# Azure Blob Storage (slim) > Microsoft Azure's object storage for files, backups and application data. Agents call a REST API or the Azure SDKs on a storage account, signing in with Microsoft Entra ID, an account key or a shared access signature. - Full: https://www.anchorterminal.com/tools/azure-blob-storage.md (~10,700 tokens) · this version ~1,930 tokens · JSON https://www.anchorterminal.com/tools/azure-blob-storage.json · canonical https://www.anchorterminal.com/tools/azure-blob-storage - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **BB · 75.7/100 · rank #40 of 842 · #4 in File storage & sharing · agent-ready · confidence medium** Assessment: Microsoft Entra ID roles can be scoped to one container, and a user delegation signature hands out a link that expires within seven days. Account keys with full access stay enabled until the owner turns them off, request logs are off until configured, and an Azure account needs a person, a phone number and a payment card. ## Facts - Kind: HTTP API · vendor: Microsoft Corporation · category: File storage & sharing · legal entity: Microsoft Corporation · provenance 86/100 - Endpoint: `https://.blob.core.windows.net` (HTTP) - Auth: OAuth or key · pricing: Pay per use · x402: no · licence: Proprietary service under Microsoft's Product Terms. The Azure SDK client libraries are MIT - Probe metrics: not measured yet (probes haven't run) - API: REST at https://.blob.core.windows.net, 42 documented operations on accounts, containers and blobs, XML bodies and `x-ms-` headers. Newest service version 2026-10-06, sent in `x-ms-version`. Accounts are created through Azure Resource Manager - Credentials: Microsoft Entra ID bearer tokens with Azure roles, Shared Key with one of the account's access keys, or a shared access signature in the URL. Anonymous read is possible where the owner enables it - Roles: Storage Blob Data Reader, Contributor and Owner, and Storage Blob Delegator for the user delegation key, assignable on a container, account, resource group or subscription. Attribute-based conditions narrow them further - Expiring links: User delegation SAS signed with a key from Get User Delegation Key, valid at most seven days, limited by `sp` permissions, `sip` address range and `spr` protocol. A service SAS tied to a stored access policy can be revoked, with five policies a container - Request rates: 20,000 requests a second per standard account by default, 40,000 in 29 named regions, 3,000 a second on one block blob. 503 Server Busy or 500 Operation Timeout past a partition's limit - Object limits: Block blob about 190.7 TiB (50,000 blocks of up to 4,000 MiB), 5,000 MiB in one Put Blob, append blob about 195 GiB, page blob 8 TiB - Listing: List Blobs returns up to 5,000 items a page with `prefix`, `delimiter`, `marker` and optional `include` datasets. Find Blobs by Tags queries index tags. Arrow output from version 2026-06-06 - Deletion: Blob soft delete keeps deleted or overwritten data for 1 to 365 days once enabled, and Undelete Blob restores it. Time-based retention and legal holds make blobs write-once - Audit: Azure Monitor resource logs in the StorageRead, StorageWrite and StorageDelete categories, with caller IP address. Not collected until a diagnostic setting is created - SLA: Hot tier, 99.9% for reads and writes and 99.99% for reads on RA-GRS and RA-GZRS accounts. Cool, cold and archive, 99% for writes and 99.9% for reads. Credits of 10% and 25% - Tiers and redundancy: Hot, cool, cold and archive tiers. LRS, ZRS, GRS, GZRS and the read-access forms of the last two. LRS keeps replicas inside one region - SDKs: Python azure-storage-blob 12.31.0 (30 September 2026, Python 3.10 or later) and JavaScript @azure/storage-blob 12.34.0 (Node 22 or later), both MIT. The Python client retries with exponential backoff by default, three times from 15 seconds - MCP server: None dedicated. The Azure MCP Server, listed separately, has four Blob tools for containers, blob properties and upload - Prices: Hot LRS storage, first 50 TB $0.0208 per GB per month; Cool LRS storage $0.0152 per GB per month; Hot LRS write operations $0.005 per 1,000 requests; Hot read operations $0.0004 per 1,000 requests - Scores: Reliability 88, Performance pending, Schema & documentation 85, Agent ergonomics 84, Security & auth 81, Payments & pricing 20, Task success pending, Maintenance & community 80, Transparency & trust 80 · total over the 7 assessed categories - Why: Reliability, Hosted reading. · Schema & documentation, A public OpenAPI 2.0 document for service version 2026-10-06 with 69 operations, each with a description (25). · Agent ergonomics, API reading, since Blob Storage has no MCP server of its own. · Security & auth, Microsoft Entra ID OAuth 2.0 tokens with Azure roles, managed identities on Azure, and user delegation signatures limited to seven days. · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, Read as a closed service with official SDKs. · Transparency & trust, Closed service under Microsoft's Product Terms, with MIT client libraries and a public API contract (15 of 30). - Sources: 46, open questions: 12, both in the full twin - Capabilities: storage.object, storage.presigned, storage.share, infra.azure - JSON: https://www.anchorterminal.com/api/v1/tools/azure-blob-storage.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/azure-blob-storage.svg` or a link to https://www.anchorterminal.com/tools/azure-blob-storage from a page on microsoft.com or one of its subdomains, or the README of github.com/Azure/azure-rest-api-specs, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Request an Entra ID token for https://storage.azure.com/ and send it as a Bearer header with `x-ms-version` and `x-ms-date`. Put Blob also needs `x-ms-blob-type: BlockBlob` 2. Ask for a Storage Blob Data role on the one container. Role changes can take up to 10 minutes to apply 3. To share a file, call Get User Delegation Key, then sign a SAS with `sp=r`, `spr=https` and a short expiry. Treat the URL as a secret 4. Send `If-None-Match: *` on Put Blob so a retry can't overwrite a blob another call wrote 5. On 503 ServerBusy back off exponentially. After 500 OperationTimedOut check the blob's state before retrying, since the write may have succeeded ## Connect ```bash pip install azure-storage-blob azure-identity # or: npm i @azure/storage-blob @azure/identity ``` ```bash PUT https://myaccount.blob.core.windows.net/mycontainer/myblob x-ms-version: 2026-04-06 x-ms-date: x-ms-blob-type: BlockBlob Authorization: Bearer ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/azure-blob-storage ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Amazon S3 | BB | 77.9 | storage.object, storage.presigned, storage.share | https://www.anchorterminal.com/tools/amazon-s3.min.md | | Cloudflare R2 | BB | 77.1 | storage.object, storage.presigned, storage.share | https://www.anchorterminal.com/tools/cloudflare-r2.min.md | | Backblaze B2 | BB | 75.3 | storage.object, storage.presigned, storage.share | https://www.anchorterminal.com/tools/backblaze-b2.min.md | | Tigris | E | 44.4 | storage.object, storage.presigned, storage.share | https://www.anchorterminal.com/tools/tigris.min.md | | OneDrive and SharePoint files (Microsoft Graph) | B | 65.3 | storage.share, storage.presigned | https://www.anchorterminal.com/tools/onedrive-sharepoint.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)