diff --git a/MANUAL.html b/MANUAL.html index 4a397f5b7..23f7906bf 100644 --- a/MANUAL.html +++ b/MANUAL.html @@ -233,7 +233,7 @@

rclone(1) User Manual

Nick Craig-Wood

-

Jul 31, 2026

+

Sep 04, 2026

NAME

rclone - manage files on cloud storage

@@ -868,7 +868,7 @@ current version is as below.

src="https://snapcraft.io/rclone/badge.svg" alt="rclone" />

Source installation

Make sure you have git and Go -installed. Go version 1.25 or newer is required, the latest release is +installed. Go version 1.26 or newer is required, the latest release is recommended. You can get it from your package manager, or download it from golang.org/dl. Then you can run the following:

@@ -4623,9 +4623,9 @@ SquareBracket
rclone convmv "stories/The Quick Brown Fox!.txt" --name-transform "all,command=echo"
 // Output: stories/The Quick Brown Fox!.txt
rclone convmv "stories/The Quick Brown Fox!" --name-transform "date=-{YYYYMMDD}"
-// Output: stories/The Quick Brown Fox!-20260731
+// Output: stories/The Quick Brown Fox!-20260904
rclone convmv "stories/The Quick Brown Fox!" --name-transform "date=-{macfriendlytime}"
-// Output: stories/The Quick Brown Fox!-2026-07-31 0340PM
+// Output: stories/The Quick Brown Fox!-2026-09-04 0450PM
rclone convmv "stories/The Quick Brown Fox!.txt" --name-transform "all,regex=[\\.\\w]/ab"
 // Output: ababababababab/ababab ababababab ababababab ababab!abababab

The regex command generally accepts Perl-style regular expressions, @@ -6164,6 +6164,12 @@ server.

and serve commands on macOS. For details, see vfs-case-sensitivity.

NFS mount

+

For macOS (and other platforms where this path is supported), prefer +the dedicated rclone nfsmount +command. It starts the NFS server and performs the mount for you. +rclone mount itself still uses FUSE (macFUSE/FUSE-T) and +does not switch to NFS via a flag.

This method spins up an NFS server using serve nfs command and mounts it to the specified mountpoint. If you run this in @@ -6453,7 +6459,7 @@ that will be used to buffer data in advance.

memory at all times. The buffered data is bound to one open file and won't be shared.

This flag is a upper limit for the used memory per open file. The -buffer will only use memory for data that is downloaded but not not yet +buffer will only use memory for data that is downloaded but not yet read. If the buffer is empty, only a small amount of memory will be used.

The maximum memory used by rclone for buffering can be up to @@ -6496,11 +6502,12 @@ will start with files that haven't been accessed for the longest. This cache flushing strategy is efficient and more relevant files are likely to remain cached.

The --vfs-cache-max-age will evict files from the cache -after the set time since last access has passed. The default value of 1 -hour will start evicting files from cache that haven't been accessed for -1 hour. When a cached file is accessed the 1 hour timer is reset to 0 -and will wait for 1 more hour before evicting. Specify the time with -standard notation, s, m, h, d, w .

+after the set time since last access has passed; it is based on access +time, not on when the file was first added to the cache. The default +value of 1 hour will start evicting files from cache that haven't been +accessed for 1 hour. When a cached file is accessed the 1 hour timer is +reset to 0 and will wait for 1 more hour before evicting. Specify the +time with standard notation, s, m, h, d, w .

You should not run two copies of rclone using the same VFS cache with the same or overlapping remotes if using --vfs-cache-mode > off. This can potentially cause data @@ -7438,6 +7445,12 @@ server.

and serve commands on macOS. For details, see vfs-case-sensitivity.

NFS mount

+

For macOS (and other platforms where this path is supported), prefer +the dedicated rclone nfsmount +command. It starts the NFS server and performs the mount for you. +rclone mount itself still uses FUSE (macFUSE/FUSE-T) and +does not switch to NFS via a flag.

This method spins up an NFS server using serve nfs command and mounts it to the specified mountpoint. If you run this in @@ -7727,7 +7740,7 @@ that will be used to buffer data in advance.

memory at all times. The buffered data is bound to one open file and won't be shared.

This flag is a upper limit for the used memory per open file. The -buffer will only use memory for data that is downloaded but not not yet +buffer will only use memory for data that is downloaded but not yet read. If the buffer is empty, only a small amount of memory will be used.

The maximum memory used by rclone for buffering can be up to @@ -7770,11 +7783,12 @@ will start with files that haven't been accessed for the longest. This cache flushing strategy is efficient and more relevant files are likely to remain cached.

