Agent skill

Cloudflare R2

by einverne in einverne/dotfiles

Guide for implementing Cloudflare R2 - S3-compatible object storage with zero egress fees.

GPL-3.0Auto-check passedBackend & APIs

Install Cloudflare R2

skills CLI
$ npx skills add einverne/dotfiles --skill cloudflare-r2 -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install einverne/dotfiles cloudflare-r2 --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/einverne/dotfiles.git skills-src && mkdir -p .claude/skills && cp -r skills-src/claude/skills/cloudflare-r2 .claude/skills/cloudflare-r2 && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cloudflare-r2
GitHub stars
121
Token cost
~2.8k tokens
SKILL.md length
736 words
Files
5 (incl. references)
Skills in repo
39
Repo updated
First seen
Licence
GPL-3.0

At a glance

Guide for implementing Cloudflare R2 - S3-compatible object storage with zero egress fees.

  • Works in 3 steps: Create Bucket → Upload Object → Download Object
  • Implementing file storage
  • SKILL.md covers When to Use This Skill, Prerequisites, Core Concepts and Quick Start, plus 9 more sections
  • Calls wrangler, aws and npm; needs R2_ACCESS_KEY_ID and R2_SECRET_ACCESS_KEY

What it does

Cloudflare R2 is an agent skill from einverne/dotfiles. Guide for implementing Cloudflare R2 - S3-compatible object storage with zero egress fees. Use when implementing file storage, uploads/downloads, data migration to/from R2, configuring buckets, integrating with Workers, or working with R2 APIs and SDKs.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/api-reference.md`, `references/pricing-guide.md` and `references/sdk-examples.md`).

It sits in Backend & APIs, covering File uploads and storage. It works with Cloudflare R2, Amazon Web Services, Cloudflare Workers and Cloudflare. The repository describes itself as: my personal dotfiles managed by dotbot, zinit. The licence is GPL-3.0.

When your agent uses it

  • Implementing file storage
  • Uploads/downloads
  • Data migration to/from R2
  • Configuring buckets

Example prompts

  • “/cloudflare-r2”

Requirements

  • Python 3
  • Node.js
  • A credential in R2_SECRET_ACCESS_KEY
  • A credential in AWS_KEY

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Create Bucket
  2. Upload Object
  3. Download Object

What it can do on your machine

Read from SKILL.md and the folder at commit c6c0686. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • wrangler
    • aws
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • developers.cloudflare.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • R2_ACCESS_KEY_ID
    • R2_SECRET_ACCESS_KEY
    • AWS_KEY
    • AWS_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cloudflare R2 loads about 2.8k tokens when it runs, and up to ~20k if it reads all its reference files. Until then it costs about 67 tokens; SKILL.md has 736 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~67
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~20k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from einverne/dotfiles at commit c6c0686, republished under its GPL-3.0 licence (© einverne). 736 words, ~2,836 tokens.

Download SKILL.mdSave it as .claude/skills/cloudflare-r2/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
cloudflare-r2
description
Guide for implementing Cloudflare R2 - S3-compatible object storage with zero egress fees. Use when implementing file storage, uploads/downloads, data migration to/from R2, configuring buckets, integrating with Workers, or working with R2 APIs and SDKs.

Cloudflare R2

S3-compatible object storage with zero egress bandwidth fees. Built on Cloudflare's global network for high durability (11 nines) and strong consistency.

When to Use This Skill

  • Implementing object storage for applications
  • Migrating from AWS S3 or other storage providers
  • Setting up file uploads/downloads
  • Configuring public or private buckets
  • Integrating R2 with Cloudflare Workers
  • Using R2 with S3-compatible tools and SDKs
  • Configuring CORS, lifecycles, or event notifications
  • Optimizing storage costs with zero egress fees

Prerequisites

Required:

  • Cloudflare account with R2 purchased
  • Account ID from Cloudflare dashboard

For API access:

  • R2 Access Keys (Access Key ID + Secret Access Key)
  • Generate from: Cloudflare Dashboard → R2 → Manage R2 API Tokens

