R2 Bucket Boss

Setting up your Cloudflare R2 credentials

A step-by-step walkthrough for connecting R2 Bucket Boss to your Cloudflare R2 buckets.

R2 Bucket Boss needs two separate Cloudflare credentials, plus your Account ID: an API Token for browsing and creating buckets/folders and purging your CDN cache, and a separate R2 Access Key ID / Secret Access Key pair for the S3-compatible file transfers themselves. If you also want R2BB to generate shareable web links, you'll set up a Public URL for the bucket too.

1. Account ID

1

Find your Account ID

Open the R2 Overview page in your Cloudflare dashboard. Scroll to the bottom of the page and look for the Account ID section. (If on desktop browser it may be in the right side column)

Copy the account ID text and paste it here.

Find your Account ID Open R2 Overview →

2. Account API Token

1

Open your Account API Tokens page

Open the Cloudflare dashboard via the link below. Cloudflare has two kinds of API token - make sure the page says “Account API Tokens,” not “User API Tokens.” (If it opens to the wrong one, it's under a different menu: your account name in the sidebar → “Manage Account” → “API Tokens.”) An Account token keeps working no matter who created it or whether they're still around - a User token stops working if that person ever leaves or loses access, which is the wrong trade-off for an app's saved credentials.

Once you're on the right page, click “Create Token.”

Open Account API Tokens →
2

Create a custom token

Choose “Custom token” → “Get started.”.

Create a custom token
3

Add the required permissions

Add the following permissions, clicking “+ Add more” before each new one after the first:
a) “Account – Workers R2 Storage – Edit”
b) “Zone – Cache Purge – Purge” - pick “Specific zone” and the domain your CDN URL uses, not “All zones”
c) “Zone – Zone – Read” for that same specific zone - without this, purging silently does nothing on every upload; Cache Purge alone can't look up the zone it needs to purge
d) “Account – Stream – Edit” - every Cloudflare account has a “stream” folder shown alongside your buckets, and without this permission opening it shows an error. (The other fields are optional.)

Scroll to the bottom and tap "Continue to summary."

Add the required permissions
4

Review and create the token

Review the summary, then click “Create Token.”

Copy the token value shown into this field - it's only ever shown once, so make a note of it somewhere secure. This token is separate from the Access Key ID/Secret Access Key below; it's what lets this app create buckets and purge the CDN cache.

Review and create the token

3. R2 Access Key ID

1

Open Manage R2 API Tokens

This is a separate credential from the API Token above - open “Manage R2 API Tokens” via the link below, then click “Create API token.”

Open Manage R2 API Tokens →
2

Choose Object Read & Write

Choose “Object Read & Write.” Creating new buckets and folders uses the API Token above, not this credential, so “Admin Read & Write” isn't needed here.

Give it a name, then continue.

Choose Object Read & Write
3

Create the R2 token

Click “Create Account API Token” to finish.

Create the R2 token
4

Copy your Access Key ID

Scroll down on that same confirmation page to “Use the following credentials for S3 clients.”

Copy the Access Key ID shown into this field, and the Secret Access Key into the field below - the secret is only ever shown once.

Copy your Access Key ID

4. R2 Secret Access Key

1

Copy your Secret Access Key

Shown once, alongside the Access Key ID, when you create that R2 token. If you didn't save it, you'll need to create a new one to get a new pair.

5. Public URL

1

Open your bucket

Required in order to provide web-ready URLs. Open your bucket list via the link below, then click the bucket you use with this server - the link opens the list, not a specific bucket's settings.

Open your R2 buckets →
2

Open the Settings tab

Open that bucket's “Settings” tab, at the top of the page.

Open the Settings tab
3

Enable a Custom Domain or Public Development URL

Scroll down to either “Custom Domains” (recommended for production) or “Public Development URL” (a quick, non-production URL) and enable one.

Enable a Custom Domain or Public Development URL
4

Or hand it off to your LLM

(Optional) Skip the steps above entirely and hand this off instead - copy this prompt into an LLM that has Cloudflare API/“wrangler” access, and it can add the custom domain (or enable the Public Development URL) for you and hand back the value to paste here.

✓

Connect in R2BB

In R2 Bucket Boss, add a new R2 session with your Account ID, the API Token, and your R2 Access Key ID / Secret Access Key from the steps above. The endpoint is:

https://ACCOUNT_ID.r2.cloudflarestorage.com

← Back to R2 Bucket Boss

CONTACT US: