DroplineDownload

Cloudflare R2

Engine: S3-compatible (AWS SigV4) · Preset: Cloudflare R2

R2 is S3's API with no egress fees, which makes it the natural home for an uploader whose whole output is public links.

Configuration

Settings → Hosts → + → Cloudflare R2.

Field Value
Endpoint https://<ACCOUNT_ID>.r2.cloudflarestorage.com
Region auto
Bucket The bucket name alone, e.g. assets
Access Key ID From the R2 API token
Secret Access Key From the same token — goes to the keychain
Public base URL Your r2.dev or custom domain — see below
Object key template images/{{date}}/{{uuid}}.{{ext}}

Two things trip people up, both about the endpoint:

  • It is the account origin, not the bucket URL. Do not append the bucket — that field exists for a reason, and Dropline builds endpoint/bucket/key itself.
  • <ACCOUNT_ID> is a hex string, not your email or domain. Find it in the Cloudflare dashboard under R2 → Overview, in the S3 API box on the right, or in the URL of any R2 page.

The region is always auto. R2 has no regions in the AWS sense; it accepts the signature as long as the profile and the request agree.

Create the bucket and token

  1. Cloudflare dashboard → R2 → Create bucket. Choose a name; the location hint is optional.
  2. R2 → API → Manage API tokens → Create API token.
  3. Permission: Object Read & Write. Scope it to Apply to specific buckets and pick just this one.
  4. Create. Copy the Access Key ID and Secret Access Key — the secret is shown once.

R2 tokens cannot be narrowed to a key prefix, only to a bucket, so use one bucket per purpose if you want isolation.

Make the bucket public

R2 buckets are private by default and there is no bucket-policy equivalent. Two options:

A managed r2.dev subdomain — quickest, rate-limited, fine for personal use. Bucket → Settings → Public access → R2.dev subdomain → Allow access. You get:

text
https://pub-<hash>.r2.dev

A custom domain — what you want for anything real. Bucket → Settings → Custom domains → Connect domain, on a zone in the same Cloudflare account. Traffic is then served and cached by Cloudflare's CDN with no rate limit:

text
https://cdn.example.com

Either way, paste that origin into Public base URL. Without it, Dropline returns the …r2.cloudflarestorage.com/bucket/key URL, which is the API endpoint and requires a signature — it will not open in a browser.

text
https://cdn.example.com/images/2026/08/19/a1f3….png

Verify

Test Upload, then open the URL. If the upload succeeds but the link returns 401 or 404, public access is not enabled or the base URL is still the API endpoint.

Common problems

Symptom Cause
SignatureDoesNotMatch The endpoint has the bucket appended, or a trailing slash
HTTP 401 on upload Token lacks Object Read & Write, or is scoped to another bucket
Link asks for a signature Public base URL is still the r2.cloudflarestorage.com endpoint
Link 404s Public access not enabled on the bucket

Cost note

R2 charges for storage and operations but not for egress. For an uploader whose whole output is links other people load, that is usually the difference between a few cents and a real bill.

On this page