---
title: Backblaze B2
description: Receive B2 Event Notifications at files.events.webhook(), verified with the rule's HMAC-SHA256 signing secret.
---

B2 Event Notifications POST to a webhook URL. The `backblaze-b2` adapter reads the `b2` format.

Create a rule in the B2 web UI (Buckets → Event Notifications) or with the `b2_set_bucket_notification_rules` API. Choose `b2:ObjectCreated:*`, `b2:ObjectDeleted:*` and `b2:HideMarkerCreated:*`, set the webhook URL, and set a signing secret.

```ts title="app/api/storage-events/route.ts" lineNumbers
import { createRouteHandler } from "files-sdk/next";
import { files } from "@/lib/files";

export const { POST } = createRouteHandler(
  files.events.webhook({ verify: { secret: process.env.B2_SIGNING_SECRET! } })
);
```

`verify: { secret }` checks `X-Bz-Event-Notification-Signature` (`v1=<hex HMAC-SHA256 of the body>`). A rule without a signing secret sends unsigned deliveries; authenticate those another way, for example a `?token=` in the URL with `verify: { token }`.

## Hide markers are deletes

`files-sdk/backblaze-b2` deletes through B2's S3-compatible API without a version id, which hides the file instead of removing its versions. That arrives as `b2:HideMarkerCreated:Hide`, so subscribe to hide markers to see your own deletes. Both hide markers and `b2:ObjectDeleted:*` become `deleted`.

`b2:TestEvent` (the dashboard's test button) parses to nothing. `event.id` is B2's `eventId`, and `versionId` is the file version.
