- 08 Oct 2026
- Print
- DarkLight
Usage Reports for Organizations
- Updated on 08 Oct 2026
- Print
- DarkLight
Usage Reports provide a daily, detailed ledger of storage, bandwidth, transaction, and bucket usage for a Backblaze B2 Cloud Storage Organization.
Organizations configure and access Usage Reports through the Enterprise Web Console. Creating and managing reports requires the Administrator role scoped to the Organization.
If an Organization contains multiple Billing Accounts, Usage Reports are configured separately for each Billing Account.
Enable Usage Reports
Sign in to your Organization in the Enterprise Web Console.
In the left navigation menu, select Organization > Reports.
Select Report Settings.
Turn on Enable Reporting.
Select the region in which the Usage Reports should be stored.
Select Save.
Backblaze creates a restricted report bucket in the selected region. The bucket name begins with b2-reports.
The Reports page displays the files in the active Usage Report bucket.
Organizations with Multiple Billing Accounts
If a Billing Account selector appears on the Reports page, Usage Reports are configured separately for each Billing Account.
Enabling reports for one Billing Account does not enable reports for the other Billing Accounts in the Organization.
Billing Accounts and B2 Accounts
A Billing Account is a container for billing and usage reporting across one or more B2 Accounts.
A Billing Account is not:
A B2 storage Account
An S3 namespace
A bucket owner
An IAM or application-key credential boundary
Billing Account identifiers use the following resource-name format:
billingAccounts/{billingAccountId}
B2 Accounts use 12-digit account identifiers. B2 Accounts own buckets, application keys, IAM resources, and S3 credentials.
Each B2 Account in an Organization is associated with one Billing Account. Multiple B2 Accounts can be associated with the same Billing Account.
The Account resource exposes this association through its billingAccount field:
{
"name": "accounts/123456789012",
"accountId": "123456789012",
"displayName": "customer-storage",
"billingAccount": "billingAccounts/456"
}
Enable Reports for a Billing Account
Sign in to your Organization in the Enterprise Web Console.
Select Organization > Reports.
Select the Billing Account whose usage you want to report.
Select Report Settings.
Turn on Enable Reporting.
Select a destination Account.
Select the region in which the report bucket should be stored.
Select Save.
The destination Account must be associated with the selected Billing Account. Its billingAccount field must identify the Billing Account whose reports are being configured.
Backblaze creates a restricted report bucket in the selected destination Account and region.
Repeat these steps for every Billing Account for which Usage Reports are required.
Report Generation
Backblaze generates two CSV file types daily:
Locations: Lists the Usage files generated for each region.
Usage: Contains storage, bandwidth, transaction, bucket, and other usage information.
For an Organization with multiple Billing Accounts, each report covers the B2 Accounts associated with the selected Billing Account.
A separate Usage file is generated for each region that contains reportable usage. If a bucket has no usage to report, that bucket does not appear in the Usage file.
Daily Folder Structure
Files for each UTC day are placed in a folder named in YYYY-MM-DD format. For example:
2026-09-14/
When Usage Reports are first enabled, Backblaze automatically backfills up to seven days of prior usage data.
Locations File
The Locations file identifies the Usage files generated for each region.
The filename uses the following convention:
usage.{resource_name}.reportingLocations.csv
For an Organization with multiple Billing Accounts, resource_name identifies the Billing Account reporting scope.
Column | Description |
|---|---|
| UTC date covered by the report, in |
| Empty for Organization reports. |
| Revision number of the file format. This value generally changes when columns are added or removed. |
| Name of the Usage file generated for the specified region. |
| Region associated with the Usage file. |
| Identifier for the report's Organization or Billing Account scope. |
Usage File
A Usage file is generated for each region with reportable usage.
The filename uses the following convention:
usage.{resource_name}.{reporting_location}.csv
Rows for bucket-level usage identify the corresponding B2 Account and bucket. Account-level transactions are represented separately because those transactions cannot always be attributed to an individual bucket.
Column | Description |
|---|---|
| Empty for Organization reports. |
| Identifier of the B2 Account associated with the reported usage. |
| Number of Class A transactions. |
| Number of Class B transactions. |
| Number of Class C transactions. |
| Number of Class D transactions. |
| Identifier of the bucket associated with the usage row. |
| Name of the bucket associated with the usage row. |
| UTC date covered by the report, in |
| Amount of deleted data, in gigabytes. |
| Number of downloaded bytes, including any applicable free allocation. |
| Number of favored downloaded bytes. Backblaze does not charge for favored bytes. |
| Amount of downloaded data, in gigabytes. |
| Empty for Organization reports. |
| Revision number of the file format. |
| Region associated with the reported usage. |
| Identifier of the Resource Group associated with the bucket. |
| Name of the Resource Group associated with the bucket. |
| Identifier for the report's Organization or Billing Account scope. |
| Number of stored byte-hours, including any applicable free allocation. |
| Amount of data stored at the end of the day, in gigabytes. |
| Amount of uploaded data, in gigabytes. |
Additional columns may be added in future file-format revisions. Integrations should use the header row to identify columns rather than relying only on column positions.
