{"_id":"@backblaze-labs/b2-sdk","_rev":"4-62fa9f22165467775ff2fed36ad0136f","name":"@backblaze-labs/b2-sdk","dist-tags":{"latest":"0.4.0"},"versions":{"0.1.0":{"name":"@backblaze-labs/b2-sdk","version":"0.1.0","keywords":["backblaze","b2","cloud-storage","object-storage","s3","upload","download","multipart","streaming","typescript"],"author":"Backblaze, Inc.","license":"MIT","_id":"@backblaze-labs/b2-sdk@0.1.0","maintainers":[{"name":"goanpeca","email":"goanpeca@gmail.com"},{"name":"jdnyc","email":"jdeleon@jdeleon.com"}],"homepage":"https://github.com/backblaze-labs/b2-sdk-typescript#readme","bugs":{"url":"https://github.com/backblaze-labs/b2-sdk-typescript/issues"},"dist":{"shasum":"0e7dc68a43a100163a3f15be7e60b81a0134327a","tarball":"https://registry.npmjs.org/@backblaze-labs/b2-sdk/-/b2-sdk-0.1.0.tgz","fileCount":512,"integrity":"sha512-cpXLay7OTkalGUPmROBZrjvPrwVgUxDwEKZkpYoLwCTyxr6ykhP2y6X4uZ7BUZsn3EyRqPhXEk9U3RDC2VhgDw==","signatures":[{"sig":"MEUCIAqmRwsAbEsCNt+wrCW87GlWmyK0MpfvqfNGXkIrEY1RAiEA0Y2C+r9X7SGnyrP4KesJWDM7B3jNafmf8so0Caxe/c0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2572828},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=22"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./s3":{"import":{"types":"./dist/s3/index.d.ts","default":"./dist/s3/index.js"},"require":{"types":"./dist/s3/index.d.cts","default":"./dist/s3/index.cjs"}},"./raw":{"import":{"types":"./dist/raw/index.d.ts","default":"./dist/raw/index.js"},"require":{"types":"./dist/raw/index.d.cts","default":"./dist/raw/index.cjs"}},"./auth":{"import":{"types":"./dist/auth/index.d.ts","default":"./dist/auth/index.js"},"require":{"types":"./dist/auth/index.d.cts","default":"./dist/auth/index.cjs"}},"./sync":{"import":{"types":"./dist/sync/index.d.ts","default":"./dist/sync/index.js"},"require":{"types":"./dist/sync/index.d.cts","default":"./dist/sync/index.cjs"}},"./errors":{"import":{"types":"./dist/errors/index.d.ts","default":"./dist/errors/index.js"},"require":{"types":"./dist/errors/index.d.cts","default":"./dist/errors/index.cjs"}},"./streams":{"import":{"types":"./dist/streams/index.d.ts","default":"./dist/streams/index.js"},"require":{"types":"./dist/streams/index.d.cts","default":"./dist/streams/index.cjs"}},"./auth/file":{"import":{"types":"./dist/auth/file.d.ts","default":"./dist/auth/file.js"},"require":{"types":"./dist/auth/file.d.cts","default":"./dist/auth/file.cjs"}},"./simulator":{"import":{"types":"./dist/simulator/index.d.ts","default":"./dist/simulator/index.js"},"require":{"types":"./dist/simulator/index.d.cts","default":"./dist/simulator/index.cjs"}},"./notifications":{"import":{"types":"./dist/notifications/index.d.ts","default":"./dist/notifications/index.js"},"require":{"types":"./dist/notifications/index.d.cts","default":"./dist/notifications/index.cjs"}}},"scripts":{"docs":"typedoc","lint":"biome check --error-on-warnings .","test":"vitest run","build":"vite build && node scripts/build-cts-types.mjs","clean":"rm -rf dist docs","verify":"pnpm run lint && pnpm run lint:docs && pnpm run lint:spelling && pnpm run typecheck && pnpm run typecheck:examples && pnpm run test && pnpm run build && pnpm run docs && pnpm run verify:metadata && pnpm run verify:exports","version":"node scripts/cut-changelog.mjs && git add CHANGELOG.md","lint:fix":"biome check --write .","test:all":"vitest run && vitest run --config vitest.slow.config.ts","lint:docs":"eslint src/ --no-warn-ignored","test:slow":"vitest run --config vitest.slow.config.ts","typecheck":"tsc --noEmit","docs:watch":"typedoc --watch","test:watch":"vitest","test:browser":"vitest run --config vitest.browser.config.ts","lint:docs:fix":"eslint src/ --fix --no-warn-ignored","lint:spelling":"cspell --no-progress --gitignore \"src/**/*.ts\" \"examples/**/*.ts\" \"examples/**/*.md\" \"*.md\" \"CLAUDE.md\"","test:coverage":"vitest run --config vitest.coverage.config.ts --coverage","verify:exports":"node scripts/verify-package-exports.mjs","verify:metadata":"node scripts/verify-package-metadata.mjs","test:integration":"vitest run --config vitest.integration.ts","typecheck:examples":"tsc --noEmit -p examples/tsconfig.json"},"_npmUser":{"name":"goanpeca","email":"goanpeca@gmail.com"},"repository":{"url":"https://github.com/backblaze-labs/b2-sdk-typescript","type":"git"},"description":"The official Backblaze B2 Cloud Storage SDK for TypeScript and JavaScript","directories":{},"sideEffects":false,"_nodeVersion":"24.10.0","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"vite":"^6.3.0","cspell":"^10.0.0","eslint":"^10.3.0","vitest":"^3.1.0","typedoc":"^0.28.19","@eslint/js":"^10.0.1","playwright":"^1.59.1","typescript":"^5.7.0","@types/node":"^25.6.2","@biomejs/biome":"^1.9.0","@vitest/browser":"^3.2.4","vite-plugin-dts":"^4.5.0","typescript-eslint":"^8.59.2","@vitest/coverage-v8":"^3.2.4","eslint-plugin-jsdoc":"^62.9.0","eslint-plugin-tsdoc":"^0.5.2","@microsoft/tsdoc-config":"^0.18.1"},"peerDependencies":{"@aws-sdk/client-s3":"^3.0.0"},"peerDependenciesMeta":{"@aws-sdk/client-s3":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/b2-sdk_0.1.0_1780016238105_0.7101514624051122","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@backblaze-labs/b2-sdk","version":"0.2.0","keywords":["backblaze","b2","cloud-storage","object-storage","s3","upload","download","multipart","streaming","typescript"],"author":{"name":"Backblaze, Inc."},"license":"MIT","_id":"@backblaze-labs/b2-sdk@0.2.0","maintainers":[{"name":"goanpeca","email":"goanpeca@gmail.com"},{"name":"jdnyc","email":"jdeleon@jdeleon.com"}],"homepage":"https://github.com/backblaze-labs/b2-sdk-typescript#readme","bugs":{"url":"https://github.com/backblaze-labs/b2-sdk-typescript/issues"},"dist":{"shasum":"0980efdac15132b1da85d7ff1a37baa69ee00e9c","tarball":"https://registry.npmjs.org/@backblaze-labs/b2-sdk/-/b2-sdk-0.2.0.tgz","fileCount":764,"integrity":"sha512-qYjCVtFuiHp54R8okZbuG7oVU0U0Xj9A/Yn4VBLeMKp5JxVKFp3+M3Ywry+aB6ZKX24P3NTh8JURZMGuayFWDQ==","signatures":[{"sig":"MEUCIQCeUedVQQlvy/dClmivhrFpjXzuniidTrd9gyjp5bOXFAIgLnyxZVfNC3JV7HcpAmEktsXxOkwhZZagOXcPP1sSego=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@backblaze-labs%2fb2-sdk@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":4898053},"main":"./dist/index.cjs","type":"module","_from":"file:.release/backblaze-labs-b2-sdk-0.2.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=22.3.0"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./s3":{"import":{"types":"./dist/s3/index.d.ts","default":"./dist/s3/index.js"},"require":{"types":"./dist/s3/index.d.cts","default":"./dist/s3/index.cjs"}},"./raw":{"import":{"types":"./dist/raw/index.d.ts","default":"./dist/raw/index.js"},"require":{"types":"./dist/raw/index.d.cts","default":"./dist/raw/index.cjs"}},"./auth":{"import":{"types":"./dist/auth/index.d.ts","default":"./dist/auth/index.js"},"require":{"types":"./dist/auth/index.d.cts","default":"./dist/auth/index.cjs"}},"./sync":{"import":{"types":"./dist/sync/index.d.ts","default":"./dist/sync/index.js"},"require":{"types":"./dist/sync/index.d.cts","default":"./dist/sync/index.cjs"}},"./errors":{"import":{"types":"./dist/errors/index.d.ts","default":"./dist/errors/index.js"},"require":{"types":"./dist/errors/index.d.cts","default":"./dist/errors/index.cjs"}},"./streams":{"import":{"types":"./dist/streams/index.d.ts","default":"./dist/streams/index.js"},"require":{"types":"./dist/streams/index.d.cts","default":"./dist/streams/index.cjs"}},"./auth/file":{"import":{"types":"./dist/auth/file.d.ts","default":"./dist/auth/file.js"},"require":{"types":"./dist/auth/file.d.cts","default":"./dist/auth/file.cjs"}},"./simulator":{"import":{"types":"./dist/simulator/index.d.ts","default":"./dist/simulator/index.js"},"require":{"types":"./dist/simulator/index.d.cts","default":"./dist/simulator/index.cjs"}},"./notifications":{"import":{"types":"./dist/notifications/index.d.ts","default":"./dist/notifications/index.js"},"require":{"types":"./dist/notifications/index.d.cts","default":"./dist/notifications/index.cjs"}}},"scripts":{"docs":"typedoc","lint":"biome check --error-on-warnings .","test":"vitest run","build":"vite build && node scripts/build-cts-types.mjs","clean":"rm -rf dist docs","verify":"pnpm run lint && pnpm run lint:docs && pnpm run lint:spelling && pnpm run typecheck && pnpm run typecheck:examples && pnpm run test && pnpm run build && pnpm run docs && pnpm run verify:metadata && pnpm run verify:release && pnpm run verify:exports","version":"node scripts/cut-changelog.mjs && git add CHANGELOG.md","lint:fix":"biome check --write .","test:all":"vitest run && vitest run --config vitest.slow.config.ts","lint:docs":"eslint src/ --no-warn-ignored","test:slow":"vitest run --config vitest.slow.config.ts","typecheck":"tsc --noEmit","docs:watch":"typedoc --watch","test:watch":"vitest","test:browser":"vitest run --config vitest.browser.config.ts","lint:docs:fix":"eslint src/ --fix --no-warn-ignored","lint:spelling":"cspell --no-progress --gitignore \"src/**/*.ts\" \"examples/**/*.ts\" \"examples/**/*.md\" \"*.md\" \"CLAUDE.md\"","test:coverage":"vitest run --config vitest.coverage.config.ts --coverage","verify:exports":"node scripts/verify-package-exports.mjs","verify:release":"node scripts/verify-release-workflow.mjs","verify:metadata":"node scripts/verify-package-metadata.mjs","test:integration":"vitest run --config vitest.integration.ts","typecheck:examples":"tsc --noEmit -p examples/tsconfig.json","verify:release-workflow":"node scripts/verify-release-workflow.