Usage Reports for Organizations
  • 08 Oct 2026
  • Dark
    Light

Usage Reports for Organizations

  • Dark
    Light

Article summary

Usage Reports provide a daily, detailed ledger of storage, bandwidth, transaction, and bucket usage for a Backblaze B2 Cloud Storage Organization.

Organizations configure and access Usage Reports through the Enterprise Web Console. Creating and managing reports requires the Administrator role scoped to the Organization.

If an Organization contains multiple Billing Accounts, Usage Reports are configured separately for each Billing Account.

Enable Usage Reports

  1. Sign in to your Organization in the Enterprise Web Console.

  2. In the left navigation menu, select Organization > Reports.

  3. Select Report Settings.

  4. Turn on Enable Reporting.

  5. Select the region in which the Usage Reports should be stored.

  6. Select Save.

Backblaze creates a restricted report bucket in the selected region. The bucket name begins with b2-reports.

The Reports page displays the files in the active Usage Report bucket.

Organizations with Multiple Billing Accounts

If a Billing Account selector appears on the Reports page, Usage Reports are configured separately for each Billing Account.

Enabling reports for one Billing Account does not enable reports for the other Billing Accounts in the Organization.

Billing Accounts and B2 Accounts

A Billing Account is a container for billing and usage reporting across one or more B2 Accounts.

A Billing Account is not:

  • A B2 storage Account

  • An S3 namespace

  • A bucket owner

  • An IAM or application-key credential boundary

Billing Account identifiers use the following resource-name format:

billingAccounts/{billingAccountId}

B2 Accounts use 12-digit account identifiers. B2 Accounts own buckets, application keys, IAM resources, and S3 credentials.

Each B2 Account in an Organization is associated with one Billing Account. Multiple B2 Accounts can be associated with the same Billing Account.

The Account resource exposes this association through its billingAccount field:

{
  "name": "accounts/123456789012",
  "accountId": "123456789012",
  "displayName": "customer-storage",
  "billingAccount": "billingAccounts/456"
}

Enable Reports for a Billing Account

  1. Sign in to your Organization in the Enterprise Web Console.

  2. Select Organization > Reports.

  3. Select the Billing Account whose usage you want to report.

  4. Select Report Settings.

  5. Turn on Enable Reporting.

  6. Select a destination Account.

  7. Select the region in which the report bucket should be stored.

  8. Select Save.

The destination Account must be associated with the selected Billing Account. Its billingAccount field must identify the Billing Account whose reports are being configured.

Backblaze creates a restricted report bucket in the selected destination Account and region.

Repeat these steps for every Billing Account for which Usage Reports are required.

Report Generation

Backblaze generates two CSV file types daily:

  • Locations: Lists the Usage files generated for each region.

  • Usage: Contains storage, bandwidth, transaction, bucket, and other usage information.

For an Organization with multiple Billing Accounts, each report covers the B2 Accounts associated with the selected Billing Account.

A separate Usage file is generated for each region that contains reportable usage. If a bucket has no usage to report, that bucket does not appear in the Usage file.

Daily Folder Structure

Files for each UTC day are placed in a folder named in YYYY-MM-DD format. For example:

2026-09-14/

When Usage Reports are first enabled, Backblaze automatically backfills up to seven days of prior usage data.

Locations File

The Locations file identifies the Usage files generated for each region.

The filename uses the following convention:

usage.{resource_name}.reportingLocations.csv

For an Organization with multiple Billing Accounts, resource_name identifies the Billing Account reporting scope.

Column

Description

date

UTC date covered by the report, in YYYY-MM-DD format.

group_id

Empty for Organization reports.

line_version

Revision number of the file format. This value generally changes when columns are added or removed.

report_file_name

Name of the Usage file generated for the specified region.

reporting_location

Region associated with the Usage file.

resource_name

Identifier for the report's Organization or Billing Account scope.

Usage File

A Usage file is generated for each region with reportable usage.

The filename uses the following convention:

usage.{resource_name}.{reporting_location}.csv

Rows for bucket-level usage identify the corresponding B2 Account and bucket. Account-level transactions are represented separately because those transactions cannot always be attributed to an individual bucket.

Column

Description

account_email

Empty for Organization reports.

account_id

Identifier of the B2 Account associated with the reported usage.

api_txn_class_a

Number of Class A transactions.

api_txn_class_b

Number of Class B transactions.

api_txn_class_c

Number of Class C transactions.

api_txn_class_d

Number of Class D transactions.

bucket_id

Identifier of the bucket associated with the usage row.

bucket_name

Name of the bucket associated with the usage row.

date

UTC date covered by the report, in YYYY-MM-DD format.

deleted_gb

Amount of deleted data, in gigabytes.

downloaded_bytes

Number of downloaded bytes, including any applicable free allocation.

downloaded_favored_bytes

Number of favored downloaded bytes. Backblaze does not charge for favored bytes.

downloaded_gb

Amount of downloaded data, in gigabytes.

group_id

Empty for Organization reports.

line_version

Revision number of the file format.

reporting_location

Region associated with the reported usage.

resource_group_id

Identifier of the Resource Group associated with the bucket.

resource_group_name

Name of the Resource Group associated with the bucket.

resource_name

Identifier for the report's Organization or Billing Account scope.

storage_byte_hours

Number of stored byte-hours, including any applicable free allocation.

stored_gb

Amount of data stored at the end of the day, in gigabytes.

uploaded_gb

Amount of uploaded data, in gigabytes.