Usage Report Bucket
Backblaze writes Usage Reports to a restricted bucket whose name begins with b2-reports.
For an Organization with multiple Billing Accounts, the administrator selects a destination B2 Account and region for each Billing Account. The destination Account must be associated with the selected Billing Account.
The report bucket belongs to the destination B2 Account. It does not belong directly to the Billing Account.
The report bucket is reserved for Usage Report files:
The bucket cannot be made public.
Customers cannot upload files to the bucket.
The bucket should not be used for general-purpose storage.
Third-party applications may not support restricted buckets.
Stored report files and applicable downloads and transactions are charged to the destination B2 Account.
Backblaze checks for missing report files from the previous seven days and regenerates them when necessary. Do not delete report files until they are at least seven days old.
If the report destination region is changed, the existing report bucket and its files remain available from the Buckets page in the original Account and region. New reports are written to the newly configured destination.
Access Reports through the S3-Compatible API
The report bucket belongs to a regular B2 Account. Credentials must belong to that destination Account even when the report contains usage for an entire Billing Account.
A Billing Account is not an IAM principal or credential boundary. Do not use:
billingAccounts/{billingAccountId}
as a credential target. Use:
accounts/{accountId}
Create an Application Key from the Reports Page
Select Organization > Reports.
If a Billing Account selector appears, select the Billing Account.
Confirm that reporting is enabled and that the report bucket has been provisioned.
Select Application Keys.
Create an application key.
Save the application-key ID and application-key secret.
The secret is displayed only when the key is created.
Use the application-key ID and secret as the S3 access-key ID and secret, together with the S3 endpoint and bucket name shown in the report-bucket details.
The key belongs to the destination B2 Account and is restricted to read-only access to the report bucket.
Create Credentials with the AWS IAM-Compatible API
You can use the Backblaze AWS IAM-compatible API to create and manage credentials for a Usage Report bucket.
Create the IAM user, role, policies, and access keys in the destination B2 Account that owns the report bucket.
An integration can:
Create or select an IAM user in the destination Account.
Attach an IAM policy that permits the required read operations on the report bucket.
Call the IAM-compatible
CreateAccessKeyoperation for that IAM user.Use the returned access-key ID and secret access key with the Backblaze S3-Compatible API.
The policy should grant only the permissions required to list the report bucket and read its objects. Scope those permissions to the report bucket whenever possible.
Use Temporary IAM Credentials
For short-lived access, use the Backblaze AWS STS-compatible API, such as AssumeRole, or the Organizations API GenerateIamRoleCredentials operation.
The IAM role belongs to the destination B2 Account. Its policies must permit the required read operations on the report bucket.
A GenerateIamRoleCredentials request targets the 12-digit destination Account:
accounts/{accountId}
The returned temporary access-key ID, secret access key, and session token can be used with the Backblaze S3-Compatible API until they expire.
Access Reports for Multiple Billing Accounts
There is no B2 application key that spans report buckets stored in multiple B2 Accounts.
For each Billing Account:
Identify its destination B2 Account.
Identify the report bucket and S3 endpoint.
Create an application key, create an IAM access key, or obtain temporary IAM credentials in the destination Account.
Retrieve the report files through the S3-Compatible API.
A credential created in one B2 Account cannot access a bucket owned by another B2 Account unless the supported authorization model explicitly grants that access.
Billing Account IDs are never used directly to create S3 credentials.
Frequently Asked Questions
Why can't I create a credential for a Billing Account?
A Billing Account is a billing and reporting container, not a storage or credential boundary. Credentials are created for the B2 Account that owns the report bucket.
Why doesn't the Billing Account ID match a 12-digit Account ID?
Billing Accounts and B2 Accounts are different resource types with separate identifier namespaces.
How do I determine which Billing Account contains a B2 Account?
Read the B2 Account resource's billingAccount field.
Can I store a Billing Account's reports in any Account?
No. The destination B2 Account must be associated with the Billing Account whose reports are being configured.
Can one credential access reports for every Billing Account?
A credential can access only the buckets allowed by its Account and policy. Credentials must be created separately when report buckets are stored in different B2 Accounts.