Backblaze B2 MCP Server (backblaze-labs/b2-mcp) is an MCP server listed on the M8ven Trust Index. It scores 89 out of 100, grade B. It declares 40 tools. The publisher has proved control of what we score (Verified Publisher). It is connected through the M8ven GitHub App, so the listing is re-checked on every push.
MCP server for Backblaze B2 Cloud Storage: a focused, safe 40-tool surface (17 native B2 SDK, 19 S3 data-plane, 4 analytics) for any MCP-compatible AI client, currently incubating in Backblaze-Labs
Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Monitored 5 days · every push re-verified
Who stands behind it
backblaze.com (@backblaze-labs) · Verified Publisher
Source: Publisher
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
B2_ALLOW_LOCAL_FILESAppend-only plaintext JSONL credential ledger for file sink mode. HTTP/serverless file mode requires this explicit absolute path and B2_ALLOW_LOCAL_FILES=trueB2_CAPABILITY_CACHE_MAX_ENTRIESBounded capability-discovery cache TTL and size; cache identity is secret-bound, log labels are non-secret fingerprintsB2_CAPABILITY_CACHE_TTL_MSBounded capability-discovery cache TTL and size; cache identity is secret-bound, log labels are non-secret fingerprintsB2_DESTRUCTIVE_POLICYGate on destructive tools: confirm requires MCP form elicitation approval on compatible 2026 clients, or confirm: true when elicitation is unavailable/disabled; elicit requires human elicitation approval and refuses when no human can be prompted; block refuses before elicitation; allow skips both gatesB2_ENABLE_MCP_PROMPTSMCP workflow prompts (prompts/list, prompts/get) are off by default; set true once every replica runs prompt-capable code. Gates registration and advertisement together, so flip it atomically across the fleet (or use sticky routing)B2_FILE_ROOTB2_HTTP_CREDENTIAL_MODEheaders, server, or principal; unset preserves existing header-based clients. Set explicitly for hosted deploymentsB2_MAX_KEY_DURATION_SECONDSOptional maximum for b2_create_key; when set, non-expiring keys and longer durations are refused before any B2 create callB2_MCP_OUTPUT_FORMATLLM-facing TextContent.text format for structured successes: compact json or opt-in toonB2_MCP_PUBLIC_URLB2_MCP_UA_SUFFIXOptional operator token appended _after_ the built-in b2-mcp/<version> product token on the outbound User-Agent (tag a deployment)B2_OAUTH_JWKS_URIB2_OAUTH_RESOURCEB2_PRINCIPAL_CREDENTIAL_MAPJSON map from verified MCP principal to a customer-managed credential referenceB2_REGIONFallback/default S3-compatible endpoint region; authorized B2 responses override this for S3/report toolsB2_S3_SAVE_TO_PATH_IDLE_TIMEOUT_MSIdle timeout while streaming s3_get_object results to saveToPathB2_TRUST_PROXY_HEADERSHTTP transport: trust X-Forwarded-For / X-Real-IP for unauthenticated admission keys only behind a trusted proxyLOG_LEVELVERCEL[](https://m8ven.ai/mcp/backblaze-labs-b2-mcp-92j1t6)?variant=verified to the badge URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check