Connect Cloudflare R2 with Blob0

Connect your R2 bucket to the Blob0 macOS desktop client: create bucket-scoped credentials, fill in the S3 API endpoint, test the connection, and save your profile.

For the public macOS release 0.1.0. Field and button names below match its English interface. Reviewed 2026-10-10.

Download and installation guide

1. Prepare your R2 bucket

Enable R2 in your Cloudflare account, then select an existing bucket or create one in R2 object storage. Note its exact name and account. You do not need to make the bucket public to manage it with Blob0; storage usage and API charges follow your Cloudflare plan.

2. Create S3 API credentials

  1. In the R2 overview, choose Manage beside API Tokens. Create an Account API token or User API token, depending on your account permissions.
  2. For file management, select Object Read & Write and apply it only to the bucket you will connect. For browsing and downloading only, Object Read only is sufficient; uploads and changes will fail with that permission.
  3. Copy the Access Key ID and Secret Access Key from the confirmation screen into a secure place. The secret is shown only once. Use this pair in Blob0, rather than the general Cloudflare API token value.
Cloudflare credential and permission documentation

3. Fill in the Blob0 connection form

On first launch, use the connection form. To add another bucket later, open the sidebar Settings gear → Connections → Add connection.

Copy the S3 API endpoint from Cloudflare. A default-jurisdiction endpoint has this shape:

https://<ACCOUNT_ID>.r2.cloudflarestorage.com

For EU, US or FedRAMP jurisdiction buckets, copy the matching jurisdiction-specific endpoint shown in Cloudflare. Do not append the bucket name or use an r2.dev / public custom domain as the API endpoint.

3. Fill in the Blob0 connection form
App fieldWhat to enter
Connection nameA local label, such as Personal R2. It does not rename your bucket.
S3 API endpointThe HTTPS endpoint from your R2 account, as explained above.
BucketThe exact bucket name, without a URL or folder prefix.
Regionauto — the R2 SDK region value and the default in Blob0.
Access Key IDThe Access Key ID from the R2 token confirmation.
Secret Access KeyThe matching Secret Access Key, with no extra whitespace.
Public / custom domainOptional. Leave blank for private access. Only set a public domain you have configured for direct file links; this field does not authenticate the connection.

4. Test, then save the connection

Select Test connection. Blob0 lists the bucket root without uploading or deleting objects. A successful result starts with Connected — and shows the number of items returned at the root; an empty bucket can correctly show 0 items.

Select Add connection after the test succeeds. Blob0 saves the profile and connects to the bucket. To switch between saved buckets later, use the sidebar connection menu. Access keys are stored in the macOS Keychain; the profile configuration stores non-sensitive metadata.

A successful listing confirms read/list access, not write permission. If you need uploads or changes, use the scoped read/write token. For an optional transfer check, use a small disposable file in your own bucket and remove it afterward.

Troubleshooting

AccessDenied or 403
Check that the token is valid, covers this bucket, and belongs to the account in the endpoint. If listing works but uploads fail, check Object Read & Write permission.
NoSuchBucket or 404
Check the exact bucket name, account endpoint and jurisdiction. The Bucket field is a name, not a URL.
SignatureDoesNotMatch
Re-enter the matching key pair without whitespace, use Region auto and the correct S3 endpoint, and check that your Mac clock is accurate.
Connection or network error
Check internet access and whether a proxy or firewall blocks the R2 endpoint. Keep public/custom domains separate from the S3 API endpoint.
No objects are visible
An empty root can be valid. Confirm the selected bucket and open its folder prefixes. The test result is not a recursive total of every object.

If the issue persists, send support your Blob0 version and the error message. Redact access keys, license codes and signed URLs from logs or screenshots. If a secret was exposed, revoke that token in Cloudflare and create a replacement.

Contact Blob0 support

Official references