The --vfs-cache-max-age will evict files from the cache -after the set time since last access has passed. The default value of 1 -hour will start evicting files from cache that haven't been accessed for -1 hour. When a cached file is accessed the 1 hour timer is reset to 0 -and will wait for 1 more hour before evicting. Specify the time with -standard notation, s, m, h, d, w .

+after the set time since last access has passed; it is based on access +time, not on when the file was first added to the cache. The default +value of 1 hour will start evicting files from cache that haven't been +accessed for 1 hour. When a cached file is accessed the 1 hour timer is +reset to 0 and will wait for 1 more hour before evicting. Specify the +time with standard notation, s, m, h, d, w .

You should not run two copies of rclone using the same VFS cache with the same or overlapping remotes if using --vfs-cache-mode > off. This can potentially cause data @@ -8847,7 +8861,7 @@ that will be used to buffer data in advance.

memory at all times. The buffered data is bound to one open file and won't be shared.

This flag is a upper limit for the used memory per open file. The -buffer will only use memory for data that is downloaded but not not yet +buffer will only use memory for data that is downloaded but not yet read. If the buffer is empty, only a small amount of memory will be used.

The maximum memory used by rclone for buffering can be up to @@ -8890,11 +8904,12 @@ will start with files that haven't been accessed for the longest. This cache flushing strategy is efficient and more relevant files are likely to remain cached.

The --vfs-cache-max-age will evict files from the cache -after the set time since last access has passed. The default value of 1 -hour will start evicting files from cache that haven't been accessed for -1 hour. When a cached file is accessed the 1 hour timer is reset to 0 -and will wait for 1 more hour before evicting. Specify the time with -standard notation, s, m, h, d, w .

+after the set time since last access has passed; it is based on access +time, not on when the file was first added to the cache. The default +value of 1 hour will start evicting files from cache that haven't been +accessed for 1 hour. When a cached file is accessed the 1 hour timer is +reset to 0 and will wait for 1 more hour before evicting. Specify the +time with standard notation, s, m, h, d, w .

You should not run two copies of rclone using the same VFS cache with the same or overlapping remotes if using --vfs-cache-mode > off. This can potentially cause data @@ -9411,7 +9426,7 @@ that will be used to buffer data in advance.

memory at all times. The buffered data is bound to one open file and won't be shared.

This flag is a upper limit for the used memory per open file. The -buffer will only use memory for data that is downloaded but not not yet +buffer will only use memory for data that is downloaded but not yet read. If the buffer is empty, only a small amount of memory will be used.

The maximum memory used by rclone for buffering can be up to @@ -9454,11 +9469,12 @@ will start with files that haven't been accessed for the longest. This cache flushing strategy is efficient and more relevant files are likely to remain cached.

The --vfs-cache-max-age will evict files from the cache -after the set time since last access has passed. The default value of 1 -hour will start evicting files from cache that haven't been accessed for -1 hour. When a cached file is accessed the 1 hour timer is reset to 0 -and will wait for 1 more hour before evicting. Specify the time with -standard notation, s, m, h, d, w .

+after the set time since last access has passed; it is based on access +time, not on when the file was first added to the cache. The default +value of 1 hour will start evicting files from cache that haven't been +accessed for 1 hour. When a cached file is accessed the 1 hour timer is +reset to 0 and will wait for 1 more hour before evicting. Specify the +time with standard notation, s, m, h, d, w .

You should not run two copies of rclone using the same VFS cache with the same or overlapping remotes if using --vfs-cache-mode > off. This can potentially cause data @@ -9920,7 +9936,7 @@ that will be used to buffer data in advance.

memory at all times. The buffered data is bound to one open file and won't be shared.

This flag is a upper limit for the used memory per open file. The -buffer will only use memory for data that is downloaded but not not yet +buffer will only use memory for data that is downloaded but not yet read. If the buffer is empty, only a small amount of memory will be used.

The maximum memory used by rclone for buffering can be up to @@ -9963,11 +9979,12 @@ will start with files that haven't been accessed for the longest. This cache flushing strategy is efficient and more relevant files are likely to remain cached.

The --vfs-cache-max-age will evict files from the cache -after the set time since last access has passed. The default value of 1 -hour will start evicting files from cache that haven't been accessed for -1 hour. When a cached file is accessed the 1 hour timer is reset to 0 -and will wait for 1 more hour before evicting. Specify the time with -standard notation, s, m, h, d, w .

+after the set time since last access has passed; it is based on access +time, not on when the file was first added to the cache. The default +value of 1 hour will start evicting files from cache that haven't been +accessed for 1 hour. When a cached file is accessed the 1 hour timer is +reset to 0 and will wait for 1 more hour before evicting. Specify the +time with standard notation, s, m, h, d, w .

