How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC
Backblaze website screenshot

Backblaze

Backblaze is a cloud storage and data backup provider offering B2 Cloud Storage - a low-cost, S3-compatible object storage service. Backblaze provides both a native B2 API and an S3-compatible API, enabling developers to build applications that store unlimited data at a fraction of major cloud provider costs. Features include file versioning, lifecycle rules, event notifications, object lock, cross-region replication, and a Cloudflare bandwidth alliance for zero-egress CDN delivery.

agent ready

Real signal across most facets with visible, nameable gaps — the contract exists but is thin, or the portal is good while governance and commercial terms are absent.

Kin Score

API Evangelist profiles Backblaze the way a machine reads it — 181 machine-readable artifacts across 7 APIs, pulled from the provider's own public surface and indexed so a developer, an analyst, or an AI agent can evaluate it against every other provider on the network.

Every provider in the network is reduced to the same set of machine-readable artifacts — OpenAPI contracts, event specifications, GraphQL schemas, runnable collections, pricing and rate-limit signals, security posture, OAuth scopes, and the agent surfaces (MCP servers and skills) that let software drive the API on its own. We profile them because the interface is the part of a company you can actually inspect: it is a truer signal of what a provider does than any marketing page. From those artifacts we compute the Kin Score — Backblaze scores 47.0/100 (developing), with a separate agent-readiness read of 32/100 (agent ready). The full breakdown is below, followed by every artifact we hold — each card links through to its machine-readable definition on apis.io.

Kin Score

This is the API Evangelist rating — a single, repeatable read computed from the artifacts on this page. Green fill is points earned; the red track is points possible, so every bar shows earned-versus-possible at a glance. Every facet and dimension name is a link: it opens that measurement's page on APIs.io, where the rating runs across the whole catalog — the exact checks that feed it, how every profiled provider distributes on it, and who is at the top of it.

Kin Score Kin Score How this is scored →
scored 2026-09-10 · rubric v0.20.0
Backblaze Kin Score — API readiness rating by API Evangelist

Put this on your own site. The badge is drawn live from Backblaze's current Kin Score — paste it once and it updates itself every time the score is recomputed. It follows your visitor's light or dark setting, and it links back here so anyone who sees it can read the full breakdown.

<!-- Kin Score · API Evangelist -->
<a href="https://providers.apievangelist.com/providers/backblaze/"
   title="Backblaze on API Evangelist — API profile and Kin Score">
  <img src="https://apis.io/badge/backblaze.svg"
       alt="Backblaze Kin Score — API readiness rating by API Evangelist" width="150" height="150" loading="lazy">
</a>

More shapes, themes and sizes → · Score as JSON · How badges work

How we profile Backblaze

Each block below is one kind of artifact we hold for Backblaze. For each we say what it is and why it earns a place in the profile, then list every one we've indexed — capped at two rows, scroll within the panel for the rest.

APIs 7

Each API is captured as its own OpenAPI definition — every operation, parameter, and response. This is the single most useful machine-readable description of what an API does, and it's what lets us score, lint, mock, and generate against it without asking the provider for anything.

Individual APIs this provider publishes, each with its own machine-readable definition.

Backblaze S3-Compatible API

The Backblaze S3-Compatible API allows existing applications built for Amazon S3 to work with Backblaze B2 Cloud Storage with minimal code changes. Supports S3 authentication (A...

Backblaze Application Keys API

Create and manage application keys for access control

Backblaze Authorization API

Account authorization and token management

Backblaze Buckets API

Bucket creation, management, and configuration

Backblaze Files API

File upload, download, listing, deletion, and metadata

Backblaze Large Files API

Multi-part upload for large files

Backblaze Notifications API

Bucket event notification configuration

Scroll within the panel for all 7 ·

Postman Collections 1

A runnable collection turns the contract into something a developer can execute in seconds. We profile them because the fastest way to trust an API is to make a real call against it.