For Wrangler CLI:

bash
npm install -g wrangler
wrangler login

Core Concepts

Architecture
  • S3-compatible API - works with AWS SDKs and tools
  • Workers API - native Cloudflare Workers integration
  • Global network - strong consistency across all regions
  • Zero egress fees - no bandwidth charges for data retrieval
Storage Classes
  • Standard - default, optimized for frequent access
  • Infrequent Access - lower storage cost, retrieval fees apply, 30-day minimum
Access Methods
  1. R2 Workers Binding - serverless integration (recommended for new apps)
  2. S3 API - compatibility with existing tools
  3. Public buckets - direct HTTP access via custom domains or r2.dev
  4. Presigned URLs - temporary access without credentials

Quick Start

1. Create Bucket

Wrangler:

bash
wrangler r2 bucket create my-bucket

With location hint:

bash
wrangler r2 bucket create my-bucket --location=wnam

Locations: wnam (West NA), enam (East NA), weur (West EU), eeur (East EU), apac (Asia Pacific)

2. Upload Object

Wrangler:

bash
wrangler r2 object put my-bucket/file.txt --file=./local-file.txt

Workers API:

javascript
await env.MY_BUCKET.put('file.txt', fileContents, {
  httpMetadata: {
    contentType: 'text/plain',
  },
});
3. Download Object

Wrangler:

bash
wrangler r2 object get my-bucket/file.txt --file=./downloaded.txt

Workers API:

javascript
const object = await env.MY_BUCKET.get('file.txt');
const contents = await object.text();

Workers Integration

Binding Configuration

wrangler.toml:

toml
[[r2_buckets]]
binding = "MY_BUCKET"
bucket_name = "my-bucket"
preview_bucket_name = "my-bucket-preview"
Common Operations

Upload with metadata:

javascript
await env.MY_BUCKET.put('user-uploads/photo.jpg', imageData, {
  httpMetadata: {
    contentType: 'image/jpeg',
    cacheControl: 'public, max-age=31536000',
  },
  customMetadata: {
    uploadedBy: userId,
    uploadDate: new Date().toISOString(),
  },
});

Download with streaming:

javascript
const object = await env.MY_BUCKET.get('large-file.mp4');
if (object === null) {
  return new Response('Not found', { status: 404 });
}

return new Response(object.body, {
  headers: {
    'Content-Type': object.httpMetadata.contentType,
    'ETag': object.etag,
  },
});

List objects:

javascript
const listed = await env.MY_BUCKET.list({
  prefix: 'user-uploads/',
  limit: 100,
});

for (const object of listed.objects) {
  console.log(object.key, object.size);
}

Delete object:

javascript
await env.MY_BUCKET.delete('old-file.txt');

Check if object exists:

javascript
const object = await env.MY_BUCKET.head('file.txt');
if (object) {
  console.log('Exists:', object.size, 'bytes');
}

S3 SDK Integration

AWS CLI

Configure:

bash
aws configure
# Access Key ID: <your-key-id>
# Secret Access Key: <your-secret>
# Region: auto

Operations:

bash
# List buckets
aws s3api list-buckets --endpoint-url https://<accountid>.r2.cloudflarestorage.com

# Upload file
aws s3 cp file.txt s3://my-bucket/ --endpoint-url https://<accountid>.r2.cloudflarestorage.com

# Generate presigned URL (expires in 1 hour)
aws s3 presign s3://my-bucket/file.txt --endpoint-url https://<accountid>.r2.cloudflarestorage.com --expires-in 3600
JavaScript (AWS SDK v3)
javascript
import { S3Client, PutObjectCommand } from "@aws-sdk/client-s3";

const s3 = new S3Client({
  region: "auto",
  endpoint: `https://${accountId}.r2.cloudflarestorage.com`,
  credentials: {
    accessKeyId: process.env.R2_ACCESS_KEY_ID,
    secretAccessKey: process.env.R2_SECRET_ACCESS_KEY,
  },
});

await s3.send(new PutObjectCommand({
  Bucket: "my-bucket",
  Key: "file.txt",
  Body: fileContents,
}));
Python (Boto3)
python
import boto3

s3 = boto3.client(
    service_name="s3",
    endpoint_url=f'https://{account_id}.r2.cloudflarestorage.com',
    aws_access_key_id=access_key_id,
    aws_secret_access_key=secret_access_key,
    region_name="auto",
)

