, has four Blob tools (container create, container get, blob get, blob upload), each marked read-only or destructive (source: ) - https://www.microsoft.com/.well-known/security.txt shows Expires 2026-09-23T16:00:00.000Z, which had passed on 8 October 2026 - The Product Terms' competitive benchmarking clause asks a customer that sells a competing service and publishes a benchmark of an Online Service to give Microsoft the information needed to replicate it (source: ) ## Compare - [Azure Blob Storage vs Box API + MCP](https://www.anchorterminal.com/compare/azure-blob-storage-vs-box-api.md): BB 75.7 vs B 69.4 - [Azure Blob Storage vs Dropbox API + MCP](https://www.anchorterminal.com/compare/azure-blob-storage-vs-dropbox-api.md): BB 75.7 vs B 68.2 - [Azure Blob Storage vs Google Drive API + MCP](https://www.anchorterminal.com/compare/azure-blob-storage-vs-google-drive-api.md): BB 75.7 vs A 79.6 - [Amazon S3 vs Azure Blob Storage](https://www.anchorterminal.com/compare/amazon-s3-vs-azure-blob-storage.md): BB 77.9 vs BB 75.7 - [Azure Blob Storage vs Backblaze B2](https://www.anchorterminal.com/compare/azure-blob-storage-vs-backblaze-b2.md): BB 75.7 vs BB 75.3 - [Azure Blob Storage vs Bunny Storage](https://www.anchorterminal.com/compare/azure-blob-storage-vs-bunny-storage.md): BB 75.7 vs C 58.3 - [Azure Blob Storage vs Cloudflare R2](https://www.anchorterminal.com/compare/azure-blob-storage-vs-cloudflare-r2.md): BB 75.7 vs BB 77.1 - [Azure Blob Storage vs Tigris](https://www.anchorterminal.com/compare/azure-blob-storage-vs-tigris.md): BB 75.7 vs E 44.4 - [Azure Blob Storage vs OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/compare/azure-blob-storage-vs-onedrive-sharepoint.md): BB 75.7 vs B 65.3 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on microsoft.com or one of its subdomains, or the README of github.com/Azure/azure-rest-api-specs. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "azure-blob-storage", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Azure Blob Storage on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Azure Blob Storage on Anchor Terminal](https://www.anchorterminal.com/badges/azure-blob-storage.svg)](https://www.anchorterminal.com/tools/azure-blob-storage) ``` Plain link: ```html Azure Blob Storage on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Azure Blob Storage is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/azure-blob-storage-dark.png - Light: https://www.anchorterminal.com/assets/share/azure-blob-storage-light.png