Ready-to-run Postman collections for exercising this provider's APIs.

Open Collections 7

Open, tool-agnostic collections carry the same runnable value as Postman without locking you to one client — the portable, forkable form of the same exercise.

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

Scroll within the panel for all 7 ·

Arazzo Workflows 13

Real integrations are rarely a single call. Arazzo describes the multi-step sequences — auth, then create, then confirm — so both a human and an agent can follow the choreography, not just the endpoints.

Multi-step API workflows described with the Arazzo specification.

Backblaze Authorize and Provision Bucket

Authorize the account, then create a new private bucket using the returned account context.

ARAZZO

Backblaze Browse Bucket Files

Authorize, list buckets, list the file names in a bucket, then fetch full info for the first file.

ARAZZO

Backblaze Clean Up Unfinished Large Files

Authorize, list unfinished large files in a bucket, then cancel the first stalled upload found.

ARAZZO

Backblaze Configure Bucket Event Notifications

Authorize, set a webhook notification rule on a bucket, then read the rules back to confirm.

ARAZZO

Backblaze Copy a File Into Another Bucket

Authorize, locate a source file by listing, then server-side copy it into a destination bucket.

ARAZZO

Backblaze Create Scoped Application Key

Authorize, create a capability-scoped application key, then confirm it appears in the key list.

ARAZZO

Backblaze Large File Multi-Part Upload

Authorize, start a large file, get a part upload URL, then finish the large file from its parts.

ARAZZO

Backblaze Provision Bucket and Upload First File

Authorize, create a bucket, get its upload URL, and upload the first file end to end.

ARAZZO

Backblaze Purge a File's Versions

Authorize, list a file's versions by prefix, then delete the most recent version found.

ARAZZO

Backblaze Rotate Application Key

Authorize, create a replacement application key, then delete the old key it supersedes.

ARAZZO

Backblaze Share Private Files

Authorize, mint a prefix-scoped download authorization token, then download a private file by name.

ARAZZO

Backblaze Tear Down a Bucket

Authorize, list a bucket's file names, delete the first file version, then delete the empty bucket.

ARAZZO

Backblaze Upload a File

Authorize, request a bucket upload URL, then upload a single file to that bucket.

ARAZZO

Scroll within the panel for all 13 ·

Pricing Plans 1

Pricing is part of the interface. Machine-readable plans tell you what a tier costs and includes before you commit — one of the things the Kin Score reads for access clarity — renamed from commercial clarity in rubric 0.12, because a free statutory interface has access terms and no commercial ones.

Published pricing tiers and plan structures.

Rate Limits 1

Rate limits are the difference between a demo that works and a production integration that doesn't fall over. Publishing them is an operational-transparency signal — and a hard requirement for any agent that plans its own throughput.

Documented rate limits and quota policies.

Backblaze Rate Limits

5 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals let a buyer model the financial operations of an API before it's live. We profile them for the same reason we profile pricing: the money is part of the contract.

Cost, billing, and metering signals for API financial operations.

Features 11

The notable capabilities this provider advertises, captured as structured features so they can be searched and compared instead of read one landing page at a time.

Notable capabilities this provider offers.

Object Storage

Store and retrieve any amount of data with a simple flat namespace and unique file IDs.

S3-Compatible API

Use existing S3 tools and libraries without modification via the S3-compatible API endpoint.

Large File Multi-Part Upload

Upload files larger than 5GB using the multi-part upload API (b2_start_large_file / b2_upload_part / b2_finish_large_file).

Application Key Management

Create and manage scoped application keys with per-bucket and per-prefix restrictions.

Lifecycle Rules

Automatically delete or hide files after a specified number of days using lifecycle rules.

File Versioning

Keep multiple versions of files; older versions are preserved and accessible by file ID.

Event Notifications

Configure webhook-based event notifications when objects are created, modified, or deleted.

