Cloudflare R2
Engine: S3-compatible (AWS SigV4) · Preset: Cloudflare R2
R2 is S3's API with no egress fees, which makes it the natural home for an uploader whose whole output is public links.
Configuration
Settings → Hosts → + → Cloudflare R2.
| Field | Value |
|---|---|
| Endpoint | https://<ACCOUNT_ID>.r2.cloudflarestorage.com |
| Region | auto |
| Bucket | The bucket name alone, e.g. assets |
| Access Key ID | From the R2 API token |
| Secret Access Key | From the same token — goes to the keychain |
| Public base URL | Your r2.dev or custom domain — see below |
| Object key template | images/{{date}}/{{uuid}}.{{ext}} |
Two things trip people up, both about the endpoint:
- It is the account origin, not the bucket URL. Do not append the bucket —
that field exists for a reason, and Dropline builds
endpoint/bucket/keyitself. <ACCOUNT_ID>is a hex string, not your email or domain. Find it in the Cloudflare dashboard under R2 → Overview, in the S3 API box on the right, or in the URL of any R2 page.
The region is always auto. R2 has no regions in the AWS sense; it accepts the
signature as long as the profile and the request agree.
Create the bucket and token
- Cloudflare dashboard → R2 → Create bucket. Choose a name; the location hint is optional.
- R2 → API → Manage API tokens → Create API token.
- Permission: Object Read & Write. Scope it to Apply to specific buckets and pick just this one.
- Create. Copy the Access Key ID and Secret Access Key — the secret is shown once.
R2 tokens cannot be narrowed to a key prefix, only to a bucket, so use one bucket per purpose if you want isolation.
Make the bucket public
R2 buckets are private by default and there is no bucket-policy equivalent. Two options:
A managed r2.dev subdomain — quickest, rate-limited, fine for personal
use. Bucket → Settings → Public access → R2.dev subdomain → Allow access.
You get:
https://pub-<hash>.r2.dev
A custom domain — what you want for anything real. Bucket → Settings → Custom domains → Connect domain, on a zone in the same Cloudflare account. Traffic is then served and cached by Cloudflare's CDN with no rate limit:
https://cdn.example.com
Either way, paste that origin into Public base URL. Without it, Dropline
returns the …r2.cloudflarestorage.com/bucket/key URL, which is the API
endpoint and requires a signature — it will not open in a browser.
The link you get back
https://cdn.example.com/images/2026/08/19/a1f3….png
Verify
Test Upload, then open the URL. If the upload succeeds but the link returns
401 or 404, public access is not enabled or the base URL is still the API
endpoint.
Common problems
| Symptom | Cause |
|---|---|
SignatureDoesNotMatch |
The endpoint has the bucket appended, or a trailing slash |
HTTP 401 on upload |
Token lacks Object Read & Write, or is scoped to another bucket |
| Link asks for a signature | Public base URL is still the r2.cloudflarestorage.com endpoint |
| Link 404s | Public access not enabled on the bucket |
Cost note
R2 charges for storage and operations but not for egress. For an uploader whose whole output is links other people load, that is usually the difference between a few cents and a real bill.