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:eec9f7df-91b4-4dab-ba12-d2caa3fd8c4c"}},"_resolved":"/home/runner/work/b2-sdk-typescript/b2-sdk-typescript/.release/backblaze-labs-b2-sdk-0.2.0.tgz","_integrity":"sha512-qYjCVtFuiHp54R8okZbuG7oVU0U0Xj9A/Yn4VBLeMKp5JxVKFp3+M3Ywry+aB6ZKX24P3NTh8JURZMGuayFWDQ==","repository":{"url":"git+https://github.com/backblaze-labs/b2-sdk-typescript.git","type":"git"},"_npmVersion":"11.16.0","description":"The official Backblaze B2 Cloud Storage SDK for TypeScript and JavaScript","directories":{},"sideEffects":false,"_nodeVersion":"24.18.0","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"vite":"^8.1.0","cspell":"^10.0.1","eslint":"^10.6.0","vitest":"^4.1.9","typedoc":"^0.28.19","@eslint/js":"^10.0.1","playwright":"^1.61.1","typescript":"^6.0.3","@types/node":"^26.0.0","@biomejs/biome":"^2.5.1","@vitest/browser":"^4.1.9","vite-plugin-dts":"^5.0.3","typescript-eslint":"^8.62.0","@vitest/coverage-v8":"^4.1.9","eslint-plugin-jsdoc":"^63.0.10","eslint-plugin-tsdoc":"^0.5.2","@microsoft/tsdoc-config":"^0.18.1","@vitest/browser-playwright":"^4.1.9"},"peerDependencies":{"@aws-sdk/client-s3":"^3.0.0"},"peerDependenciesMeta":{"@aws-sdk/client-s3":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/b2-sdk_0.2.0_1783520187459_0.5724930263541386","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@backblaze-labs/b2-sdk","version":"0.3.0","keywords":["backblaze","b2","cloud-storage","object-storage","s3","upload","download","multipart","streaming","typescript"],"author":{"name":"Backblaze, Inc."},"license":"MIT","_id":"@backblaze-labs/b2-sdk@0.3.0","maintainers":[{"name":"goanpeca","email":"goanpeca@gmail.com"},{"name":"jdnyc","email":"jdeleon@jdeleon.com"}],"homepage":"https://github.com/backblaze-labs/b2-sdk-typescript#readme","bugs":{"url":"https://github.com/backblaze-labs/b2-sdk-typescript/issues"},"dist":{"shasum":"09d57a7062e3dd189e157da7840d3b51abc0dafa","tarball":"https://registry.npmjs.org/@backblaze-labs/b2-sdk/-/b2-sdk-0.3.0.tgz","fileCount":916,"integrity":"sha512-ABfrCTV0uN3ADXBgOC6hmMm2n3Mcnz2mnFafC1z1/Hvijv9GKlhaNBmfkY3UiRuVyjgWFCm8f5uiuQyNWFwFAg==","signatures":[{"sig":"MEYCIQDq4lnrav/SDG085hI8Ns+ZapS4k69zOCOeoVCV1YCuVwIhAMaqdpi+c3QXRcuhpCaCTfAC76JjMQ7d99A1K9tm7yPn","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@backblaze-labs%2fb2-sdk@0.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":6507676},"main":"./dist/index.cjs","type":"module","_from":"file:.release/backblaze-labs-b2-sdk-0.3.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=22.3.0"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./s3":{"import":{"types":"./dist/s3/index.d.ts","default":"./dist/s3/index.js"},"require":{"types":"./dist/s3/index.d.cts","default":"./dist/s3/index.cjs"}},"./raw":{"import":{"types":"./dist/raw/index.d.ts","default":"./dist/raw/index.js"},"require":{"types":"./dist/raw/index.d.cts","default":"./dist/raw/index.cjs"}},"./auth":{"import":{"types":"./dist/auth/index.d.ts","default":"./dist/auth/index.js"},"require":{"types":"./dist/auth/index.d.cts","default":"./dist/auth/index.cjs"}},"./sync":{"import":{"types":"./dist/sync/index.d.ts","default":"./dist/sync/index.js"},"require":{"types":"./dist/sync/index.d.cts","default":"./dist/sync/index.cjs"}},"./backup":{"import":{"types":"./dist/backup/index.d.ts","default":"./dist/backup/index.js"},"require":{"types":"./dist/backup/index.d.cts","default":"./dist/backup/index.cjs"}},"./errors":{"import":{"types":"./dist/errors/index.d.ts","default":"./dist/errors/index.js"},"require":{"types":"./dist/errors/index.d.cts","default":"./dist/errors/index.cjs"}},"./partner":{"import":{"types":"./dist/partner/index.d.ts","default":"./dist/partner/index.js"},"require":{"types":"./dist/partner/index.d.cts","default":"./dist/partner/index.cjs"}},"./streams":{"import":{"types":"./dist/streams/index.d.ts","default":"./dist/streams/index.js"},"require":{"types":"./dist/streams/index.d.cts","default":"./dist/streams/index.cjs"}},"./auth/file":{"import":{"types":"./dist/auth/file.d.ts","default":"./dist/auth/file.js"},"require":{"types":"./dist/auth/file.d.cts","default":"./dist/auth/file.cjs"}},"./simulator":{"import":{"types":"./dist/simulator/index.d.ts","default":"./dist/simulator/index.js"},"require":{"types":"./dist/simulator/index.d.cts","default":"./dist/simulator/index.cjs"}},"./notifications":{"import":{"types":"./dist/notifications/index.d.ts","default":"./dist/notifications/index.js"},"require":{"types":"./dist/notifications/index.d.cts","default":"./dist/notifications/index.cjs"}}},"scripts":{"docs":"typedoc","lint":"biome check --error-on-warnings .","test":"vitest run","build":"vite build && node scripts/build-cts-types.mjs","clean":"rm -rf dist docs","verify":"pnpm run lint && pnpm run lint:docs && pnpm run lint:spelling && pnpm run typecheck && pnpm run typecheck:examples && pnpm run test && pnpm run build && pnpm run docs && pnpm run verify:metadata && pnpm run verify:release && pnpm run verify:exports","version":"node scripts/cut-changelog.mjs && git add CHANGELOG.md","lint:fix":"biome check --write .","test:all":"vitest run && vitest run --config vitest.slow.config.ts","lint:docs":"eslint src/ --no-warn-ignored","test:slow":"vitest run --config vitest.slow.config.ts","typecheck":"tsc --noEmit","docs:watch":"typedoc --watch","test:watch":"vitest","test:browser":"vitest run --config vitest.browser.config.ts","lint:docs:fix":"eslint src/ --fix --no-warn-ignored","lint:spelling":"cspell --no-progress --gitignore \"src/**/*.ts\" \"examples/**/*.ts\" \"examples/**/*.md\" \"adr/**/*.md\" \"*.md\" \"CLAUDE.md\"","test:coverage":"vitest run --config vitest.coverage.config.ts --coverage","verify:exports":"node scripts/verify-package-exports.mjs","verify:release":"node scripts/verify-release-workflow.mjs","smoke:published":"node scripts/smoke-published-package.mjs","verify:metadata":"node --test scripts/verify-package-metadata.test.mjs && node scripts/verify-package-metadata.mjs","test:integration":"vitest run --config vitest.integration.ts","typecheck:examples":"tsc --noEmit -p examples/tsconfig.json","test:smoke-published":"node --test scripts/smoke-published-package.test.mjs","verify:release-workflow":"node scripts/verify-release-workflow.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:eec9f7df-91b4-4dab-ba12-d2caa3fd8c4c"}},"_resolved":"/home/runner/work/b2-sdk-typescript/b2-sdk-typescript/.release/backblaze-labs-b2-sdk-0.3.0.tgz","_integrity":"sha512-ABfrCTV0uN3ADXBgOC6hmMm2n3Mcnz2mnFafC1z1/Hvijv9GKlhaNBmfkY3UiRuVyjgWFCm8f5uiuQyNWFwFAg==","repository":{"url":"git+https://github.com/backblaze-labs/b2-sdk-typescript.git","type":"git"},"_npmVersion":"11.17.0","description":"The official Backblaze B2 Cloud Storage SDK for TypeScript and JavaScript","directories":{},"sideEffects":false,"_nodeVersion":"24.19.0","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"vite":"^8.2.1","cspell":"^10.0.1","eslint":"^10.8.1","vitest":"^4.1.10","typedoc":"^0.28.20","@eslint/js":"^10.0.1","playwright":"^1.62.1","typescript":"^6.0.3","@types/node":"^26.2.0","@biomejs/biome":"^2.5.8","@vitest/browser":"^4.1.10","vite-plugin-dts":"^5.0.3","typescript-eslint":"^8.67.0","@vitest/coverage-v8":"^4.1.10","eslint-plugin-jsdoc":"^64.2.0","eslint-plugin-tsdoc":"^0.5.2","@microsoft/tsdoc-config":"^0.18.1","@vitest/browser-playwright":"^4.1.10"},"peerDependencies":{"@aws-sdk/client-s3":"^3.0.0"},"peerDependenciesMeta":{"@aws-sdk/client-s3":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/b2-sdk_0.3.0_1787043213560_0.21869990936438932","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@backblaze-labs/b2-sdk","version":"0.4.0","description":"The official Backblaze B2 Cloud Storage SDK for TypeScript and