Additional columns may be added in future file-format revisions. Integrations should use the header row to identify columns rather than relying only on column positions.

Usage Report Bucket

Backblaze writes Usage Reports to a restricted bucket whose name begins with b2-reports.

For an Organization with multiple Billing Accounts, the administrator selects a destination B2 Account and region for each Billing Account. The destination Account must be associated with the selected Billing Account.

The report bucket belongs to the destination B2 Account. It does not belong directly to the Billing Account.

The report bucket is reserved for Usage Report files:

  • The bucket cannot be made public.

  • Customers cannot upload files to the bucket.

  • The bucket should not be used for general-purpose storage.

  • Third-party applications may not support restricted buckets.

  • Stored report files and applicable downloads and transactions are charged to the destination B2 Account.

Backblaze checks for missing report files from the previous seven days and regenerates them when necessary. Do not delete report files until they are at least seven days old.

If the report destination region is changed, the existing report bucket and its files remain available from the Buckets page in the original Account and region. New reports are written to the newly configured destination.

Access Reports through the S3-Compatible API

The report bucket belongs to a regular B2 Account. Credentials must belong to that destination Account even when the report contains usage for an entire Billing Account.

A Billing Account is not an IAM principal or credential boundary. Do not use:

billingAccounts/{billingAccountId}

as a credential target. Use:

accounts/{accountId}

Create an Application Key from the Reports Page

  1. Select Organization > Reports.

  2. If a Billing Account selector appears, select the Billing Account.

  3. Confirm that reporting is enabled and that the report bucket has been provisioned.

  4. Select Application Keys.

  5. Create an application key.

  6. Save the application-key ID and application-key secret.

The secret is displayed only when the key is created.

Use the application-key ID and secret as the S3 access-key ID and secret, together with the S3 endpoint and bucket name shown in the report-bucket details.

The key belongs to the destination B2 Account and is restricted to read-only access to the report bucket.

Create Credentials with the AWS IAM-Compatible API

You can use the Backblaze AWS IAM-compatible API to create and manage credentials for a Usage Report bucket.

Create the IAM user, role, policies, and access keys in the destination B2 Account that owns the report bucket.

An integration can:

  1. Create or select an IAM user in the destination Account.

  2. Attach an IAM policy that permits the required read operations on the report bucket.

  3. Call the IAM-compatible CreateAccessKey operation for that IAM user.

  4. Use the returned access-key ID and secret access key with the Backblaze S3-Compatible API.

The policy should grant only the permissions required to list the report bucket and read its objects. Scope those permissions to the report bucket whenever possible.

Use Temporary IAM Credentials

For short-lived access, use the Backblaze AWS STS-compatible API, such as AssumeRole, or the Organizations API GenerateIamRoleCredentials operation.

The IAM role belongs to the destination B2 Account. Its policies must permit the required read operations on the report bucket.

A GenerateIamRoleCredentials request targets the 12-digit destination Account:

accounts/{accountId}

The returned temporary access-key ID, secret access key, and session token can be used with the Backblaze S3-Compatible API until they expire.

Access Reports for Multiple Billing Accounts

There is no B2 application key that spans report buckets stored in multiple B2 Accounts.

For each Billing Account:

  1. Identify its destination B2 Account.

  2. Identify the report bucket and S3 endpoint.

  3. Create an application key, create an IAM access key, or obtain temporary IAM credentials in the destination Account.

  4. Retrieve the report files through the S3-Compatible API.

A credential created in one B2 Account cannot access a bucket owned by another B2 Account unless the supported authorization model explicitly grants that access.

Billing Account IDs are never used directly to create S3 credentials.

Frequently Asked Questions

Why can't I create a credential for a Billing Account?

A Billing Account is a billing and reporting container, not a storage or credential boundary. Credentials are created for the B2 Account that owns the report bucket.

Why doesn't the Billing Account ID match a 12-digit Account ID?

Billing Accounts and B2 Accounts are different resource types with separate identifier namespaces.

How do I determine which Billing Account contains a B2 Account?

Read the B2 Account resource's billingAccount field.

Can I store a Billing Account's reports in any Account?

No. The destination B2 Account must be associated with the Billing Account whose reports are being configured.

Can one credential access reports for every Billing Account?

A credential can access only the buckets allowed by its Account and policy. Credentials must be created separately when report buckets are stored in different B2 Accounts.


Was this article helpful?