# DigitalOcean Spaces (slim) > DigitalOcean Spaces is S3-compatible object storage with a built-in CDN, sold as a $5 monthly subscription. Agents use it through AWS S3 SDKs with a Spaces access key, and manage keys through the DigitalOcean API or MCP server. - Full: https://www.anchorterminal.com/tools/digitalocean-spaces.md (~9,300 tokens) · this version ~2,130 tokens · JSON https://www.anchorterminal.com/tools/digitalocean-spaces.json · canonical https://www.anchorterminal.com/tools/digitalocean-spaces - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-10 **B · 63.2/100 · rank #402 of 950 · #9 in File storage & sharing · not agent-ready · confidence medium** Assessment: Per-bucket access keys with read or read-write-delete grants, an 800 operations a second limit per bucket and a 99.9 per cent SLA are all published. The MCP server manages keys and CDN endpoints only, not objects, and the S3 reference documents no error codes. A payment method is required before any bucket is created. ## Facts - Kind: HTTP API · vendor: DigitalOcean, LLC · category: File storage & sharing · legal entity: DigitalOcean, LLC · provenance 85/100 - Endpoint: `https://nyc3.digitaloceanspaces.com` (HTTP, Streamable HTTP) - Auth: API key · pricing: Pay per use · x402: no · licence: Proprietary service under the DigitalOcean Terms of Service Agreement. The MCP server is MIT - Probe metrics: not measured yet (probes haven't run) - APIs: S3-compatible XML API on `.digitaloceanspaces.com` (a subset of AWS S3, SigV4 recommended, SigV2 accepted). The DigitalOcean API v2 at `api.digitalocean.com` for access keys and CDN endpoints - Endpoints: `https://.digitaloceanspaces.com` path-style or `https://..digitaloceanspaces.com`. CDN at `..cdn.digitaloceanspaces.com`. Static sites at `.-static.digitaloceanspaces.com` - Regions: 13 for Standard Storage (NYC3, AMS3, SFO2, SFO3, SGP1, LON1, FRA1, TOR1, BLR1, SYD1, ATL1, RIC1, MKC1). Cold Storage in all of them except BLR1 - Credentials: Access key and secret, up to 200 an account. Full access, or limited to named buckets with Read or Read/Write/Delete. The secret is shown once and can be regenerated. Limited keys cannot be combined with bucket policies - MCP server: Remote at `https://spaces.mcp.digitalocean.com/mcp`, OAuth or `Authorization: Bearer` with an API token. Ten tools at v1.2.0, `spaces-key-*` and `spaces-cdn-*`, none for objects. Also runs locally as `npx @digitalocean/mcp --services spaces`. MIT licence - Rate limits: 800 operations a second per new bucket, with `LIST` limited further under load. Cold Storage 450 write, 250 read and 25 list requests a second per bucket. The DigitalOcean API allows 5,000 requests an hour and 250 a minute per token, with `retry-after` on 429 - Object limits: `PUT` up to 5 GB, multipart to 5 TB in 10,000 parts of at least 5 MiB. 100 buckets an account. 100 million unversioned or 50 million versioned objects a bucket. Incomplete multipart uploads are deleted after 30 days - Presigned URLs: SigV2 and SigV4. The control panel makes links valid for 1 hour, 6 hours, 1 day, 3 days or 7 days. Uploads through the CDN with a presigned URL are capped at 8,100 KiB - Minimums: $5 a month while any bucket exists, prorated hourly. 4 KiB per object on Standard. On Cold Storage 128 KiB per object and per read, and 30 days of storage - Sign-up credit: $5, expiring 90 days after sign-up. A valid payment method must be added before any resource is created - Deletion controls: Bucket versioning (API only), lifecycle expiry by time, and a one-week pending period in which a destroyed bucket can be recovered. No Object Lock found in the reviewed documentation - Logging: Bucket access logs in Amazon S3 server access log format and CDN logs in CloudFront format, off by default, set through `PutBucketLogging` or Terraform, usually written within one hour - SLA: 99.9 per cent monthly uptime per bucket. Credit of 10 per cent from 99.0 to 99.9, 25 per cent from 95.0 to 99.0 and 100 per cent below 95.0. Claims need written notice within 24 hours