JavaScript","license":"MIT","type":"module","engines":{"node":">=22.3.0"},"sideEffects":false,"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./raw":{"import":{"types":"./dist/raw/index.d.ts","default":"./dist/raw/index.js"},"require":{"types":"./dist/raw/index.d.cts","default":"./dist/raw/index.cjs"}},"./errors":{"import":{"types":"./dist/errors/index.d.ts","default":"./dist/errors/index.js"},"require":{"types":"./dist/errors/index.d.cts","default":"./dist/errors/index.cjs"}},"./auth":{"import":{"types":"./dist/auth/index.d.ts","default":"./dist/auth/index.js"},"require":{"types":"./dist/auth/index.d.cts","default":"./dist/auth/index.cjs"}},"./auth/file":{"import":{"types":"./dist/auth/file.d.ts","default":"./dist/auth/file.js"},"require":{"types":"./dist/auth/file.d.cts","default":"./dist/auth/file.cjs"}},"./partner":{"import":{"types":"./dist/partner/index.d.ts","default":"./dist/partner/index.js"},"require":{"types":"./dist/partner/index.d.cts","default":"./dist/partner/index.cjs"}},"./backup":{"import":{"types":"./dist/backup/index.d.ts","default":"./dist/backup/index.js"},"require":{"types":"./dist/backup/index.d.cts","default":"./dist/backup/index.cjs"}},"./streams":{"import":{"types":"./dist/streams/index.d.ts","default":"./dist/streams/index.js"},"require":{"types":"./dist/streams/index.d.cts","default":"./dist/streams/index.cjs"}},"./sync":{"import":{"types":"./dist/sync/index.d.ts","default":"./dist/sync/index.js"},"require":{"types":"./dist/sync/index.d.cts","default":"./dist/sync/index.cjs"}},"./simulator":{"import":{"types":"./dist/simulator/index.d.ts","default":"./dist/simulator/index.js"},"require":{"types":"./dist/simulator/index.d.cts","default":"./dist/simulator/index.cjs"}},"./notifications":{"import":{"types":"./dist/notifications/index.d.ts","default":"./dist/notifications/index.js"},"require":{"types":"./dist/notifications/index.d.cts","default":"./dist/notifications/index.cjs"}},"./s3":{"import":{"types":"./dist/s3/index.d.ts","default":"./dist/s3/index.js"},"require":{"types":"./dist/s3/index.d.cts","default":"./dist/s3/index.cjs"}}},"main":"./dist/index.cjs","module":"./dist/index.js","types":"./dist/index.d.ts","devDependencies":{"@biomejs/biome":"^2.5.8","@eslint/js":"^10.0.1","@microsoft/tsdoc-config":"^0.18.1","@types/node":"^26.2.0","@vitest/browser":"^4.1.10","@vitest/browser-playwright":"^4.1.10","@vitest/coverage-v8":"^4.1.10","cspell":"^10.0.1","eslint":"^10.8.1","eslint-plugin-jsdoc":"^64.2.0","eslint-plugin-tsdoc":"^0.5.2","playwright":"^1.62.1","typedoc":"^0.28.20","typescript":"^6.0.3","typescript-eslint":"^8.67.0","vite":"^8.2.1","vite-plugin-dts":"^5.0.3","vitest":"^4.1.10"},"peerDependencies":{"@aws-sdk/client-s3":"^3.0.0"},"peerDependenciesMeta":{"@aws-sdk/client-s3":{"optional":true}},"keywords":["backblaze","b2","cloud-storage","object-storage","s3","upload","download","multipart","streaming","typescript"],"repository":{"type":"git","url":"git+https://github.com/backblaze-labs/b2-sdk-typescript.git"},"author":{"name":"Backblaze, Inc."},"homepage":"https://github.com/backblaze-labs/b2-sdk-typescript#readme","bugs":{"url":"https://github.com/backblaze-labs/b2-sdk-typescript/issues"},"publishConfig":{"access":"public","provenance":true},"scripts":{"build":"vite build && node scripts/build-cts-types.mjs","build:release":"node scripts/build-release-artifact.mjs","test":"vitest run","test:slow":"vitest run --config vitest.slow.config.ts","test:all":"vitest run && vitest run --config vitest.slow.config.ts","test:watch":"vitest","test:coverage":"vitest run --config vitest.coverage.config.ts --coverage","test:browser":"vitest run --config vitest.browser.config.ts","test:integration":"vitest run --config vitest.integration.ts","lint":"biome check --error-on-warnings .","lint:fix":"biome check --write .","lint:docs":"eslint src/ --no-warn-ignored","lint:docs:fix":"eslint src/ --fix --no-warn-ignored","lint:spelling":"cspell --no-progress --gitignore \"src/**/*.ts\" \"examples/**/*.ts\" \"examples/**/*.md\" \"docs/**/*.md\" \"*.md\"","audit:deps":"node scripts/audit-dependencies.mjs","test:audit:deps":"node --test scripts/audit-dependencies.test.mjs","test:release-channel":"node --test scripts/verify-release-channel.test.mjs","typecheck":"tsc --noEmit","typecheck:examples":"tsc --noEmit -p examples/tsconfig.json","docs":"typedoc","docs:watch":"typedoc --watch","clean":"rm -rf dist api-docs","version":"node scripts/cut-changelog.mjs && git add CHANGELOG.md","verify:metadata":"node --test scripts/verify-package-metadata.test.mjs && node scripts/verify-package-metadata.mjs","verify:release":"node scripts/verify-release-workflow.mjs","verify:release-channel":"node scripts/verify-release-channel.mjs","verify:ci-docs-filter":"node --test scripts/verify-docs-only-classifier.test.mjs","verify:docs-consistency":"node --test scripts/verify-docs-consistency.test.mjs","verify:exports":"node scripts/verify-package-exports.mjs","verify:release-workflow":"node scripts/verify-release-workflow.mjs","smoke:published":"node scripts/smoke-published-package.mjs","test:smoke-published":"node --test scripts/smoke-published-package.test.mjs","verify":"pnpm run lint && pnpm run lint:docs && pnpm run lint:spelling && pnpm run typecheck && pnpm run typecheck:examples && pnpm run test:audit:deps && pnpm run test && pnpm run test:release-channel && pnpm run build && pnpm run verify:release-channel && pnpm run docs && pnpm run verify:metadata && pnpm run verify:release && pnpm run verify:ci-docs-filter && pnpm run verify:docs-consistency && pnpm run verify:exports"},"_id":"@backblaze-labs/b2-sdk@0.4.0","_integrity":"sha512-Xs5dHWF2YNDVaZpumgJAAqy1rFYVw1F8l2ZAsKL36AA6lwpxuqjRHPgwQMX92WiowQLCl5O1bZRjD3pVJA7m+Q==","_resolved":"/home/runner/work/b2-sdk-typescript/b2-sdk-typescript/.release/backblaze-labs-b2-sdk-0.4.0.tgz","_from":"file:.release/backblaze-labs-b2-sdk-0.4.0.tgz","_nodeVersion":"24.19.0","_npmVersion":"11.17.0","dist":{"integrity":"sha512-Xs5dHWF2YNDVaZpumgJAAqy1rFYVw1F8l2ZAsKL36AA6lwpxuqjRHPgwQMX92WiowQLCl5O1bZRjD3pVJA7m+Q==","shasum":"9ee4ccf69ee641b74c1d19ddab3e49571e9e357e","tarball":"https://registry.npmjs.org/@backblaze-labs/b2-sdk/-/b2-sdk-0.4.0.tgz","fileCount":948,"unpackedSize":7127457,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@backblaze-labs%2fb2-sdk@0.4.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCID75Z8r4TRh38lx1Ad/t5eYZXLRM50nJOsqJai9b7zKLAiBCWUNH3G45WJvIEmKLUtM8U36ojF9VaNhxjGY0/UPgCw=="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:eec9f7df-91b4-4dab-ba12-d2caa3fd8c4c"}},"directories":{},"maintainers":[{"name":"goanpeca","email":"goanpeca@gmail.com"},{"name":"jdnyc","email":"jdeleon@jdeleon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/b2-sdk_0.4.0_1788288649014_0.8312254810804582"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-29T00:57:17.936Z","modified":"2026-09-01T18:50:49.654Z","0.1.0":"2026-05-29T00:57:18.319Z","0.2.0":"2026-07-08T14:16:27.617Z","0.3.0":"2026-08-18T08:53:33.741Z","0.4.0":"2026-09-01T18:50:49.255Z"},"bugs":{"url":"https://github.com/backblaze-labs/b2-sdk-typescript/issues"},"author":{"name":"Backblaze, Inc."},"license":"MIT","homepage":"https://github.com/backblaze-labs/b2-sdk-typescript#readme","keywords":["backblaze","b2","cloud-storage","object-storage","s3","upload","download","multipart","streaming","typescript"],"repository":{"type":"git","url":"git+https://github.com/backblaze-labs/b2-sdk-typescript.git"},"description":"The official Backblaze B2 Cloud Storage SDK for TypeScript and JavaScript","maintainers":[{"name":"goanpeca","email":"goanpeca@gmail.com"},{"name":"jdnyc","email":"jdeleon@jdeleon.com"}],"readme":"# @backblaze-labs/b2-sdk\n\n[![CI](https://github.com/backblaze-labs/b2-sdk-typescript/actions/workflows/ci.yml/badge.svg)](https://github.com/backblaze-labs/b2-sdk-typescript/actions/workflows/ci.yml)\n[![API Docs](https://github.com/backblaze-labs/b2-sdk-typescript/actions/workflows/docs.yml/badge.svg)](https://backblaze-labs.github.io/b2-sdk-typescript/)\n[![npm](https://img.shields.io/npm/v/@backblaze-labs/b2-sdk?color=cb3837)](https://www.npmjs.com/package/@backblaze-labs/b2-sdk)\n[![License: MIT](https://img.shields.io/badge/license-MIT-blue.svg)](LICENSE)\n[![TypeScript](https://img.shields.io/badge/TypeScript-6.x-3178c6?logo=typescript&logoColor=white)](https://www.typescriptlang.org/)\n[![Node.js](https://img.shields.io/badge/Node.js-%E2%89%A522.3-339933?logo=nodedotjs&logoColor=white)](https://nodejs.org/)\n[![Zero Dependencies](https://img.shields.io/badge/dependencies-0-brightgreen)](package.json)\n\nA Backblaze-maintained TypeScript and JavaScript SDK for Backblaze B2 Cloud Storage, currently incubating in [Backblaze Labs](https://github.com/backblaze-labs).\n\n**Isomorphic at the source level.** One source tree runs unmodified in Node.js 22.3+, Bun, Deno, and browsers, and is designed around the same Web APIs used by Cloudflare Workers and Vercel Edge. Internal imports use `.ts` extensions so Deno reads `src/` directly with no build step. See [Source isomorphism](#source-isomorphism).\n\n**Async-first.** Built on Web Streams, `AbortSignal`, and `crypto.subtle`. No callbacks, no legacy APIs.\n\n**Fully typed.** Branded IDs, discriminated unions for encryption settings and errors, strict TypeScript with `exactOptionalPropertyTypes`.\n\n**Zero runtime dependencies.** The core package has no `dependencies` in `package.json`.\n\n**Full API reference:** [backblaze-labs.github.io/b2-sdk-typescript](https://backblaze-labs.github.io/b2-sdk-typescript/) (generated from source on every push to `main`).