Skip to main content
Blob Storage keeps your files, serves public ones from a CDN and hands out links to private ones. This page takes you from an API key to an uploaded file and a download link, with curl. Storage is included in every plan: see Blob Storage for the plans, prices and FAQ.

Base URL

Every endpoint of this reference is relative to:

Authentication

Blob Storage takes the same API keys as the Square Cloud API, in the Authorization header. The key needs the blob:write scope to upload and blob:read to list and download, and it can’t be restricted to specific applications. Create one in your account security settings and keep it in an environment variable:
More on scopes and upload tokens in Authentication.

Upload a file

Object Post takes the file as multipart/form-data and its name, without extension, in the query:
The file is public by default: url works right away in a browser or an <img> tag. Store the id as it comes, since every other route takes it. A single request takes files from 512 bytes to 100 MB. Larger files, up to 10 GiB, go through the chunked upload or the S3 gateway.

Upload a private file

Add private=true and the file gets no public URL (url is null):

Download a file

A public file downloads from its url. For a private one, Object Download signs a temporary link that works without credentials, and redirects to it, so curl -L saves the file:
Replace <id> with the id of the upload. Add redirect=false to get the link as JSON and hand it to someone else. For links you can revoke or protect with a password, create a share link.

List and delete files

Object List returns your files page by page:
Objects Delete removes one file, or up to 100 in one request:

When something fails

Errors come as { "status": "error", "code": "..." }. The ones you are most likely to meet first: Every code is in Errors.

Next steps

Blob SDK

Upload and manage files from JavaScript, with chunked uploads handled for you.

S3 compatibility

Use aws-cli, boto3, rclone or any AWS SDK.

Links and sharing

Temporary links, share links and when to use each.

Upload from the browser

Let visitors upload without exposing your API key.