Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

For a one-off screenshot, upload the local image in the Backblaze B2 web console. For an automated website or browser workflow, keep B2 credentials on your server and give the browser only a narrowly scoped upload capability. Backblaze provides both a B2 Native API and an S3-Compatible API. Its documentation recommends the S3-Compatible API for new applications when you already work with S3 because more SDKs and libraries support it.

Choose the upload route

Route Best for Important limits and security points
Web console Occasional manual uploads Select a bucket and local file. The documented maximum is 500 MB per individual file. Public buckets allow unauthenticated reads, not public writes.
B2 Native API B2-specific features or mediated browser uploads Your server obtains an upload URL and token, then the client sends the file to that URL. The token can upload to any path in the bucket, so do not expose it broadly.
S3-Compatible API Existing S3 code, SDKs, or presigned URLs Presigned uploads are supported. Browser presigned POST uploads are not supported by Backblaze; use a presigned upload URL instead.

Manual upload in the Backblaze console

  1. Sign in to the Backblaze web console and open Buckets.
  2. Select the destination bucket.
  3. Choose the upload action, select the screenshot from your computer, and start the transfer.
  4. Verify the object name and content type after the upload. Use image/png, image/jpeg, or the type matching the actual file.

This path is intentionally simple: it requires no application credentials or CORS configuration. It is not a practical replacement for an automated capture pipeline, and the 500 MB limit applies to each file uploaded through the console.

Automated uploads with the B2 Native API

A Native API upload has two requests. First, your trusted server calls b2_get_upload_url for the bucket. B2 returns an upload URL tied to a storage pod and an authorization token. Second, the client sends the image bytes to that returned URL with b2_upload_file.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Server-side authorization

Keep the account key, application key, authorization response, upload URL, and upload token on your server. A browser should never receive account-level credentials. If you let a browser call the authorization or upload-URL endpoint directly, a malicious user could reuse the resulting capability.

#1 Best Overall
Sandisk 2TB Extreme Portable SSD, Up to 1050MB/s, USB-C, USB 3.2 Gen 2, IP65 Water and Dust Resistance, Updated Firmware, External Solid State Drive, SDSSDE61-2T00-G25
  • Get NVMe solid state performance with up to 1050MB/s read and 1000MB/s write speeds in a portable, high-capacity drive(1) (Based on internal testing; performance may be lower depending on host device & other factors. 1MB=1,000,000 bytes.)
  • Up to 3-meter drop protection and IP65 water and dust resistance mean this tough drive can take a beating(3) (Previously rated for 2-meter drop protection and IP55 rating. Now qualified for the higher, stated specs.)
  • Use the handy carabiner loop to secure it to your belt loop or backpack for extra peace of mind.
  • Help keep private content private with the included password protection featuring 256‐bit AES hardware encryption.(3)
  • Easily manage files and automatically free up space with the SanDisk Memory Zone app.(5). Non-Operating Temperature -20°C to 85°C

Request requirements

  • Send the complete file body, not a multipart form wrapper, to the returned upload URL.
  • Include Content-Length. Chunked transfer encoding without this header is not supported.
  • Provide the file name and an accurate content type such as image/png or image/jpeg.
  • Keep custom file information and headers small. Backblaze documents a combined file-name/file-information limit of 7,000 bytes in most cases, reduced to 2,048 bytes for server-side-encrypted or Object Lock files.

Illustrative server flow

The exact authorization endpoint and credentials depend on your B2 account configuration. Your server implementation should perform this sequence:

  1. Authorize the application with the B2 Native API.
  2. Call b2_get_upload_url with the bucket identifier.
  3. Return a short-lived application response to your browser containing only the upload URL, upload token, object name, and any metadata your server has chosen.
  4. Have the browser issue the upload request to that URL with the screenshot bytes and Content-Length.
  5. Record the returned file identifier and name on your server.

When a storage pod returns a 50X response, obtain a new upload URL and token, then retry. Do not blindly reuse a failed URL forever.

Browser upload example

After your server has supplied the capability, browser JavaScript can upload a selected file directly:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
async function uploadScreenshot(file, capability) {
  const response = await fetch(capability.uploadUrl, {
    method: "POST",
    headers: {
      "Authorization": capability.uploadToken,
      "X-Bz-File-Name": encodeURIComponent(capability.fileName),
      "Content-Type": file.type || "application/octet-stream",
      "Content-Length": String(file.size),
      "X-Bz-Content-Sha1": "do_not_verify"
    },
    body: file
  });
  if (!response.ok) throw new Error(`B2 upload failed: ${response.status}`);
  return response.json();
}

Your server must configure a CORS rule that permits the browser origin and the upload request. CORS only enables the upload call; it does not make authorization or upload-URL acquisition safe to move into untrusted browser code.