\n\n## Install\n\n```bash\nnpm install @backblaze-labs/b2-sdk\n# or\npnpm add @backblaze-labs/b2-sdk\n# or\nyarn add @backblaze-labs/b2-sdk\n```\n\n## Quick start\n\n```ts\nimport { B2Client, BufferSource } from '@backblaze-labs/b2-sdk'\n\nconst client = new B2Client({\n  applicationKeyId: process.env.B2_APPLICATION_KEY_ID,\n  applicationKey: process.env.B2_APPLICATION_KEY,\n})\n\nawait client.authorize()\n\nconst bucket = await client.getBucket('my-app-data')\nif (!bucket) throw new Error('bucket not found')\n\nconst data = new TextEncoder().encode('Hello, B2!')\nconst file = await bucket.upload({\n  fileName: 'hello.txt',\n  source: new BufferSource(data),\n  contentType: 'text/plain',\n})\n\nconsole.log(`Uploaded: ${file.fileName} (${file.contentLength} bytes)`)\n```\n\n## Features\n\n### Buckets\n\n```ts\nimport { BucketType } from '@backblaze-labs/b2-sdk'\n\n// List all buckets\nconst buckets = await client.listBuckets()\n\n// Get a bucket by name\nconst bucket = await client.getBucket('my-bucket')\n\n// Update bucket settings\nawait bucket.update({\n  bucketType: BucketType.AllPublic,\n  lifecycleRules: [{ fileNamePrefix: 'logs/', daysFromUploadingToHiding: 30 }],\n})\n\n// Delete a bucket\nawait bucket.delete()\n```\n\n> The `BucketType`, `RetentionMode`, `LegalHoldValue`, `Capability`, `EventType`, and `EncryptionMode` `as const` objects exported from the main entry give you type-safe alternatives to the raw string literals — pick whichever style you prefer; both are accepted at the type level.\n\n### Partner and Computer Backup APIs\n\nPartner API and Computer Backup API helpers are exported from dedicated subpaths:\n\n```ts\nimport { PartnerClient } from '@backblaze-labs/b2-sdk/partner'\nimport { BackupClient } from '@backblaze-labs/b2-sdk/backup'\n```\n\nBoth clients authorize with a Master Application Key through the Partner authorization flow. Account-creating Partner operations, including group member creation and trial reservation, require a valid SMS phone number on the administrator account. See [examples/README.md](examples/README.md#partner-and-computer-backup-examples) for current prerequisites and runnable examples.\n\n### Uploads\n\nSmall files (under the recommended part size, typically 100 MB) are uploaded in a single request. Larger files automatically use multipart upload with parallel part uploads.\n\n```ts\nimport { BufferSource, BlobSource, FileSource, toContentSource } from '@backblaze-labs/b2-sdk'\n\n// From a Uint8Array\nawait bucket.upload({\n  fileName: 'data.bin',\n  source: new BufferSource(myUint8Array),\n})\n\n// From a Blob or File (browser)\nawait bucket.upload({\n  fileName: 'photo.jpg',\n  source: new BlobSource(fileInput.files[0]),\n  contentType: 'image/jpeg',\n})\n\n// From a local file path (Node)\nawait bucket.upload({\n  fileName: 'backups/db.dump',\n  source: await FileSource.fromPath('/var/backups/db.dump'),\n})\n\n// From a forward-only stream or async iterable (size required)\nawait bucket.upload({\n  fileName: 'exports/report.ndjson',\n  source: toContentSource(nodeReadable, knownByteLength),\n})\n\n// Large file with progress tracking (Node)\nawait bucket.upload({\n  fileName: 'backup.tar.gz',\n  source: await FileSource.fromPath('/path/to/backup.tar.gz'),\n  concurrency: 8,\n  partSize: 64 * 1024 * 1024,\n  onProgress: (event) => {\n    console.log(`${event.bytesTransferred}/${event.totalBytes} bytes`)\n  },\n  signal: AbortSignal.timeout(300_000),\n})\n```\n\n`FileSource` rejects non-regular leaf paths, later leaf path swaps, and same-size rewrites that restore mtime on POSIX platforms. Parent directory symlinks are followed unless your application validates the containing root first. On Windows, `FileSource` skips unreliable dev/inode and ctime comparisons and validates size and mtime instead.\n\nTransient upload failures are retried with a fresh B2 upload URL, matching B2's documented flow. If the first upload POST succeeded but its response was lost, retrying can create a duplicate file version.\n\nUse `onUploadRetry` to log or count retry attempts, compare returned file IDs and SHA-1 values when reconciling uploads, and configure lifecycle or version-retention rules for buckets where duplicate versions must be cleaned up automatically. Retry diagnostics are event-only: the SDK does not log, count, or persist them unless this listener records them. Payload re-POSTs and fresh-URL fetches spend one upload retry budget and are bounded by `retry.maxRetries + 1` attempts per file or part; aggregate retries scale with multipart transfer concurrency. Upload 429 throttling backs off on the same upload URL instead of fetching a new one.\n\nUploads do not retry lost success response bodies or upload POST network errors by default because re-posting `b2_upload_file` can create duplicate versions, especially in versioned or Object Lock buckets. If callers opt into this ambiguity with `retryResponseBodyFailures: true`, retryable upload POST network errors and unreadable response bodies can re-post the payload with a fresh URL, bounded by `retry.maxRetries`; any uploaded `fileRetention` or `legalHold` applies to each duplicate version and can prevent deletion until the retention policy expires or the hold is cleared. Multipart callers may also opt in when replaying the same `partNumber` is acceptable before `finishLargeFile`, including SSE-B2 encrypted parts.\n\nLarge-file part retries are coordinated per part, not by a shared circuit breaker. During a B2 pod or main-API incident, concurrent parts can independently back off with jitter, fetch fresh part URLs, and retry in parallel; aggregate fresh-URL traffic scales with multipart concurrency and `retry.maxRetries`. Multipart workers abort sibling work promptly after a fatal part failure, and best-effort cleanup is bounded so aborting a stream does not hang indefinitely. Tune `concurrency`, `retry`, and `onUploadRetry` for operators that need outage counters or stricter load shedding. Each HTTP attempt has a 15 minute deadline by default; for streamed download bodies the timeout is idle/no-progress and resets after each chunk. Set `retry.requestTimeoutMs` higher for very slow upload links or to `0` to rely only on your own `AbortSignal`.\n\n`FileSource` is the Node.js-only content adapter. It is safe to import from the\nmain package in browser builds, but `FileSource.fromPath()` and its read methods\nneed local filesystem APIs at runtime. The source records the validated file\nidentity and fails with `FileSource file changed after validation` if the path is\nreplaced, truncated, content-modified, or has ctime-changing metadata updates\nwhile a multipart upload is reading it. On platforms without `O_NOFOLLOW`,\nleaf-symlink swaps are rejected by the post-open identity check rather than by\nthe open flag. Retry after active writers stop changing the file.\n\n#### Resume a failed multipart upload\n\nResume has two paths. `resumeFileId` targets a known unfinished large-file ID returned by B2 when the multipart upload was started. `resume: true` without `resumeFileId` runs bounded same-name discovery and may continue uploading into the newest compatible unfinished upload; incompatible candidates are skipped and a fresh upload starts. Automatic discovery reuploads every planned part into the selected unfinished file instead of trusting pre-existing server parts by SHA-1 alone. With explicit `resumeFileId`, each local part is hashed again and matching server parts are skipped only when the locally recomputed SHA-1 equals B2's part SHA-1.\n\nResume discovery is intentionally conservative. The SDK reuses only the newest unfinished large file whose file name, content type, caller-provided file info, encryption, Object Lock retention, legal hold, and uploaded part lengths match the current call. If those checks fail, a new large file is started instead. Caller-provided file info such as `large_file_sha1` or `src_last_modified_millis` is part of that identity, so keep it stable across retries. Discovery does not add SDK metadata to unfinished or finished file info.\n\nAutomatic resume requires a stable content type. When the upload uses the SDK default `b2/x-auto`, same-name discovery starts a fresh large file unless B2 lists the unfinished file with the same `b2/x-auto` value. Provide an explicit `contentType` for automatic resume, or use `resumeFileId` when the caller deliberately trusts a specific unfinished file's listed content type. Explicit content types still require an exact match.\n\nAutomatic resume discovery does not use B2's stored part SHA-1 to skip local bytes because B2 unfinished-large-file records do not identify the writer that started them. It may still finish a compatible same-name unfinished upload after overwriting planned parts with locally read bytes, so use exact file names and stable caller-owned file info when shared buckets have concurrent writers. Use `resumeFileId` only when the caller deliberately trusts the specific unfinished file ID.