# Wasabi Hot Cloud Storage (slim) > Wasabi Hot Cloud Storage is S3-compatible object storage from Wasabi Technologies, sold at one price per terabyte with no egress or request fees. Agents reach it through the S3, IAM and STS APIs with standard AWS SDKs. - Full: https://www.anchorterminal.com/tools/wasabi-hot-cloud-storage.md (~7,650 tokens) · this version ~1,880 tokens · JSON https://www.anchorterminal.com/tools/wasabi-hot-cloud-storage.json · canonical https://www.anchorterminal.com/tools/wasabi-hot-cloud-storage - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-10 **C · 61.2/100 · rank #478 of 950 · #10 in File storage & sharing · not agent-ready · confidence medium** Assessment: IAM policies, STS sessions of up to 12 hours, Object Lock and audit logging give an agent tight, revocable access at $7.99 a TB-month with no egress or request fees. No request limits are published with numbers for the S3 API, there is no OpenAPI file, and billing assumes 1 TB and 90 days of storage as minimums. ## Facts - Kind: HTTP API · vendor: Wasabi Technologies LLC · category: File storage & sharing · legal entity: Wasabi Technologies LLC · provenance 79/100 - Endpoint: `https://s3.wasabisys.com` (HTTP, Streamable HTTP) - Auth: API key · pricing: Pay per use · x402: no · licence: Proprietary service under the Wasabi Customer Agreement - Probe metrics: not measured yet (probes haven't run) - APIs: S3 API (compatible with AWS S3 2006-03-01), IAM (2010-05-08 subset) and STS (AssumeRole, GetCallerIdentity, GetSessionToken). Wasabi Account Control API and WACM Connect API for partners and control accounts, and a Stats API for utilisation - Endpoints: `s3.wasabisys.com` for US East 1 and `s3..wasabisys.com` for the other 15 regions. Path-style requests recommended. HTTP and HTTPS both accepted - Credentials: Access key and secret key, up to two per user, for the root user or a sub-user. Sub-users need IAM policies such as AmazonS3FullAccess or AmazonS3ReadOnlyAccess. Up to 1,000 policies an account. STS sessions up to 12 hours - MCP server: Hosted beta at `https://mcp.wasabisys.dev/s3`, `/iam` and `/wacm`, Streamable HTTP, OAuth with dynamic client registration and short-lived tokens. Wasabi keys are saved once in the server's dashboard. Tool names follow `wasabi__`. Tool list not published - Minimums: 1 TB of active storage a month, 90 days of storage per object on Pay as You Go (30 days on request), 4 KB per object - Free trial: No card. 100 GB for 30 days with a company email, 10 GB for 14 days with a free mail address, per the trial page. MFA is required on new trial accounts. Trial data is deleted if the account is not converted - Presigned URLs: GET and PUT, valid from 12 hours to 7 days when made in the console, per the docs - Rate limits: None published with numbers for the S3 API. The Account Control API allows 1,000 GET, 100 PUT, 100 POST and 10 DELETE operations a minute and answers 429 beyond that - Errors: AWS S3 error responses where possible, plus Wasabi codes such as `RequestRateLimitExceeded`, `StorageQuotaExceeded`, `AuthenticationLockout` and `EntityTemporarilyUnmodifiable` - Deletion controls: Object Lock with legal hold, compliance mode, bucket versioning, MFA Delete, Multi-User Authorisation through security contacts, and Covert Copy - Logging: Bucket access logs, administrative audit logs (CSV for up to 90 days, or saved to an Object Lock bucket), compliance logging and S3 event notifications - SLA: The version of 21 February 2024 gives a 10 per cent credit below 99.9 per cent monthly uptime and 25 per cent below 99.0. The current page is drawn by script and was not read - Certifications: ISO 27001:2022 held by Wasabi Technologies LLC (A-LIGN, valid to 9 June 2028). Data centres are described as SOC 2 compliant and certified for ISO 27001 and PCI-DSS. The DPA of 14 July 2025 cites an annual Type 2 HIPAA/HITECH audit - Sub-processors: 13 companies with location and purpose in the list of 19 December 2025, Stripe, Salesforce, Sentry, LogRocket and IBM (for AiR) among them, plus six Wasabi affiliates. The DPA of 14 July 2025 allows 30 days to object to a new one - Prices: Pay as You Go storage $0.0078 per GB per month - Scores: Reliability 65, Performance pending, Schema & documentation 59, Agent ergonomics 68, Security & auth 83, Payments & pricing 40, Task success pending, Maintenance & community 46, Transparency & trust 69 · negative events -2 · total over the 7 assessed categories - Why: Reliability, Graded as a hosted API on the S3 surface. · Schema & documentation, No OpenAPI file. · Agent ergonomics, Graded as an API. · Security & auth, IAM users, groups, roles and policies, bucket policies, key rotation with two keys a user, and STS AssumeRole sessions of up to 12 hours. · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, Closed service. · Transparency & trust, Closed service under a Customer Agreement whose current text is drawn by script. - Sources: 33, open questions: 9, both in the full twin - Capabilities: storage.object, storage.s3, storage.presigned - JSON: https://www.anchorterminal.com/api/v1/tools/wasabi-hot-cloud-storage.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/wasabi-hot-cloud-storage.svg` or a link to https://www.anchorterminal.com/tools/wasabi-hot-cloud-storage from a page on wasabi.com or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Use the bucket's own regional endpoint, such as `s3.eu-central-2.wasabisys.com`. The docs say a wrong endpoint allows GET but not PUT or DELETE 2. Ask for a sub-user key with a policy limited to one bucket, or an STS session. A root key has full access, billing included 3. Avoid short-lived objects. Each object deleted before 90 days is billed for the remaining days, and objects under 4 KB bill as 4 KB 4. Keep monthly downloads at or below the stored volume, the limit of the free egress policy 5. Call `https://` endpoints explicitly. The S3 API also accepts plain HTTP 6. For the MCP beta, type `https://mcp.wasabisys.dev/s3` from the page text. The links in the docs table point at a different host ## Connect ```bash import boto3 s3 = boto3.client( 's3', endpoint_url='https://s3.wasabisys.com', aws_access_key_id='YOUR_KEY', aws_secret_access_key='YOUR_SECRET' ) s3.upload_file('localfile.jpg', 'my-bucket-name', 'uploaded.jpg') ``` ```bash claude mcp add --transport http wasabi-s3 https://mcp.wasabisys.dev/s3 ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/wasabi-hot-cloud-storage ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Amazon S3 | BB | 77.9 | storage.object, storage.s3, storage.presigned | https://www.anchorterminal.com/tools/amazon-s3.min.md | | Cloudflare R2 | BB | 77.1 | storage.object, storage.s3, storage.presigned | https://www.anchorterminal.com/tools/cloudflare-r2.min.md | | Backblaze B2 | BB | 75.3 | storage.object, storage.s3, storage.presigned | https://www.anchorterminal.com/tools/backblaze-b2.min.md | | DigitalOcean Spaces | B | 63.2 | storage.object, storage.s3, storage.presigned | https://www.anchorterminal.com/tools/digitalocean-spaces.min.md | | Bunny Storage | C | 58.3 | storage.object, storage.s3, storage.presigned | https://www.anchorterminal.com/tools/bunny-storage.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)