# Upload file
s3.upload_fileobj(file_obj, 'my-bucket', 'file.txt')

# Download file
s3.download_file('my-bucket', 'file.txt', './local-file.txt')
Rclone (Large Files)

Configure:

bash
rclone config
# Select: Amazon S3 → Cloudflare R2
# Enter credentials and endpoint

Upload with multipart optimization:

bash
# For large files (>100MB)
rclone copy large-video.mp4 r2:my-bucket/ \
  --s3-upload-cutoff=100M \
  --s3-chunk-size=100M

Public Buckets

Enable Public Access

Wrangler:

bash
wrangler r2 bucket create my-public-bucket
# Then enable in dashboard: R2 → Bucket → Settings → Public Access
Access URLs

r2.dev (development only, rate-limited):

https://pub-<hash>.r2.dev/file.txt

Custom domain (recommended for production):

  1. Dashboard → R2 → Bucket → Settings → Public Access
  2. Add custom domain
  3. Cloudflare handles DNS/TLS automatically

CORS Configuration

Required for:

  • Browser-based uploads
  • Cross-origin API calls
  • Presigned URL usage from web apps

Wrangler:

bash
wrangler r2 bucket cors put my-bucket --rules '[
  {
    "AllowedOrigins": ["https://example.com"],
    "AllowedMethods": ["GET", "PUT", "POST"],
    "AllowedHeaders": ["*"],
    "ExposeHeaders": ["ETag"],
    "MaxAgeSeconds": 3600
  }
]'

Important: Origins must match exactly (no trailing slash).

Multipart Uploads

For files >100MB or parallel uploads:

Workers API:

javascript
const multipart = await env.MY_BUCKET.createMultipartUpload('large-file.mp4');

// Upload parts (5MiB - 5GiB each, max 10,000 parts)
const part1 = await multipart.uploadPart(1, chunk1);
const part2 = await multipart.uploadPart(2, chunk2);

// Complete upload
const object = await multipart.complete([part1, part2]);

Constraints:

  • Part size: 5MiB - 5GiB
  • Max parts: 10,000
  • Max object size: 5TB
  • Incomplete uploads auto-abort after 7 days (configurable via lifecycle)

Data Migration

Sippy (Incremental, On-Demand)

Best for: Gradual migration, avoiding upfront egress fees

bash
# Enable for bucket
wrangler r2 bucket sippy enable my-bucket \
  --provider=aws \
  --bucket=source-bucket \
  --region=us-east-1 \
  --access-key-id=$AWS_KEY \
  --secret-access-key=$AWS_SECRET

Objects migrate when first requested. Subsequent requests served from R2.

Super Slurper (Bulk, One-Time)

Best for: Complete migration, known object list

  1. Dashboard → R2 → Data Migration → Super Slurper
  2. Select source provider (AWS, GCS, Azure)
  3. Enter credentials and bucket name
  4. Start migration

Lifecycle Rules

Auto-delete or transition storage classes:

Wrangler:

bash
wrangler r2 bucket lifecycle put my-bucket --rules '[
  {
    "action": {"type": "AbortIncompleteMultipartUpload"},
    "filter": {},
    "abortIncompleteMultipartUploadDays": 7
  },
  {
    "action": {"type": "Transition", "storageClass": "InfrequentAccess"},
    "filter": {"prefix": "archives/"},
    "daysFromCreation": 90
  }
]'

Event Notifications

Trigger Workers on bucket events:

Wrangler:

bash
wrangler r2 bucket notification create my-bucket \
  --queue=my-queue \
  --event-type=object-create

Supported events:

  • object-create - new uploads
  • object-delete - deletions

Message format:

json
{
  "account": "account-id",
  "bucket": "my-bucket",
  "object": {"key": "file.txt", "size": 1024, "etag": "..."},
  "action": "PutObject",
  "eventTime": "2024-01-15T12:00:00Z"
}
Show full SKILL.md (288 more words)Show less