Rank #2
SSK Portable SSD 500GB External Solid State Hard Drive USB C Up to 1050MB/s
  • Capacity Display Variance: 500GB external ssd often appears as around 465GB on Windows. MacOS can show full 500 GB capacity. This is binary calculation difference and doesn’t affect SSD hard drive actual physical storage
  • 1050 MB/s Speed: Instantly access to your files with blazing-fast 10Gbps external SSD read up to 1050MB/s and write up to 1000MB/s. LED Light indicates USB SSD instant activity
  • Data Security: Solid state drives S.M.A.R.T. health diagnostics​ and adaptive TRIM optimizing data block management ensures consistent write speeds and extends the longevity of the portable SSD
  • USB-C & USB-A Cable: Both cables featuring rapid USB 3.2 Gen2, this USB SSD effortlessly bridges devices, enabling seamless cross-platform file transfers and backup between computers, smartphones, tablets and iPhone
  • Always Fast: No slowdowns for large file transfers. With SLC caching (25% of current available capacity allocated as high-speed cache), this external SSD delivers steady 10Gbps for transfers within the cache capacity

Parallel and large-file uploads

Each concurrent Native API upload needs its own upload URL and token. For files that require multipart operations, use the Native API’s large-file sequence and finish with b2_finish_large_file. A normal PNG or JPEG screenshot is usually much smaller, but full-page captures and generated PDFs should still be checked against your application’s size limits.

S3-Compatible uploads and presigned URLs

The S3-Compatible API is a natural fit when your application already uses S3 tooling. Backblaze states that this API supports presigned URLs for downloading and uploading. Your server creates a presigned upload URL with the intended bucket, object key, content type, and expiration; the browser then performs a PUT to that URL. The browser does not receive your S3 access key or secret.

Presigned browser sequence

  1. The browser sends your application a request such as “prepare an upload,” including only the screenshot’s intended logical name and size.
  2. Your server validates the user, chooses the final B2 object key, and creates a presigned PUT URL.
  3. The server returns that URL and the required headers to the browser.
  4. The browser uploads the bytes with fetch(url, { method: "PUT", headers, body: file }).
  5. Your server records the object key after a successful response.

Do not implement this as a presigned browser POST form: Backblaze documents that browser presigned POST uploads are unsupported. Configure S3 CORS for the exact web origin and methods you use.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Object names, content types, and privacy

Names

Backblaze does not prescribe screenshot naming. A useful application convention is a server-generated path containing a user or job identifier and a collision-resistant suffix, for example captures/account-42/2026-09-29T120000Z-8f3c.png. Treat this as an application design choice, not a B2 requirement. Never trust a browser-supplied path to decide where another user’s files are stored.

Rank #3
Sale
Sandisk 1TB Extreme Portable SSD, Up to 2000MB/s Transfer Speeds-New Model
  • NEARLY 2X FASTER THAN OUR PREVIOUS GENERATION(8) – move 1,000 high-res photos in under 60 seconds(6) with up to 2000MB/s transfer speeds(2).
  • IP65 RATING AND UP TO 3M DROP PROTECTION(3) – protects against spills and drops.
  • POCKET-SIZED – fits easily in pockets and small bags.
  • SPACE TO OWN YOUR AI CONTENT – speed and capacity to download your high-res clips and photo edits.
  • 256-BIT AES ENCRYPTION(4) – helps keep private files secure with password protection.

Content type

Set the MIME type that matches the bytes. A PNG should be image/png; a JPEG should be image/jpeg. Incorrect metadata can cause browsers to download an image as an unknown file or display it incorrectly.

Access control

Use a private bucket when screenshots contain personal, customer, or unpublished information. A public bucket makes objects readable without credentials, but it is not publicly writable. For private files, deliver access through authenticated application responses or time-limited download authorization.

Capturing screenshots before you upload

If your source is a website, separate capture from storage. A browser automation job can save a PNG or JPEG locally, then send that file through either the Native API or an S3 presigned URL. Decide whether you need full-page scrolling, a particular viewport, a dark color scheme, or a single CSS-selected element before creating the object key and content type. Keep retention and deletion rules in your application because the B2 documentation does not define screenshot-specific policies.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Or skip the browser setup

ScreenshotNeo returns a website screenshot or PDF from one request, so your server can send the response directly to B2. Before capture it accepts cookie and consent banners and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each cleanup step can be disabled. Bot checks, CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and whether it was billed. Its MCP server provides take_screenshot, get_page_info, and capture_pdf tools for Claude, Cursor, and other MCP clients.