of the start of downtime - Certifications: SOC 2 and SOC 3 reports and Global PRP named on the trust page. DigitalOcean states eligibility for HIPAA and DORA workloads. ISO 27001 was not named on the page read - Sub-processors: More than 30 with activity and location in the list of 10 June 2026, Cloudflare (CDN), Wasabi (Cold Storage), Amazon Web Services and Stripe among them. The DPA of 6 February 2026 allows 30 days to object to a new one - Prices: Spaces subscription $5 per month (plan); Standard storage beyond 250 GiB $0.02 per GB per month; Cold Storage $0.007 per GB per month; Outbound transfer beyond 1,024 GiB $0.01 per GB of traffic - Scores: Reliability 77, Performance pending, Schema & documentation 63, Agent ergonomics 73, Security & auth 77, Payments & pricing 20, Task success pending, Maintenance & community 37, Transparency & trust 74 · total over the 7 assessed categories - Why: Reliability, Graded as a hosted API on the S3 surface. · Schema & documentation, The DigitalOcean API has a public OpenAPI file, which covers access keys and CDN endpoints. · Agent ergonomics, Graded as an API, with the MCP server noted. · Security & auth, Access keys are revocable, can be regenerated and can be limited to named buckets with Read or Read/Write/Delete. · Payments & pricing, No x402, MPP or L402. Stablecoin payment through Stripe is an account payment method (0). · Maintenance & community, Closed service. · Transparency & trust, Closed service under a Terms of Service Agreement updated on 22 August 2026 that leaves ownership of content with the customer. - Sources: 34, open questions: 11, both in the full twin - Capabilities: storage.object, storage.s3, storage.presigned, storage.share - JSON: https://www.anchorterminal.com/api/v1/tools/digitalocean-spaces.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/digitalocean-spaces.svg` or a link to https://www.anchorterminal.com/tools/digitalocean-spaces from a page on digitalocean.com or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Set the endpoint to `https://.digitaloceanspaces.com` and, in AWS SDKs other than Python's, set `region` to `us-east-1` when creating a bucket 2. Ask for a limited access key with a Read or Read/Write/Delete grant on one bucket. A full access key can create, configure and delete every bucket 3. Do the object work through the S3 API. The MCP server and `doctl` cannot upload, list, move or delete files 4. Retry with exponential backoff on `503 Slow Down`, and keep below 800 operations a second per bucket 5. Fetch presigned links from the origin host, not the CDN. The docs say presigned requests through the CDN are not cached and can double the bandwidth charge 6. Avoid many tiny objects. Each bills as at least 4 KiB on Standard and 128 KiB on Cold Storage, which also has a 30-day minimum ## Connect ```bash import boto3 session = boto3.session.Session() client = session.client('s3', region_name='nyc3', endpoint_url='https://nyc3.digitaloceanspaces.com', aws_access_key_id='YOUR_SPACES_KEY', aws_secret_access_key='YOUR_SPACES_SECRET') client.upload_file('localfile.txt', 'my-bucket', 'uploaded.txt') ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/digitalocean-spaces ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Amazon S3 | BB | 77.9 | storage.object, storage.s3, storage.presigned, storage.share | https://www.anchorterminal.com/tools/amazon-s3.min.md | | Cloudflare R2 | BB | 77.1 | storage.object, storage.s3, storage.presigned, storage.share | https://www.anchorterminal.com/tools/cloudflare-r2.min.md | | Backblaze B2 | BB | 75.3 | storage.object, storage.s3, storage.presigned, storage.share | https://www.anchorterminal.com/tools/backblaze-b2.min.md | | Tigris | E | 44.4 | storage.object, storage.s3, storage.presigned, storage.share | https://www.anchorterminal.com/tools/tigris.min.md | | Azure Blob Storage | BB | 75.7 | storage.object, storage.presigned, storage.share | https://www.anchorterminal.com/tools/azure-blob-storage.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)