\n\nThe discovery scan is bounded to avoid unbounded prefix-flood work in shared buckets, but it still runs before the first upload byte. By default the SDK inspects up to 10 unfinished-file pages, up to 25 metadata-compatible candidates, and up to 10 part pages per candidate, so a worst-case resume attempt can add many sequential B2 list calls before data transfer starts. Tune `resumeMaxListPages`, `resumeMaxPartCandidates`, and `resumeMaxPartPages` for buckets with many concurrent same-prefix uploads. The SDK does not install a default resume discovery timeout; set `resumeDiscoveryTimeoutMs` or pass an abort signal such as `AbortSignal.timeout(...)` when discovery needs a first-byte time budget. If the scan is truncated, the SDK reports `search-truncated`; when a compatible candidate was already scanned, that candidate may still be reused.\n\nRejected candidates and failed attempts that reused an existing unfinished file are left unfinished. B2 stores uploaded parts for unfinished large files until they are finished, cancelled, or removed by a lifecycle rule, so stricter matching or repeated prefix-flood truncation can leave billable unfinished uploads behind. Applications with strict resume matching should configure lifecycle cleanup or periodically use `listUnfinishedLargeFiles` and `cancelLargeFile` to remove stale unfinished uploads.\n\nWhen the caller omits `serverSideEncryption`, high-level bucket and object uploads verify candidates against the bucket's current default encryption freshly fetched from B2, including default SSE-B2 or no encryption. Explicit `serverSideEncryption: { mode: 'none' }` still requires an unencrypted candidate. SSE-C uploads are not resumed automatically or with `resumeFileId` because B2 does not expose a non-secret customer-key identity for unfinished files. With `resume: true`, an SSE-C retry starts a new large file. With `resumeFileId`, SSE-C fails with `ResumeFileIdMismatchError` rather than risking a finish under an unverified key.\n\nObject Lock state must also be verified before reuse. When the caller omits `fileRetention`, high-level bucket and object uploads use the readable bucket default retention freshly fetched from B2; candidates without the exact required default retention window are skipped. Unreadable bucket default retention, candidate retention, or candidate legal-hold fields fail closed. Explicit retention or legal-hold values still require readable matching candidate metadata.\n\nPass `onResumeCandidateRejected` to collect diagnostic events when a same-name unfinished large file is skipped, including reasons such as `file-info-mismatch`, `part-length-mismatch`, `search-truncated`, or `sse-c-unsupported`. Resume diagnostics are event-only: without this listener, a conservative resume decline falls back to a fresh upload without SDK logging or counters. Candidate-specific events include `requestedFileName` and `candidateFileName` so logging can distinguish the intended upload name from the rejected unfinished file. Pass `onResumePartReused` to observe each pre-existing server part accepted by explicit `resumeFileId` through the SHA-1 equality gate. If a supplied `resumeFileId` is incompatible or cannot be verified through B2's unfinished-large-file listing, `ResumeFileIdMismatchError` is thrown instead of silently starting a different large file.\n\n```ts\n// Restart the upload that crashed at part 47 of 100\nawait bucket.upload({\n  fileName: 'backup.tar.gz',\n  source: new BlobSource(largeBlob),\n  partSize: 64 * 1024 * 1024,\n  resumeFileId: knownLargeFileId,\n})\n```\n\n#### Streaming uploads via WritableStream\n\nPipe any `ReadableStream<Uint8Array>` straight into B2. The SDK buffers up to `partSize` bytes per part and uploads them in parallel through the multipart protocol. Backpressure is honoured via the internal queue.\n\n```ts\nconst { writable, done } = bucket.file('logs.ndjson').createWriteStream({\n  partSize: 16 * 1024 * 1024,\n  concurrency: 4,\n})\n\n// Pipe from any ReadableStream source: fetch().body, fs.createReadStream(...) (with toWeb), etc.\nawait response.body.pipeTo(writable)\nconst fileVersion = await done\nconsole.log(`Streamed upload finished: ${fileVersion.fileName} (${fileVersion.contentLength} bytes)`)\n```\n\n> Streaming uploads do not support resume because the total size and per-part SHA-1s are not known in advance. Use the buffered `upload` path with `resumeFileId` when that matters.\n\n### Downloads\n\n```ts\n// Download by file name\nconst result = await bucket.download('hello.txt')\nconst text = await new Response(result.body).text()\n\n// Download by file ID with range\nconst partial = await bucket.download('large-file.bin', {\n  range: 'bytes=0-1023',\n})\n\n// Parallel ranged download (for large files).\n// Each range uses the client's configured RetryTransport budget, so transient\n// 503s are retried without adding a second default retry layer per chunk.\nconst obj = bucket.file('big-dataset.parquet')\nconst stream = obj.createReadStream(fileId, totalSize, {\n  concurrency: 4,\n  rangeSize: 10 * 1024 * 1024,\n})\n```\n\nFull-body downloads are automatically verified when B2 returns a real `X-Bz-Content-Sha1` digest. If the downloaded bytes do not match, the body stream errors with `ChecksumMismatchError`; discard any partially written output when piping to disk. HEAD requests, range GETs, and files whose SHA-1 is unavailable are not verified because no matching whole-body digest exists.\n\n### Sync SHA-1 comparisons\n\n`compareMode: 'sha1'` hashes matching-size local files and compares them with verifiable B2 SHA-1 metadata. B2 multipart objects do not have an authoritative `contentSha1`; when only `fileInfo.large_file_sha1` or another untrusted hint is available, a real sync downloads that selected B2 version and hashes the full object before skipping a transfer. The SDK does not persist that verification result, so an unchanged 100 GB multipart object can cost 100 GB of B2 download reads on every SHA-1 sync run. `compare.bytesVerified` reports those B2 verification bytes for the run. Use `sha1VerificationMaxBytes` to skip objects above your per-file verification budget, raise `sha1VerificationTimeoutMillis` for large objects on slow links, or use `size`/`modtime` mode when recurring verification egress is not acceptable.\n\nB2-to-local sync streams downloads through a private managed staging directory under the destination root before renaming into place. The scanner ignores that managed directory and stale SDK-owned staging entries are reaped on later download setup. New files are published as 0600 by default, replacements keep the previous file mode, and download body stalls use `downloadIdleTimeoutMillis` (60 seconds by default) rather than `sha1ReadTimeoutMillis`. `B2Folder` prefixes are raw B2 key prefixes: use `photos/` for a slash-delimited folder, or `photos` to match every key beginning with those bytes.\n\n### File operations\n\n```ts\n// List files (single page)\nconst listing = await bucket.listFileNames({ prefix: 'photos/', pageSize: 100 })\n\n// Iterate all files (async generator, handles pagination)\nfor await (const file of bucket.paginateFileNames({ prefix: 'logs/' })) {\n  console.log(file.fileName, file.contentLength)\n}\n\n// Look up the latest visible version by name (returns null if missing or hidden)\nconst info = await bucket.getFileInfoByName('hello.txt')\n\n// Fetch metadata without transferring the body (HTTP HEAD). Returns a\n// body-less result so callers never have to drain a (logically empty)\n// HEAD response stream themselves.\nconst { headers } = await bucket.head('hello.txt')\nconsole.log(headers.contentLength, headers.contentSha1)\n\n// Hide a file (soft delete)\nawait bucket.hideFile('old-config.json')\n\n// Restore visibility by removing the latest hide marker\nawait bucket.unhideFile('old-config.json')\n\n// Delete a specific file version\nawait bucket.deleteFileVersion('file.txt', fileId)\n\n// Server-side copy (single call, suitable for any size B2 supports)\nawait bucket.copyFile({\n  sourceFileId: originalFileId,\n  fileName: 'copy-of-file.txt',\n})\n\n// Server-side multipart copy for large files. Splits the source into parts\n// copied in parallel via b2_copy_part. Falls back to copyFile below partSize.\nawait bucket.copyLargeFile({\n  sourceFileId: originalFileId,\n  fileName: 'big-replica.bin',\n  partSize: 64 * 1024 * 1024,\n  concurrency: 4,\n})\n```\n\n### Bulk delete\n\nTwo primitives on `Bucket` for cleanup at scale:\n\n```ts\n// Delete a known set of file versions with bounded concurrency\nconst result = await bucket.deleteMany(\n  [\n    { fileName: 'a.txt', fileId: id1 },\n    { fileName: 'b.txt', fileId: id2 },\n  ],\n  { concurrency: 10 },\n)\nconsole.log(`deleted=${result.deleted} errors=${result.errors.length}`)\n\n// Stream-delete every version matching a prefix (or the whole bucket if omitted).\n// Yields a DeleteAllEvent per version; never materialises the full list in memory.