Object Lock

Protect files from deletion or modification for a specified retention period using object lock.

Cross-Region Replication

Replicate buckets to other regions or accounts for disaster recovery and data locality.

Server-Side Encryption

Encrypt data at rest using Backblaze-managed or customer-managed keys.

Cloudflare Bandwidth Alliance

Zero egress fees when serving B2 data through Cloudflare CDN.

Scroll within the panel for all 11 ·

Semantic Vocabularies 1

JSON-LD contexts give the data shared meaning across APIs. We profile them because semantics are what let a machine reconcile 'customer' here with 'customer' somewhere else.

JSON-LD contexts and semantic vocabularies used across these APIs.

Backblaze B2 Context

42 classes · 68 properties

JSON-LD

Spectral Rules 2

Governance rulesets we run against this provider's specs — the automated checks behind parts of the score. Profiling them makes the quality bar explicit and re-runnable, not a matter of opinion.

Backblaze API Rules

5 rules · 3 warnings

SPECTRAL

Backblaze API Rules

36 rules · 12 errors · 16 warnings

SPECTRAL

JSON Schema 42

Standalone JSON Schema definitions describe the data models behind the API. We profile them so the shapes are validatable on their own — useful long after a single request is forgotten.

Standalone JSON Schema definitions for this provider's data models.

AllowedCapabilities

4 properties

JSON SCHEMA

ApiInfo

1 properties

JSON SCHEMA

ApplicationKey

8 properties

JSON SCHEMA

AuthorizeAccountResponse

4 properties

JSON SCHEMA

BucketNotificationRulesResponse

2 properties

JSON SCHEMA

Bucket

8 properties

JSON SCHEMA

CancelLargeFileRequest

1 properties

JSON SCHEMA

CancelLargeFileResponse

4 properties

JSON SCHEMA

CopyFileRequest

5 properties

JSON SCHEMA

CreateBucketRequest

6 properties

JSON SCHEMA

CreateKeyRequest

6 properties

JSON SCHEMA

DeleteBucketRequest

2 properties

JSON SCHEMA

DeleteFileVersionRequest

3 properties

JSON SCHEMA

DeleteFileVersionResponse

2 properties

JSON SCHEMA

DeleteKeyRequest

1 properties

JSON SCHEMA

FileInfo

10 properties

JSON SCHEMA

FinishLargeFileRequest

2 properties

JSON SCHEMA

GetBucketNotificationRulesRequest

1 properties

JSON SCHEMA

GetDownloadAuthorizationRequest

3 properties

JSON SCHEMA

GetDownloadAuthorizationResponse

3 properties

JSON SCHEMA

GetFileInfoRequest

1 properties

JSON SCHEMA

GetUploadPartUrlRequest

1 properties

JSON SCHEMA

GetUploadPartUrlResponse

3 properties

JSON SCHEMA

GetUploadUrlRequest

1 properties

JSON SCHEMA

GetUploadUrlResponse

3 properties

JSON SCHEMA

HideFileRequest

2 properties

JSON SCHEMA

ListBucketsRequest

4 properties

JSON SCHEMA

ListBucketsResponse

1 properties

JSON SCHEMA

ListFileNamesRequest

5 properties

JSON SCHEMA

ListFileNamesResponse

2 properties

JSON SCHEMA

ListFileVersionsRequest

6 properties

JSON SCHEMA

ListFileVersionsResponse

3 properties

JSON SCHEMA

ListKeysRequest

3 properties

JSON SCHEMA

ListKeysResponse

2 properties

JSON SCHEMA

ListPartsRequest

3 properties

JSON SCHEMA

ListPartsResponse

2 properties

JSON SCHEMA

ListUnfinishedLargeFilesRequest

4 properties

JSON SCHEMA

ListUnfinishedLargeFilesResponse

2 properties

JSON SCHEMA

NotificationRule

4 properties

JSON SCHEMA

SetBucketNotificationRulesRequest

2 properties

JSON SCHEMA

StartLargeFileRequest

5 properties

JSON SCHEMA

UpdateBucketRequest

7 properties

JSON SCHEMA

Scroll within the panel for all 42 ·

JSON Structure 42

JSON Structure captures the data shapes in a form built for tooling — a complement to JSON Schema that keeps the model machine-legible.

JSON Structure definitions describing this provider's data shapes.

B2 Native Api Api Info Structure

1 properties

JSON STRUCTURE

B2 Native Api Application Key Structure

8 properties

JSON STRUCTURE

B2 Native Api Bucket Structure

8 properties

JSON STRUCTURE

B2 Native Api Copy File Request Structure

5 properties

JSON STRUCTURE

B2 Native Api Create Key Request Structure

6 properties

JSON STRUCTURE

B2 Native Api Delete Key Request Structure

1 properties

JSON STRUCTURE

B2 Native Api File Info Structure

10 properties

JSON STRUCTURE

B2 Native Api Hide File Request Structure

2 properties

JSON STRUCTURE

B2 Native Api List Keys Request Structure

3 properties

JSON STRUCTURE

B2 Native Api List Keys Response Structure

2 properties

JSON STRUCTURE

B2 Native Api List Parts Request Structure

3 properties

JSON STRUCTURE

B2 Native Api Notification Rule Structure

4 properties

JSON STRUCTURE

Scroll within the panel for all 42 ·

Examples 42

Real request and response payloads are what turn a spec from abstract into obvious — and they're one of the twelve things an agent needs to call an API correctly on the first try.

Example request and response payloads for these APIs.

Scroll within the panel for all 42 ·

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals — the evidence that a provider takes security seriously enough to document it. We profile it because you can't govern what you can't see.

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Backblaze Authentication

http · 2 schemes

SECURITY

Backblaze Domain Security

TLSv1.3 · HSTS · DNSSEC · DMARC

SECURITY

Backblaze Trust Center

SOC 2 Type 2, ISO 27001, HIPAA, GDPR, UK GDPR, CCPA/CPRA, PCI-DSS, GovRAMP, TX-RAMP, HECVAT, TPN (Trusted Partner Network) Blue Shield, VPAT (Section 508), Internet2 Cloud Score...

SECURITY

Agentic Access 1

An x-agentic-access contract marks which operations are safe for an agent to run on its own and which need a human in the loop. It is the difference between an API an agent can use and one it can use safely.

Recommended x-agentic-access execution contracts for AI agents.

Backblaze Agentic Access

27 operations · 24 acting

27 operations · 24 acting

AGENTIC

Use Cases 6

What developers actually build with this provider — captured so the catalogue answers 'what is this for', not just 'what does this expose'.

What developers build with this provider.

Application Data Storage

Store application data, user-uploaded content, and media files in the cloud.

Backup and Disaster Recovery

Use Backblaze B2 as the storage backend for backup tools like Arq, MSP360, and Veeam.

Media Hosting and Delivery

Host images, videos, and other media files and serve them via CDN integration.

Archival Storage

Store infrequently accessed archival data at low cost with lifecycle-based management.

Data Migration

Migrate data from S3 or other cloud storage providers using the S3-compatible API.

CI/CD Artifact Storage

Store build artifacts, logs, and deployment packages in B2 buckets.

Resources

Every other property we hold for Backblaze — documentation, portals, status pages, policies, and corporate surface — grouped by the job it does, following the integrator's arc from getting started to running in production.

Get Started 3

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Access & Security 3

Authentication, authorization, and security posture

Commercial 3

Pricing, plans, and the legal terms of use

Company 3

The organization behind the API

Other 1

Properties that don't map to a standard resource type

← All providers · Data indexed from github.com/api-evangelist/backblaze · machine-readable index on apis.io

Where this information came from

This is an independent, third-party profile of Backblaze, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.