Skip to content

Cloudflare R2

Cloudflare R2 is S3-compatible. In ConstellaWP, choose provider Cloudflare R2. ConstellaWP builds the endpoint as https://{account_id}.r2.cloudflarestorage.com.

  • A Cloudflare account with R2 enabled
  • Permission to create buckets and R2 API tokens
  • ConstellaWP role owner or admin
  1. In the Cloudflare dashboard, open R2 and create a bucket. Note the bucket name.

    Cloudflare R2: create a bucket
  2. On the R2 overview, copy the Account ID (also in the right sidebar of most Cloudflare pages).

    Cloudflare: Account ID on the R2 overview
  3. Create an R2 API token with Object Read & Write on this bucket (or the account). Cloudflare shows an Access Key ID and Secret Access Key — these are S3 credentials, not the global Cloudflare API token.

    Cloudflare R2: create API token with Object Read and Write
  4. In ConstellaWP, go to Storage → Add Destination:

    • Provider: Cloudflare R2
    • Fill the fields from the table below
    • Save, then Test connection
ConstellaWP field Where to find it in Cloudflare
Bucket R2 bucket name
Cloudflare Account ID Account ID on the R2 overview (32 hex characters)
Access Key ID Access Key ID from the R2 API token dialog
Secret Access Key Secret Access Key from the same dialog
Path prefix Chosen by you; default backups

There is no Region field for R2. ConstellaWP uses region auto.

Error Likely cause
Unauthorized / SignatureDoesNotMatch Used a profile API token instead of R2 S3 credentials
NoSuchBucket Bucket name typo, or token scoped to another bucket
Account ID rejected Extra spaces, or the zone ID pasted instead of the account ID
AccessDenied Token is read-only; grant Object Read and Write (test deletes the probe object)