\nfor await (const event of bucket.deleteAll({ prefix: 'tmp/', dryRun: false })) {\n  if (event.type === 'delete') console.log('deleted', event.fileName)\n  else if (event.type === 'error') console.warn('failed', event.fileName, event.message)\n}\n```\n\n### Application keys\n\n```ts\nimport { Capability } from '@backblaze-labs/b2-sdk'\n\nconst key = await client.createKey({\n  capabilities: [Capability.ReadFiles, Capability.WriteFiles],\n  keyName: 'my-app-key',\n  bucketIds: [bucket.id],\n  namePrefix: 'uploads/',\n  validDurationInSeconds: 86400,\n})\n\nconst keys = await client.listKeys()\nawait client.deleteKey(key.applicationKeyId)\n```\n\n#### Capability checks\n\nFail fast with a typed error instead of waiting for a server 401/403:\n\n```ts\nimport { Capability } from '@backblaze-labs/b2-sdk'\nimport { B2InsufficientCapabilityError } from '@backblaze-labs/b2-sdk/errors'\n\nconst required = [Capability.ReadFiles, Capability.WriteFiles]\nconst { ok, missing } = client.hasCapabilities(required)\nif (!ok) {\n  throw new B2InsufficientCapabilityError(required, [...missing], missing)\n}\n```\n\n### Server-side encryption\n\n```ts\nimport { SSE_B2, sseCustomer } from '@backblaze-labs/b2-sdk'\nimport { EncryptionKey } from '@backblaze-labs/b2-sdk/streams'\n\n// SSE-B2 (Backblaze-managed keys)\nawait bucket.upload({\n  fileName: 'encrypted.dat',\n  source: new BufferSource(data),\n  serverSideEncryption: SSE_B2,\n})\n\n// SSE-C (customer-provided keys) - precomputed digests\nawait bucket.upload({\n  fileName: 'secret.dat',\n  source: new BufferSource(data),\n  serverSideEncryption: sseCustomer(base64Key, base64KeyMd5),\n})\n\n// SSE-C from raw bytes (Node). EncryptionKey computes the MD5 internally and\n// redacts itself in JSON.stringify, toString, and Node's util.inspect so the\n// key never lands in logs.\nconst key = await EncryptionKey.fromBytes(randomBytes(32))\nawait bucket.upload({\n  fileName: 'secret.dat',\n  source: new BufferSource(data),\n  serverSideEncryption: key,\n})\nconsole.log(key)            // [EncryptionKey SSE-C [redacted SSE-C key]]\nJSON.stringify(key)         // customer key and MD5 fields show \"[redacted SSE-C key]\"\n```\n\n### Object lock and legal hold\n\n```ts\nimport { LegalHoldValue, RetentionMode } from '@backblaze-labs/b2-sdk'\n\nawait bucket.updateFileRetention('important.pdf', fileId, {\n  mode: RetentionMode.Governance,\n  retainUntilTimestamp: Date.now() + 365 * 24 * 60 * 60 * 1000,\n})\n\n// Shorten a governance-mode retention. Requires the bypassGovernance capability.\nawait bucket.updateFileRetention(\n  'important.pdf',\n  fileId,\n  { mode: RetentionMode.Governance, retainUntilTimestamp: Date.now() + 24 * 60 * 60 * 1000 },\n  { bypassGovernance: true },\n)\n\nawait bucket.updateFileLegalHold('evidence.pdf', fileId, LegalHoldValue.On)\n```\n\n### Event notifications\n\n```ts\nimport { EventType } from '@backblaze-labs/b2-sdk'\n\nawait bucket.setNotificationRules([\n  {\n    name: 'upload-notify',\n    eventTypes: [EventType.ObjectCreatedAll],\n    isEnabled: true,\n    targetConfiguration: {\n      targetType: 'webhook',\n      url: 'https://my-app.com/webhooks/b2',\n      hmacSha256SigningSecret: process.env.B2_WEBHOOK_SECRET,\n      customHeaders: [{ name: 'X-B2-Source', value: 'uploads' }],\n    },\n  },\n])\n```\n\nOn the receiving side, verify the `X-Bz-Event-Notification-Signature` header before trusting the payload. The `@backblaze-labs/b2-sdk/notifications` subpath ships HMAC-SHA256 helpers so you don't have to implement constant-time signature checking yourself:\n\n```ts\nimport {\n  B2_WEBHOOK_SIGNATURE_HEADER,\n  requireValidWebhook,\n} from '@backblaze-labs/b2-sdk/notifications'\n\n// Inside your HTTP handler. `body` must be the raw request bytes — any\n// JSON re-serialisation will invalidate the HMAC.\nconst body = new Uint8Array(await request.arrayBuffer())\nconst payload = await requireValidWebhook({\n  body,\n  signature: request.headers.get(B2_WEBHOOK_SIGNATURE_HEADER),\n  secret: process.env.B2_WEBHOOK_SECRET,\n})\nfor (const event of payload.events) {\n  console.log(event.eventType, event.objectName)\n}\n```\n\n`requireValidWebhook` throws on missing/invalid signature and returns the parsed payload on success. If you'd rather branch on a boolean (e.g. to log the failure reason without throwing), use the lower-level `verifyWebhookSignature` which returns `{ valid, reason, payload }`.\n\n### Download authorization\n\n```ts\n// Generate a short-lived download authorization for sharing\nconst auth = await bucket.getDownloadAuthorization('photos/', 3600)\n```\n\n### Persistent authorization (Node)\n\n`FileAccountInfo` persists the authorization response to a JSON file on disk so processes can restart without re-authorizing. It implements the `AccountInfo` interface and is a drop-in replacement for `InMemoryAccountInfo`. Upload URL pools remain in memory.\n\n```ts\nimport { B2Client } from '@backblaze-labs/b2-sdk'\nimport { FileAccountInfo } from '@backblaze-labs/b2-sdk/auth/file'\n\nconst accountInfo = new FileAccountInfo('/var/cache/my-app/b2-auth.json', {\n  onDiscard: (event) => console.warn('ignored stale B2 auth cache', event.reason),\n  onWriteError: (event) => console.warn('could not persist B2 auth cache', event.error),\n})\nawait accountInfo.load() // populate from disk if the file exists\n\nconst client = new B2Client({\n  applicationKeyId: process.env.B2_APPLICATION_KEY_ID,\n  applicationKey: process.env.B2_APPLICATION_KEY,\n  accountInfo,\n})\n\nif (accountInfo.getAuth() === null) {\n  await client.authorize() // first run, or token cleared\n}\n```\n\n`load()` returns silently on missing or corrupt files (a fresh `authorize()` will populate fresh state). `onDiscard` fires when a loaded cache entry is ignored because its realm, application key ID, or cached endpoints do not match the current client; `onWriteError` reports asynchronous write failures that would otherwise be best-effort. Call `await accountInfo.flushed()` before process exit if you need to guarantee the latest state has hit disk.\n\n## Subpath exports\n\nThe SDK is organized into subpath exports for tree-shaking:\n\n```ts\n// High-level facade (most users need only this)\nimport { B2Client, Bucket, B2Object } from '@backblaze-labs/b2-sdk'\n\n// Low-level 1:1 API bindings for the B2 native endpoints the SDK uses\nimport { RawClient } from '@backblaze-labs/b2-sdk/raw'\n\n// Error types for catch blocks\nimport {\n  B2Error,\n  ExpiredAuthTokenError,\n  CapExceededError,\n  B2InsufficientCapabilityError,\n} from '@backblaze-labs/b2-sdk/errors'\n\n// Auth backends (in-memory default, file-backed for Node persistence)\nimport { InMemoryAccountInfo } from '@backblaze-labs/b2-sdk/auth'\nimport { FileAccountInfo } from '@backblaze-labs/b2-sdk/auth/file'\n\n// Partner and Computer Backup API surfaces\nimport { PartnerClient, PartnerRawClient } from '@backblaze-labs/b2-sdk/partner'\nimport { BackupClient, BackupRawClient } from '@backblaze-labs/b2-sdk/backup'\n\n// Streaming utilities + SSE-C key wrapper\nimport {\n  IncrementalSha1,\n  BufferSource,\n  BlobSource,\n  EncryptionKey,\n} from '@backblaze-labs/b2-sdk/streams'\n\n// Sync engine (local <-> B2)\nimport { synchronize, LocalFolder, B2Folder } from '@backblaze-labs/b2-sdk/sync'\n\n// S3-compatible helpers\nimport {\n  createS3ClientConfig,\n  presignS3GetObjectUrl,\n  presignS3PutObjectUrl,\n} from '@backblaze-labs/b2-sdk/s3'\n\n// Webhook signature verification for B2 event notifications\nimport { verifyWebhookSignature, requireValidWebhook } from '@backblaze-labs/b2-sdk/notifications'\n\n// In-memory B2 server for tests (no network required)\nimport { B2Simulator } from '@backblaze-labs/b2-sdk/simulator'\n```\n\n`createS3ClientConfig()` is for `@aws-sdk/client-s3`; install that optional peer\nbefore constructing an AWS `S3Client`. The presign helpers sign internally and\ndo not require AWS presigner packages.\n\nRaw methods use a trailing options bag for request controls such as cancellation\nand per-request retry overrides: pass `{ signal, retry }` to `getUploadUrl`,\n`getUploadPartUrl`, `uploadFile`, and `uploadPart`. The older positional\n`signal, retry` form remains available only for source compatibility.\n\n### Raw native API version policy\n\n`RawClient` builds SDK-owned B2 native storage URLs with `/b2api/v4`, matching the\ncurrent published native API docs. The version is centralized in the raw URL\nbuilder path; upload and download URLs returned by B2 are used as returned.\n\nRaw JSON endpoints use POST bodies, including read/list operations whose docs\nalso show GET query examples such as `b2_get_upload_url`, `b2_get_file_info`,\n`b2_list_file_names`, and `b2_list_keys`. B2 documents POST JSON compatibility\nfor these operations, so the SDK keeps the long-standing POST shape while moving\nthe path version to v4.\n\nEvery export is documented with full type signatures in the [API reference](https://backblaze-labs.github.io/b2-sdk-typescript/).\n\n## Sync filters\n\n`synchronize()` and the built-in `LocalFolder` / `B2Folder` scanners accept `include` and `exclude` filters for paths relative to each sync root:\n\n```ts\nfor await (const event of synchronize({\n  source: new LocalFolder('./site'),\n  dest: new B2Folder(bucket, 'site/'),\n  bucket,\n  prefix: 'site/',\n  options: {\n    compareMode: 'modtime',\n    keepMode: 'no-delete',\n    include: ['assets/**', '*.html'],\n    exclude: ['*.tmp', 'node_modules', 'dist/cache/**'],\n  },\n})) {\n  console.log(event)\n}\n```\n\nGlob strings use the SDK dialect: `*` and `?