Use the API details in the ScreenshotNeo documentation. For example:

Rank #4
Sandisk 1TB Portable SSD, Up to 800MB/s Read Speeds, Black (Old Model)
  • Solid state performance with up to 800MB/s read speeds in a portable drive. (Based on internal testing; performance may be lower depending on host device, interface, usage conditions and other factors. 1MB=1,000,000 bytes.)
  • Back up your content and memories on a storage solution that fits seamlessly into your mobile lifestyle.
  • Take it with you on your adventures—up to two-meter drop protection means this durable drive can take a beating. (Based on internal testing.)
  • Secure it to your belt loop or backpack for extra peace of mind thanks to the tough rubber hook.
  • From Sandisk, a brand professional photographers trust to take on assignments.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
r.raise_for_status()
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`Screenshot failed: ${res.status}`);
const bytes = Buffer.from(await res.arrayBuffer());
require('fs').writeFileSync('shot.webp', bytes);

Upload the resulting file to B2 using the server-side flow above. ScreenshotNeo has a free plan with 1,000 screenshots per month and no card; paid plans start at $5 for 3,000 screenshots. Create a free ScreenshotNeo account.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting

401 or 403 from B2

Check that the authorization token belongs to the same upload URL and has not expired. For browser flows, confirm your server—not the browser—is performing authorization.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

400 caused by request length

Send an exact Content-Length and the raw file bytes. Remove multipart wrappers and avoid chunked transfer encoding for Native API uploads.

CORS error in the browser

Add your exact origin and required upload method and headers to the bucket’s CORS configuration. A CORS rule cannot compensate for an invalid token or an attempt to call authorization endpoints from the browser.

Best Value
Sale
Samsung T7 Portable SSD 1TB Titan Gray, USB 3.2 Gen 2, Up to 1,050MB/s
  • MADE FOR THE MAKERS: Create; Explore; Store; The T7 Portable SSD delivers fast speeds and durable features to back up any endeavor; Build your video editing empire, file your photographs or back up your blogs all in an instant
  • SHARE IDEAS IN A FLASH: Don’t waste a second waiting and spend more time doing; The T7 is embedded with PCIe NVMe technology that brings fast read and write speeds up to 1,050/1,000 MB/s¹, making it almost twice as fast as the T5
  • ALWAYS MAKE THE SAVE: Compact design with massive capacity; With capacities up to 4TB, save exactly what you need to your drive – from large working files to game data and everything in between
  • ADAPTS TO EVERY NEED: Whether using a PC or mobile phone, count on the T7 for extensive compatibility²; It’s a true team player when it comes to heavy-duty application usage or file-saving
  • HI RESOLUTION VIDEO RECORDING: Record Ultra High Resolution (4K 60fs) videos directly onto the T7 Portable SSD with your favorite camera or mobile devices; Supports iPhone 15 Pro Res 4K at 60fps video and more³

50X from an upload URL

Request a fresh upload URL and token, then retry the file. For parallel jobs, ensure every worker has its own pair.

Image opens as a download or unknown file

Set the object content type to the actual image MIME type and avoid excessive file information headers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Operational checklist

  • Keep B2 account and application credentials server-side.
  • Generate object names server-side and prevent path traversal or cross-user writes.
  • Use a private bucket unless public reading is intentional.
  • Set the correct MIME type and exact content length.
  • Refresh Native API upload URLs after 50X responses.
  • Give each parallel Native API worker its own upload URL and token.
  • Test CORS with the production origin, not only localhost.
  • Log B2 file identifiers and your capture job ID so failed uploads can be retried safely.

Frequently Asked Questions

Can a browser upload directly to Backblaze B2?

Yes, after your server obtains a Native API upload URL and token or creates an S3-compatible presigned upload URL. Do not expose account credentials or move authorization into browser code.

Are screenshots uploaded to a public B2 bucket writable by anyone?

No. Public access makes objects readable without credentials; it does not make the bucket publicly writable.

Should I use Native API or S3-Compatible API?

Use Native API when you need B2-specific operations or its direct upload-URL flow. If you already use S3 SDKs, Backblaze recommends the S3-Compatible API for new applications because of its broader SDK and library support.

Quick Recap

SaleBestseller No. 3
Sandisk 1TB Extreme Portable SSD, Up to 2000MB/s Transfer Speeds-New Model
Sandisk 1TB Extreme Portable SSD, Up to 2000MB/s Transfer Speeds-New Model
IP65 RATING AND UP TO 3M DROP PROTECTION(3) – protects against spills and drops.; POCKET-SIZED – fits easily in pockets and small bags.
$253.00
Bestseller No. 4
Sandisk 1TB Portable SSD, Up to 800MB/s Read Speeds, Black (Old Model)
Sandisk 1TB Portable SSD, Up to 800MB/s Read Speeds, Black (Old Model)
From Sandisk, a brand professional photographers trust to take on assignments.
$188.90

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.