You should not run two copies of rclone using the same VFS cache with the same or overlapping remotes if using --vfs-cache-mode > off. This can potentially cause data @@ -10296,35 +10313,69 @@ proxy program to make a complete config.

-

And it may have this parameter

+

And it may have these parameters

If password authentication was used by the client, input to the proxy process (on STDIN) would look similar to this:

{
   "user": "me",
-  "pass": "mypassword"
-}
+ "pass": "mypassword", + "client_ip": "192.168.1.1" +}

If public-key authentication was used by the client, input to the proxy process (on STDIN) would look similar to this:

{
   "user": "me",
-  "public_key": "AAAAB3NzaC1yc2EAAAADAQABAAABAQDuwESFdAe14hVS6omeyX7edc...JQdf"
-}
-

And as an example return this on STDOUT

+ "public_key": "AAAAB3NzaC1yc2EAAAADAQABAAABAQDuwESFdAe14hVS6omeyX7edc...JQdf", + "client_ip": "192.168.1.1" +} +

If the client authenticated with an S3 access key +(rclone serve s3), the client never sends its secret, only +a signature made with it, so the input contains just the access key ID +as the user with no pass or +public_key:

{
-  "type": "sftp",
-  "_root": "",
-  "_obscure": "pass",
-  "user": "me",
-  "pass": "mypassword",
-  "host": "sftp.example.com"
-}
+ "user": "AKIAIOSFODNN7EXAMPLE", + "client_ip": "192.168.1.1" +} +

In this case the program must look up the secret access key for that +access key ID and return it in the _secret_access_key field +of the output. Rclone then uses that secret to verify the signature on +the request, refusing the request if it does not match. This means the +proxy program is the source of truth for both the credentials and the +backend they map to. If the program does not return +_secret_access_key or returns it empty the request is +refused.

+

The program's answer for an access key ID is cached (see below) but +is checked with the program again after 5 minutes even if the access key +ID is in constant use, so revoking an access key ID in the program takes +effect within 5 minutes. A rotated secret takes effect on the first +request signed with it.

+

The client_ip key holds the IP address the client +connected from, without a port number. It can be used to restrict logins +to certain networks, or to log authentication attempts centrally. It is +omitted if the client has no IP address, for example when connecting +over a unix socket. Note that if rclone is behind a reverse proxy this +will be the address of the reverse proxy and not the original +client.

+

And as an example return this on STDOUT

+
{
+  "type": "sftp",
+  "_root": "",
+  "_obscure": "pass",
+  "user": "me",
+  "pass": "mypassword",
+  "host": "sftp.example.com"
+}

This would mean that an SFTP backend would be created on the fly for the user and pass/public_key returned in the output to the host given. Note that since @@ -10337,12 +10388,13 @@ make the user be user@example.com and then set the host to example.com in the output and the user to user. For security you'd probably want to restrict the host to a limited list.

-

An internal cache of backends is keyed on the user and a -hash of the pass or public_key. This means -that if a user's password or public-key changes, or the proxy returns -different config parameters (eg a rotated api_key), a fresh -backend will be created on the next request rather than the cached one -being reused.

+

An internal cache of backends is keyed on the user, a +hash of the pass or public_key, and the +client_ip. This means that if a user's password or +public-key changes, the client connects from a new IP address, or the +proxy returns different config parameters (eg a rotated +api_key), a fresh backend will be created on the next +request rather than the cached one being reused.

This can be used to build general purpose proxies to any kind of backend that rclone supports.

rclone serve ftp remote:path [flags]
@@ -10711,7 +10763,7 @@ that will be used to buffer data in advance.

memory at all times. The buffered data is bound to one open file and won't be shared.

This flag is a upper limit for the used memory per open file. The -buffer will only use memory for data that is downloaded but not not yet +buffer will only use memory for data that is downloaded but not yet read. If the buffer is empty, only a small amount of memory will be used.

The maximum memory used by rclone for buffering can be up to @@ -10754,11 +10806,12 @@ will start with files that haven't been accessed for the longest. This cache flushing strategy is efficient and more relevant files are likely to remain cached.

The --vfs-cache-max-age will evict files from the cache -after the set time since last access has passed. The default value of 1 -hour will start evicting files from cache that haven't been accessed for -1 hour. When a cached file is accessed the 1 hour timer is reset to 0 -and will wait for 1 more hour before evicting. Specify the time with -standard notation, s, m, h, d, w .

+after the set time since last access has passed; it is based on access +time, not on when the file was first added to the cache. The default +value of 1 hour will start evicting files from cache that haven't been +accessed for 1 hour. When a cached file is accessed the 1 hour timer is +reset to 0 and will wait for 1 more hour before evicting. Specify the +time with standard notation, s, m, h, d, w .