` stay within one path segment, a whole `**` segment crosses directories, slash-less patterns match any basename or ancestor directory, and excludes win over includes. Use `dir/**` for directory-subtree patterns such as `dist/cache/**`; a slash-containing literal such as `dist/cache` matches only that exact path. RegExp filters are guarded by a best-effort synchronous safety heuristic whose exact subset may change as protections tighten. Paths beyond the RegExp input guard are skipped when any RegExp filter is present, including exclude-only RegExp deny-lists. B2 prefixes are raw object-name prefixes; backslashes are not rewritten to `/`.\n\n`SyncFolder.scan()` direct consumers should expect paths sorted with `compareSyncRelativePaths`, exported from `@backblaze-labs/b2-sdk/sync`. During `synchronize()`, custom folders are filtered before pairing even when they set `appliesScanFilters: true`; scanner-side filtering is an optimization, not the policy boundary. Custom scanner authors can call `filterSyncPaths(paths, options)` and forward `SyncScanOptions.onSkip` so RegExp input-limit diagnostics are preserved. Custom folders that do not set `appliesScanSorting: true` are sorted before pairing. The built-in local and B2 scanners set both flags. `SyncOptions.maxScanEntries` / `SyncScanOptions.maxScanEntries` default to the SDK scan ceiling and fail with a defined scan-limit error when exceeded; B2 scans count every listed file-version record, including versions later skipped by prefix, safety, or filter checks, while local and fallback scans count retained sync paths. Pass `Infinity` only when the process heap is sized for the full result set; raising the limit increases peak scanner memory because built-in scans sort or group results before yielding.\n\nBuilt-in scanner skip diagnostics use `SyncSkipReason` values such as `outside-prefix`, `unsafe-name`, `local-unsafe-name`, `relative-path-collision`, `local-path-collision`, `filesystem-error`, and `path-too-long-for-regexp`. The `onSkip` callback receives every diagnostic; the `SyncEvent` stream buffers the first 100 scanner diagnostics and then reports overflow with `scan-skip-overflow`.\n\nB2-to-local sync skips object names that are unsafe on local filesystems, including NTFS alternate data stream names, DOS device basenames, trailing dot/space names, the reserved `.b2sdk-download-staging` namespace, and case/Unicode-canonical collisions. Downloads stream into private per-download entries under the destination root's managed `.b2sdk-download-staging` directory and publish completed files into place; SDK-owned staging roots and entries carry `.b2sdk-staging-marker.partial` files. Local scans are read-only and exclude the managed staging directory when those markers are present so abandoned staging state is not uploaded as source content. Later download setup reaps stale SDK-owned staging entries only when marker and partial-file activity is old and unchanged immediately before removal. Download body reads have a 60 second idle timeout by default; set `downloadIdleTimeoutMillis` to tune it or `Infinity` to disable the watchdog. Downloads and local deletes reject symlinked local roots and symlinked path components under the root, then revalidate root, parent, and leaf identity immediately before filesystem operations. Uploads support symlinked source roots by binding the resolved root identity before scanning, then reopening scanned files with no-follow semantics and verifying the opened file remains inside that bound source root before reading. Per-action failures are emitted as `error` events; the terminal aggregate error includes `failureCount`, up to 100 `failedPaths`, and `failedPathOmittedCount` when more paths were omitted.\n\n## Custom transport\n\nThe SDK uses a pluggable transport layer. The default `FetchTransport` uses the native `fetch` API. You can provide your own:\n\n```ts\nimport type { HttpTransport, HttpRequest, HttpResponse } from '@backblaze-labs/b2-sdk'\n\nclass MyTransport implements HttpTransport {\n  async send(request: HttpRequest): Promise<HttpResponse> {\n    // your implementation\n  }\n}\n\nconst client = new B2Client({\n  applicationKeyId: '...',\n  applicationKey: '...',\n  transport: new MyTransport(),\n})\n```\n\n## Identifying your traffic (User-Agent)\n\nEvery request the SDK issues carries a User-Agent header that Backblaze can grep server logs by:\n\n```\nb2-sdk-typescript/<version-or-dev> (typescript; @backblaze-labs/b2-sdk; node/<node-version>; linux; x64)\n```\n\nBoth `b2-sdk-typescript/` (stable product token) and `@backblaze-labs/b2-sdk` (npm package name) are part of the documented contract — log queries that match either one find every request issued by this SDK. The comment block also reports the runtime (`node/<version>`, `bun/<version>`, `deno/<version>`, or `browser`) plus the OS and architecture on non-browser runtimes.\n\nThe public `VERSION` constant is always the package semver string. The User-Agent product token reports that semver only from a stable published package; source, CI, `npm pack`, and prerelease builds report `b2-sdk-typescript/dev` so development traffic stays distinguishable.\n\nTo prepend your own application identifier:\n\n```ts\nconst client = new B2Client({\n  applicationKeyId,\n  applicationKey,\n  userAgent: 'my-app/1.0',\n})\n// → \"my-app/1.0 b2-sdk-typescript/<version-or-dev> (typescript; @backblaze-labs/b2-sdk; node/<node-version>; linux; x64)\"\n```\n\n## SSRF guard\n\nThe default `FetchTransport` ships an allow-list guard that rejects any URL whose host falls outside the authorized B2 realm. This defends against URL-substitution attacks where a compromised or hostile B2 endpoint could return an upload URL pointing at an internal service (e.g. cloud metadata at `169.254.169.254`) and trick the SDK into making an authenticated request to it.\n\n```ts\nconst client = new B2Client({ applicationKeyId, applicationKey })\nawait client.authorize()\n// Guard is now locked. Hosts under backblazeb2.com / backblaze.com are\n// allowed; literal IPs, localhost, metadata.google.internal, *.internal,\n// and *.local are rejected unconditionally; anything else throws B2SsrfError.\n\nclient.urlGuard?.getAllowedSuffixes()\n// => ['backblaze.com', 'backblazeb2.com']\n```\n\nYou can extend the allow-list (e.g. for a self-hosted MITM proxy during debugging) without disabling the guard:\n\n```ts\nnew B2Client({\n  applicationKeyId,\n  applicationKey,\n  allowedHostSuffixes: ['internal-proxy.example'],\n})\n```\n\nPassing `allowedHostSuffixes: []` disables the guard entirely and should be reserved for trusted tests or controlled local harnesses. For custom realms, the SDK uses the hosts returned by `b2_authorize_account` as scoped suffixes, allowing those hosts and their subdomains without broadening unknown domains to public suffixes such as `co.uk`.\n\nThe default transport follows same-origin `GET` / `HEAD` redirects after each target passes the SSRF guard. Cross-origin redirects and `POST` redirects are blocked with `B2RedirectError`. Pass `followSameOriginRedirects: false` to the `B2Client` constructor to block same-origin redirects as well.\n\nPassing a custom `transport` opts out of the guard (your transport, your threat model).\n\n## Retry behavior\n\nThe SDK automatically retries transient errors with exponential backoff:\n\n- **401 expired_auth_token**: re-authorizes and retries\n- **408, 429, transient 5xx (500, 502, 503, 504)**: exponential backoff with jitter, respects `Retry-After` header\n- **Network errors**: retried with backoff\n- **Permanent errors** (403 cap_exceeded, 404 not_found, etc.): thrown immediately\n\nConfigure retry behavior:\n\n```ts\nconst client = new B2Client({\n  applicationKeyId: '...',\n  applicationKey: '...',\n  retry: {\n    maxRetries: 10,\n    maxRetryDelayMs: 120_000,\n    initialRetryDelayMs: 500,\n    requestTimeoutMs: 30 * 60_000,\n  },\n})\n```\n\n`requestTimeoutMs` covers request dispatch, upload POST bodies, and\nnon-streaming response-body reads. For `response.body` download streams it is an\nidle/no-progress timeout that resets after each received chunk, so healthy large\ndownloads are not aborted merely because the total transfer takes longer than\nthe timeout. Slow large-part uploads may need a higher value or `0` to rely on\nyour own `AbortSignal`. Worst-case terminal latency can be roughly\n`(retry.maxRetries + 1) * requestTimeoutMs` plus backoff when an endpoint hangs.