Private files
Files belong to the personal account, even when the user switches teams. Anonymous or other-account requests do not gain access through a preview URL. Public brand assets are separate from private storage.
Use the file library
Open /files or /zh/files. Select a valid PNG, JPEG, UTF-8 text or JSON file within the configured limit. Uploading is complete only after the server confirms storage. Refresh the list if the response is lost before uploading again.
Open a saved file to preview it or download its original bytes. Text previews are bounded; a preview may show only the first 64 KiB, so download the original for complete content. Preserve originals needed for later work.
Expired or unavailable files cannot be downloaded. Deletion releases storage through the confirmed server workflow; pending uploads and deletions can still occupy quota. A task using a file may prevent deletion until the task finishes or is cancelled.
Configuration and execution
websiteConfig.storage controls enablement, maximum bytes/files/total quota, retention and read/write limits. Optional Turnstile is controlled by security configuration and requires a matching public/private key pair. Client checks help the user; server validation remains authoritative.
The API reserves quota, writes private objects, confirms records and uses bounded cleanup for incomplete/expired files. Real R2 acceptance is still deferred. Local objects persist in .local/workerd/, which the site factory does not copy.
The file schema requires the relevant existing migrations before new code is run against a separate database. Translation changes do not create a new storage model or migrate the normal preview. See Background tasks and Environment.