Best Practices

Performance
  • Use Cloudflare Cache with custom domains for frequently accessed objects
  • Multipart uploads for files >100MB (faster, more reliable)
  • Rclone for batch operations (concurrent transfers)
  • Location hints match user geography
Security
  • Never commit Access Keys to version control
  • Use environment variables for credentials
  • Bucket-scoped tokens for least privilege
  • Presigned URLs for temporary access
  • Enable Cloudflare Access for additional protection
Cost Optimization
  • Infrequent Access storage for archives (30+ day retention)
  • Lifecycle rules to auto-transition or delete
  • Larger multipart chunks = fewer Class A operations
  • Monitor usage via dashboard analytics
Naming
  • Bucket names: lowercase, hyphens, 3-63 chars
  • Avoid sequential prefixes for better performance (e.g., use hashed prefixes)
  • No dots in bucket names if using custom domains with TLS

Limits

  • Buckets per account: 1,000
  • Object size: 5TB max
  • Bucket name: 3-63 characters
  • Lifecycle rules: 1,000 per bucket
  • Event notification rules: 100 per bucket
  • r2.dev rate limit: 1,000 req/min (use custom domains for production)

Troubleshooting

401 Unauthorized:

  • Verify Access Keys are correct
  • Check endpoint URL includes account ID
  • Ensure region is "auto" for most operations

403 Forbidden:

  • Check bucket permissions and token scopes
  • Verify CORS configuration for browser requests
  • Confirm bucket exists and name is correct

404 Not Found:

  • Object key case-sensitive
  • Check bucket name spelling
  • Verify object was uploaded successfully

Presigned URLs not working:

  • Verify CORS configuration
  • Check URL expiry time
  • Ensure origin matches CORS rules exactly

Multipart upload failures:

  • Part size must be 5MiB - 5GiB
  • Max 10,000 parts per upload
  • Complete upload within 7 days (or configure lifecycle)

Reference Files

For detailed documentation, see:

  • references/api-reference.md - Complete API endpoint documentation
  • references/sdk-examples.md - SDK examples for all languages
  • references/workers-patterns.md - Advanced Workers integration patterns
  • references/pricing-guide.md - Detailed pricing and cost optimization

Additional Resources

© einverne, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in claude/skills/cloudflare-r2 of einverne/dotfiles.

  • SKILL.md
  • references/api-reference.md
  • references/pricing-guide.md
  • references/sdk-examples.md
  • references/workers-patterns.md

Open the folder on GitHubat commit c6c0686

Compare with similar skills

Cloudflare R2 next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cloudflare R2 compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cloudflare R2 this skilleinverne/dotfiles121—~2.8kAutomated safety check: PassGPL-3.0
Cloudflare R2sickn33/agentic-awesome-skills47k2 repos~2.5kAutomated safety check: PassMIT
Neon Object Storageneondatabase/agent-skills100—~3.5kAutomated safety check: NotesApache-2.0
Olore Opennext Latestolorehq/olore104—~825Automated safety check: PassMIT
Basincloudflare/skills3k1 repos~684Automated safety check: PassApache-2.0
Vercel Migration Deep Divejeremylongshore/tons-of-skills-marketplace2.8k—~2kAutomated safety check: NotesMIT

Similar skills

  • Cloudflare R2

    sickn33/agentic-awesome-skills

    Manage Cloudflare R2 buckets, lifecycle, and signed URLs. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~2.5k tokens
    Backend & APIsAuto-check passed
  • Neon Object Storage

    neondatabase/agent-skills

    Official

    S3-compatible object storage that branches with your Neon project, so files and the database stay in sync across every branch.

    100 GitHub stars~3.5k tokensUpdated today
    Backend & APIsAuto-check: notes
  • Local opennext documentation reference (latest). An agent skill from olorehq/olore.

    104 GitHub stars~825 tokensUpdated today
    Backend & APIsAuto-check passed
  • Basin

    cloudflare/skills

    Official

    Build and troubleshoot Cloudflare Basin analytics workflows with Basin Pipelines, Basin Catalog, and Basin SQL.

    3k GitHub starsUsed in 1 repo~684 tokens
    DatabasesAuto-check passed
  • Vercel Migration Deep Dive

    jeremylongshore/tons-of-skills-marketplace

    Migrate to Vercel from other platforms or re-architecture existing Vercel deployments.

    2.8k GitHub stars~2k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Cloudflare 3

    sundial-org/awesome-openclaw-skills

    Manage Cloudflare Workers, KV, D1, R2, and secrets using the Wrangler CLI.