\n\nWhen a multipart upload, streaming upload, or multipart copy fails, the SDK calls `b2_cancel_large_file` on a best-effort basis. Pass `onCleanupFailure` on those operations to observe failed cancellation or a skipped cancellation after an ambiguous `b2_finish_large_file` response, with the relevant `fileId` so operators can reconcile unfinished or possibly committed large files. Pair long-running resume workflows with lifecycle or version-retention cleanup so orphaned unfinished large files do not accumulate past the bounded resume discovery scan.\n\n## Testing with the simulator\n\nThe SDK ships an in-memory B2 simulator for unit testing without network access:\n\n```ts\nimport { describe, it, expect, beforeEach } from 'vitest'\nimport { B2Client, BucketType } from '@backblaze-labs/b2-sdk'\nimport { B2Simulator } from '@backblaze-labs/b2-sdk/simulator'\nimport { BufferSource } from '@backblaze-labs/b2-sdk/streams'\n\ndescribe('my app', () => {\n  let client: B2Client\n\n  beforeEach(async () => {\n    const sim = new B2Simulator()\n    client = new B2Client({\n      applicationKeyId: 'test',\n      applicationKey: 'test',\n      transport: sim.transport(),\n    })\n    await client.authorize()\n  })\n\n  it('uploads and retrieves a file', async () => {\n    const bucket = await client.createBucket({\n      bucketName: 'test-bucket',\n      bucketType: BucketType.AllPrivate,\n    })\n\n    await bucket.upload({\n      fileName: 'test.txt',\n      source: new BufferSource(new TextEncoder().encode('hello')),\n    })\n\n    const listing = await bucket.listFileNames()\n    expect(listing.files).toHaveLength(1)\n    expect(listing.files[0].fileName).toBe('test.txt')\n  })\n})\n```\n\n## Error handling\n\nAll B2 API errors are thrown as typed `B2Error` subclasses. Client-side capability checks throw `B2InsufficientCapabilityError`.\n\n```ts\nimport { BucketType } from '@backblaze-labs/b2-sdk'\nimport {\n  B2Error,\n  CapExceededError,\n  DuplicateBucketNameError,\n  B2InsufficientCapabilityError,\n} from '@backblaze-labs/b2-sdk/errors'\n\ntry {\n  await client.createBucket({ bucketName: 'test', bucketType: BucketType.AllPrivate })\n} catch (err) {\n  if (err instanceof DuplicateBucketNameError) {\n    console.log('Bucket already exists')\n  } else if (err instanceof CapExceededError) {\n    console.log('Storage cap exceeded, upgrade your plan')\n  } else if (err instanceof B2InsufficientCapabilityError) {\n    console.log('Missing capabilities:', err.missing)\n  } else if (err instanceof B2Error) {\n    console.log(`B2 error: ${err.code} (status ${err.status}, retryable: ${err.retryable})`)\n  }\n}\n```\n\n## B2-native primitives, with an S3 escape hatch\n\nThe high-level surface (`B2Client`, `Bucket`, `B2Object`) gives you direct access to features that live in B2's native API:\n\n- **Per-part and whole-file SHA-1 verification** on multipart uploads, plus automatic whole-file verification on downloads when B2 provides a digest.\n- **`b2_copy_part` server-side multipart copy** via `bucket.copyLargeFile()` — no client-side bytes touched.\n- **File retention + legal hold** (object lock) on `bucket.updateFileRetention()` and `bucket.updateFileLegalHold()`.\n- **Time-scoped download tokens** via `bucket.getDownloadAuthorization()` for sharing without exposing the application key.\n- **Replication configuration** via `bucket.update({ replicationConfiguration })`.\n- **Event notification rules** via `bucket.getNotificationRules()` and `bucket.setNotificationRules()`.\n- **Application key restrictions** (per-bucket, per-prefix, per-capability) via `client.createKey()`.\n\nWhen you want S3 compatibility instead — for tooling that already speaks S3, browser direct uploads, or for the Bandwidth Alliance proxy pattern — `@backblaze-labs/b2-sdk/s3` exposes `createS3ClientConfig()`, `presignS3GetObjectUrl()`, and `presignS3PutObjectUrl()` so the same SDK covers both surfaces.\n\nS3 presigned URLs are bearer credentials. The helpers only emit `https:` URLs and require an explicit `region` for custom or proxied endpoints whose region cannot be derived from `s3.<region>.backblazeb2.com`; set `region` and call `createS3ClientConfig()` during startup or deployment health checks before serving traffic. Object keys with path segments exactly `.` or `..` cannot be S3-presigned safely because common URL parsers normalize them before sending; rename those objects, proxy the download through a trusted server, or use a B2-native download authorization URL when that fits the access model. URL validity depends on the signing host's clock, so URL-generating hosts should be NTP-synced, and downstream SigV4 403s should include a clock-skew check. For untrusted uploads, bind `contentType` and `contentLength` when you can; omitting `contentType` lets the uploader store any B2-accepted type, including browser-executable HTML, SVG, XML, or JavaScript. Bound active content types are rejected unless trusted server code passes `trustedUnsafeS3PresignOptIn` to `allowBrowserExecutableContentType`; booleans from request JSON are ignored. GET response overrides that force inline rendering or active content require the same token on their unsafe opt-in fields. The SDK's active-content checks are best-effort denylists, not a complete browser security policy; the SDK cannot set `X-Content-Type-Options: nosniff`, so callers accepting untrusted content should enforce their own content-type allow-list. Presigned PUT URLs are replayable until expiry; if a client retries after B2 stored the object but before the response was observed, the retry can create another file version. Use unique object keys or reconcile by listed file IDs/checksums, and configure lifecycle or version cleanup where duplicate versions must be removed automatically.\n\nThe deprecated `presignGetObjectUrl()` helper returns a B2-native download-authorization URL, not an S3 presigned URL. It keeps the legacy slash-escaped URL shape and permissive string-building behavior for compatibility. Use `createNativeDownloadAuthorizationUrl()` for new B2-native download-token URLs; it uses B2 path-preserving file-name encoding, requires an `https:` Backblaze download origin without userinfo, path, query, or fragment, rejects unsafe bucket names, control characters, invalid compatibility durations, and path-normalizing file names, and constructs the bearer URL from the parsed origin rather than raw-concatenating caller input.\n\n## Source isomorphism\n\nThe SDK is isomorphic at the **source** level, not just at the built artifact level. Every internal import uses a `.ts` extension (`import { foo } from './foo.ts'`, not `'./foo.js'`), `tsconfig.json` has `allowImportingTsExtensions: true` + `rewriteRelativeImportExtensions: true`, and Vite rewrites the extensions to `.js` during build so npm consumers still see a normal `dist/`.\n\nWhat this means in practice: you can point a runtime straight at `src/` without a build step.\n\n```bash\n# Deno reads src/ directly. No `pnpm build`, no node_modules, no npm: shim.\ndeno check examples/node-list-buckets.ts\n\n# Bun does the same.\nbun examples/node-list-buckets.ts\n\n# Node 22.6+ with --experimental-strip-types runs raw .ts.\nnode --experimental-strip-types examples/node-list-buckets.ts\n```\n\nSo you get both: an `npm install`-ready `dist/` (ESM + CJS + DTS), *and* a `src/` tree that runs in Node, Bun, and Deno without a build. Useful when extending the SDK locally, contributing PRs, or vendoring the source into a Deno project.\n\n## Runtime support\n\n| Runtime | Version | Status |\n|---|---|---|\n| Node.js | 22.3+ | Primary target. CI runs the fast suite on Linux, Windows, and macOS for Node 22.22.2 + 24; slow and coverage jobs run on Linux. `FileSource` uses weaker size/mtime validation on Windows because portable dev/inode and ctime fields are unreliable there. |\n| Bun | latest | Tested in CI via `bun test src/` + example typecheck. |\n| Deno | 2.x | Source isomorphism verified in CI via `deno check` against `src/`. |\n| Browsers | Chromium, Firefox, WebKit (last 2 evergreen) | Tested in CI via Playwright. |\n| Cloudflare Workers | - | Compatible target when the standard Web APIs above are available; not yet smoke-tested in CI with a Workers runtime. |\n| Vercel Edge | - | Compatible target when the standard Web APIs above are available; not yet smoke-tested in CI with Vercel Edge. |\n\nRequires: `fetch`, Web Streams, `crypto.subtle`, `AbortSignal`. Node < 22.3 is not supported (Node 20 reached EOL April 2026). `FileSource(path)` throws on runtimes that lack `process.getBuiltinModule('node:fs')`; `FileSource.fromPath(path)` remains the async construction path for supported Node filesystem platforms. On Windows, `FileSource` is supported with weaker size/mtime validation because portable dev/inode and ctime fields are unreliable there.\n\nThe browser test suite (`pnpm test:browser`) runs the same source against real Chromium, Firefox, and WebKit instances. Only Node-specific tests (filename pattern `*.node.test.ts`, covering `node:fs`, `node:os`, `node:util.inspect`) are skipped.\n\n## License\n\nMIT. See [LICENSE](LICENSE).\n\n## Contributing\n\nSee [CONTRIBUTING.md](CONTRIBUTING.md) for development setup and guidelines.\n","readmeFilename":"README.md"}