netlify-blobs
Store and retrieve unstructured objects, file uploads, and cache-like state on Netlify using the @netlify/blobs key/value API from Functions, Edge Functions, and Build Plugins. Use when a task involves saving user file or image uploads, persisting form or contact-form submissions, storing generated output from Background Functions (sitemaps/processed media/bulk-email results), building read-only asset stores, adding client-side blob expiration, or wiring file-based blob uploads at deploy time. N
Security Assessment
About netlify-blobs
This skill is a usage guide for Netlify Blobs, the zero-config key/value object store for files and assets — images, documents, uploads, exports, and cached binary artifacts — accessible from Functions, Edge Functions, and framework server routes. It solves the problem of persisting unstructured objects on Netlify without provisioning infrastructure, while steering developers away from a common misuse: it repeatedly warns that Blobs is not a dynamic/queryable data store and that records, application state, or anything transactional belongs in Netlify Database instead.
The guide documents the complete API surface deliberately (getStore and getDeployStore, the set/setJSON/get/getWithMetadata/getMetadata/delete/list methods), metadata handling, typed retrieval, prefix-based and auto-paginated listing, and directory-style key navigation. It emphasizes correct-by-default operational behavior: an upfront discovery checklist about asset type, access control, scoping, and volume; the fact that Blobs have no built-in access control so the serving layer is the security gate (default to private); the important caveat that a site-scoped store is shared across production and all preview/branch deploys so destructive tests hit production data; and eventual-versus-strong consistency plus the absence of locking or transactions (last-write-wins).
Target users are web and full-stack developers handling user uploads, form submissions, generated output from background functions, or read-only asset stores. Security guidance here is conscientious and defensive — private-by-default, explicit warnings against building counters or balances on a single blob key — so the skill is benign.
FAQ
When should I use Blobs instead of a database?
Use Blobs when you are storing a file or asset (images, documents, uploads, exports, cached binaries). For records, user data, application state, or anything queryable or transactional, use Netlify Database instead.
Does Blobs handle access control?
No. Blobs have no built-in access control; the serving layer (your function code) is the gate. The skill recommends defaulting to private and streaming through an authenticated function, since exposing data publicly is hard to undo.
What is the difference between site-scoped and deploy-scoped stores?
Site-scoped stores (getStore) persist across all deploys and are the default for user data, but they are shared across production and every preview/branch deploy, so previews read and overwrite production data. Deploy-scoped stores (getDeployStore) are tied to a single deploy's lifecycle.
Can I rely on reading a value immediately after writing it?
Only with strong consistency. Blobs are eventually consistent by default, so an immediate read may return the previous value or null. Opt into strong consistency per-store or per-read for read-your-writes, but reserve it since strong reads are slower.
Can I build a counter or balance on a blob key?
No. Blobs have no locking or transactions and concurrent writes are last-write-wins, so read-modify-write logic can silently lose updates. Use Netlify Database for atomic or transactional updates.
Install netlify-blobs
Quick Setup:
- Copy the skill folder to
.claude/skills/ - Claude will automatically detect and use the skill
Repository
netlify/context-and-tools