    663 GitHub stars~1.5k tokensUpdated 7 mo ago
    DevOps & CloudAuto-check passed

More from einverne/dotfiles

All 39 skills in this repo
  • DOCX

    einverne/dotfiles

    Comprehensive document creation, editing, and analysis with support for tracked changes, comments, formatting preservation, and text extraction.

    121 GitHub starsUsed in 35 repos~2.5k tokens
    Auto-check: notes
  • Chrome Devtools

    einverne/dotfiles

    Browser automation, debugging, and performance analysis using Puppeteer CLI scripts.

    121 GitHub starsUsed in 1 repo~1.6k tokens
    Auto-check: notes
  • PDF

    einverne/dotfiles

    Comprehensive PDF manipulation toolkit for extracting text and tables, creating new PDFs, merging/splitting documents, and handling forms.

    121 GitHub starsUsed in 47 repos~1.8k tokens
    Auto-check passed
  • Gemini Audio

    einverne/dotfiles

    Guide for implementing Google Gemini API audio capabilities - analyze audio with transcription, summarization, and understanding (up to 9.5 hours), plus generate speech with controllable TTS.

    121 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check: notes
  • Guide for implementing Google Gemini API document processing - analyze PDFs with native vision to extract text, images, diagrams, charts, and tables.

    121 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check: notes
  • PPTX

    einverne/dotfiles

    Presentation creation, editing, and analysis. An agent skill from einverne/dotfiles.

    121 GitHub starsUsed in 38 repos~6.4k tokens
    Auto-check: notes

Categories

Questions about Cloudflare R2

What does Cloudflare R2 do?

Guide for implementing Cloudflare R2 - S3-compatible object storage with zero egress fees. Cloudflare R2 is an agent skill from einverne/dotfiles. Guide for implementing Cloudflare R2 - S3-compatible object storage with zero egress fees.

When should I use Cloudflare R2?

Cloudflare R2 fits situations like: implementing file storage; uploads/downloads; data migration to/from R2; configuring buckets.

How do I install Cloudflare R2 in Claude Code?

Run `npx skills add einverne/dotfiles --skill cloudflare-r2 -a claude-code`. Or copy the skill folder (claude/skills/cloudflare-r2 in einverne/dotfiles) into .claude/skills/cloudflare-r2 in your project. Claude Code loads it when a task matches its description.

How do I install Cloudflare R2 in Codex?

Run `npx skills add einverne/dotfiles --skill cloudflare-r2 -a codex`. Or copy the skill folder (claude/skills/cloudflare-r2 in einverne/dotfiles) into .agents/skills/cloudflare-r2 in your project. Codex loads it when a task matches its description.

Can I use Cloudflare R2 in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add einverne/dotfiles --skill cloudflare-r2 -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloudflare-r2, .gemini/skills/cloudflare-r2, .github/skills/cloudflare-r2 and .opencode/skills/cloudflare-r2 in your project.

What does Cloudflare R2 need to run?

Going by SKILL.md and its folder, Cloudflare R2 needs the command-line tools its instructions call (wrangler, aws and npm) and credentials named R2_ACCESS_KEY_ID, R2_SECRET_ACCESS_KEY, AWS_KEY and AWS_SECRET. Our summary lists: Python 3; Node.js; A credential in R2_SECRET_ACCESS_KEY; A credential in AWS_KEY.

Does Cloudflare R2 access the network?

SKILL.md names 1 domain. As links in the text: developers.cloudflare.com. This is read from the text; nothing was executed.

Is Cloudflare R2 safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cloudflare R2 use?

Cloudflare R2 is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cloudflare R2 use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 17k tokens, read only when the agent opens those files.

What are the alternatives to Cloudflare R2?

Skills that share tags, products or a category with Cloudflare R2: Cloudflare R2 (sickn33/agentic-awesome-skills, 47k stars), Neon Object Storage (neondatabase/agent-skills, 100 stars), Olore Opennext Latest (olorehq/olore, 104 stars) and Basin (cloudflare/skills, 3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cloudflare R2?

einverne (a GitHub user) maintains it in einverne/dotfiles, which has 121 GitHub stars. The repository holds 39 skills in this directory. The repository was last updated on September 9, 2026.

Source: einverne/dotfiles on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.