# Next.js boilerplate with Vercel Blob

> Object storage on the platform you already deploy to, in a private Blob store. Client uploads go straight from the browser to Blob after an authorisation check. Each client token is locked to one pathname, one content type and one size. Downloads use short-lived signed URLs, and the dropzone has progress and cancel.

File storage inside your Vercel project. One env var to wire, no second vendor.

- **Category:** Storage
- **Pricing:** Hobby: free up to 1 GB stored, 10,000 simple and 2,000 advanced operations, and 10 GB of transfer a month. Past the limit, Blob stops until the 30 days reset. Pro bills by usage. Prices below are for iad1. Storage is $0.023 per GB-month and transfer $0.05 per GB. Simple operations (cache-miss reads) are $0.40 per million. Advanced operations (put, copy, list) are $5 per million. Deletes are free. Client uploads have no transfer charge.
- **Best for:** Apps already on Vercel that want user uploads (avatars, attachments, imports) without adding a cloud account, IAM, CORS rules or a second bill. Strongest when files are small to medium and read by their owner.
- **Vendor docs:** https://vercel.com/docs/vercel-blob

## Trade-offs

- Egress is billed. Blob data transfer is cheaper than Vercel's regular CDN transfer, but it is not zero. Large media served at volume is the case R2 exists for.
- A store is private or public forever. You pick at creation and cannot change it. Mixing both means two stores.
- Advanced operations are the expensive line. Every put, copy and list counts, and so does browsing the store in the Vercel dashboard.
- Authorisation is your code. Blob has no row level security. The upload route decides who may write and where, every time.
- onUploadCompleted is a webhook from Vercel to your app. It cannot reach localhost, so local testing needs a tunnel.
- Overwrites and deletes take up to 60 seconds to leave the cache. Treat blobs as immutable and give every version a new pathname.

## Known fixes it ships

- [Vercel Blob addRandomSuffix, allowOverwrite, and stale files in the cache](https://agenticboilerplate.com/cookbook/vercel-blob/addrandomsuffix-allowoverwrite-and-the-cache): Blob refuses to overwrite by default, and an overwrite can take 60 seconds to show plus whatever the browser cached. Treat blobs as immutable; use new pathnames, not overwrites.
- [Vercel Blob: client uploads vs server uploads and the 4.5 MB limit](https://agenticboilerplate.com/cookbook/vercel-blob/client-uploads-and-the-4-5-mb-body-limit): A Vercel Function accepts at most 4.5 MB of request body. Server uploads hit it; client uploads skip it. How client uploads work, and when a server upload is still right.
- [Deleting orphaned blobs in Vercel Blob](https://agenticboilerplate.com/cookbook/vercel-blob/deleting-orphaned-blobs): Blobs nobody references still bill every month. Where orphans come from, how to delete them in the same code path as the row, and a safe sweep with list() and del() for the rest.
- [Vercel Blob handleUpload: never trust the pathname from the client](https://agenticboilerplate.com/cookbook/vercel-blob/never-trust-the-client-pathname): With client uploads the browser names the pathname and the token is bound to it. Check it in onBeforeGenerateToken, or any signed-in user can write anywhere in your store.
- [Why Vercel Blob onUploadCompleted never fires on localhost](https://agenticboilerplate.com/cookbook/vercel-blob/onuploadcompleted-never-fires-on-localhost): onUploadCompleted is a webhook from Vercel to your app. It cannot reach localhost, so the SDK skips it. Use a tunnel and VERCEL_BLOB_CALLBACK_URL, and never make the upload depend on it.
- [Private vs public Vercel Blob stores: picking one you cannot change](https://agenticboilerplate.com/cookbook/vercel-blob/private-vs-public-blob-stores): A Blob store's access mode is fixed at creation. Private needs a credential for every read; public is readable by anyone with the URL. How to serve each, and why user files belong in private.
- [What Vercel Blob actually costs, and where egress hides](https://agenticboilerplate.com/cookbook/vercel-blob/vercel-blob-costs-and-egress): Storage is cheap. Advanced operations and data transfer are the lines that grow. How each is counted, why private delivery can cost more, and the habits that keep the bill flat.

## Generate it

[Build a repo with Vercel Blob](https://agenticboilerplate.com/build?b=vercel-blob)

---

Agentic Boilerplate: A Next.js repo your agent already knows. $99 once. Lifetime access and updates.

- Site map for agents: https://agenticboilerplate.com/llms.txt
- Public API: https://agenticboilerplate.com/openapi.json
- Contact: agenticstudio@gmail.com
