Cloudflare R2
Cloudflare R2 is S3-compatible. In ConstellaWP, choose provider Cloudflare R2. ConstellaWP builds the endpoint as https://{account_id}.r2.cloudflarestorage.com.
Prerequisites
Section titled “Prerequisites”- A Cloudflare account with R2 enabled
- Permission to create buckets and R2 API tokens
- ConstellaWP role owner or admin
-
In the Cloudflare dashboard, open R2 and create a bucket. Note the bucket name.
Cloudflare R2: create a bucketsrc/assets/storage/cloudflare-r2/create-bucket.pngCloudflare R2: create a bucket -
On the R2 overview, copy the Account ID (also in the right sidebar of most Cloudflare pages).
Cloudflare: Account ID on the R2 overviewsrc/assets/storage/cloudflare-r2/account-id.pngCloudflare: Account ID on the R2 overview -
Create an R2 API token with Object Read & Write on this bucket (or the account). Cloudflare shows an Access Key ID and Secret Access Key — these are S3 credentials, not the global Cloudflare API token.
Cloudflare R2: create API token with Object Read and Writesrc/assets/storage/cloudflare-r2/create-api-token.pngCloudflare R2: create API token with Object Read and Write -
In ConstellaWP, go to Storage → Add Destination:
- Provider: Cloudflare R2
- Fill the fields from the table below
- Save, then Test connection
Field mapping
Section titled “Field mapping”| ConstellaWP field | Where to find it in Cloudflare |
|---|---|
| Bucket | R2 bucket name |
| Cloudflare Account ID | Account ID on the R2 overview (32 hex characters) |
| Access Key ID | Access Key ID from the R2 API token dialog |
| Secret Access Key | Secret Access Key from the same dialog |
| Path prefix | Chosen by you; default backups |
There is no Region field for R2. ConstellaWP uses region auto.
Common errors
Section titled “Common errors”| Error | Likely cause |
|---|---|
| Unauthorized / SignatureDoesNotMatch | Used a profile API token instead of R2 S3 credentials |
| NoSuchBucket | Bucket name typo, or token scoped to another bucket |
| Account ID rejected | Extra spaces, or the zone ID pasted instead of the account ID |
| AccessDenied | Token is read-only; grant Object Read and Write (test deletes the probe object) |