You should not run two copies of rclone using the same VFS cache with the same or overlapping remotes if using --vfs-cache-mode > off. This can potentially cause data @@ -11087,35 +11140,69 @@ proxy program to make a complete config.

-

And it may have this parameter

+

And it may have these parameters

If password authentication was used by the client, input to the proxy process (on STDIN) would look similar to this:

-
{
-  "user": "me",
-  "pass": "mypassword"
-}
-

If public-key authentication was used by the client, input to the -proxy process (on STDIN) would look similar to this:

{
   "user": "me",
-  "public_key": "AAAAB3NzaC1yc2EAAAADAQABAAABAQDuwESFdAe14hVS6omeyX7edc...JQdf"
-}
-

And as an example return this on STDOUT

+ "pass": "mypassword", + "client_ip": "192.168.1.1" +} +

If public-key authentication was used by the client, input to the +proxy process (on STDIN) would look similar to this:

{
-  "type": "sftp",
-  "_root": "",
-  "_obscure": "pass",
-  "user": "me",
-  "pass": "mypassword",
-  "host": "sftp.example.com"
-}
+ "user": "me", + "public_key": "AAAAB3NzaC1yc2EAAAADAQABAAABAQDuwESFdAe14hVS6omeyX7edc...JQdf", + "client_ip": "192.168.1.1" +} +

If the client authenticated with an S3 access key +(rclone serve s3), the client never sends its secret, only +a signature made with it, so the input contains just the access key ID +as the user with no pass or +public_key:

+
{
+  "user": "AKIAIOSFODNN7EXAMPLE",
+  "client_ip": "192.168.1.1"
+}
+

In this case the program must look up the secret access key for that +access key ID and return it in the _secret_access_key field +of the output. Rclone then uses that secret to verify the signature on +the request, refusing the request if it does not match. This means the +proxy program is the source of truth for both the credentials and the +backend they map to. If the program does not return +_secret_access_key or returns it empty the request is +refused.

+

The program's answer for an access key ID is cached (see below) but +is checked with the program again after 5 minutes even if the access key +ID is in constant use, so revoking an access key ID in the program takes +effect within 5 minutes. A rotated secret takes effect on the first +request signed with it.

+

The client_ip key holds the IP address the client +connected from, without a port number. It can be used to restrict logins +to certain networks, or to log authentication attempts centrally. It is +omitted if the client has no IP address, for example when connecting +over a unix socket. Note that if rclone is behind a reverse proxy this +will be the address of the reverse proxy and not the original +client.

+

And as an example return this on STDOUT

+
{
+  "type": "sftp",
+  "_root": "",
+  "_obscure": "pass",
+  "user": "me",
+  "pass": "mypassword",
+  "host": "sftp.example.com"
+}

This would mean that an SFTP backend would be created on the fly for the user and pass/public_key returned in the output to the host given. Note that since @@ -11128,12 +11215,13 @@ make the user be user@example.com and then set the host to example.com in the output and the user to user. For security you'd probably want to restrict the host to a limited list.

-

An internal cache of backends is keyed on the user and a -hash of the pass or public_key. This means -that if a user's password or public-key changes, or the proxy returns -different config parameters (eg a rotated api_key), a fresh -backend will be created on the next request rather than the cached one -being reused.

+

An internal cache of backends is keyed on the user, a +hash of the pass or public_key, and the +client_ip. This means that if a user's password or +public-key changes, the client connects from a new IP address, or the +proxy returns different config parameters (eg a rotated +api_key), a fresh backend will be created on the next +request rather than the cached one being reused.

This can be used to build general purpose proxies to any kind of backend that rclone supports.

rclone serve http remote:path [flags]
@@ -11281,20 +11369,20 @@ default is 1000000, but consider lowering this limit if the server's system resource usage causes problems. This is only used by the memory type cache.

To serve NFS over the network use following command:

-
rclone serve nfs remote: --addr 0.0.0.0:$PORT --vfs-cache-mode=full
+
rclone serve nfs remote: --addr 0.0.0.0:$PORT --vfs-cache-mode=full

This specifies a port that can be used in the mount command. To mount the server under Linux/macOS, use the following command:

-
mount -t nfs -o port=$PORT,mountport=$PORT,tcp $HOSTNAME:/ path/to/mountpoint
+
mount -t nfs -o port=$PORT,mountport=$PORT,tcp $HOSTNAME:/ path/to/mountpoint

Where $PORT is the same port number used in the serve nfs command and $HOSTNAME is the network address of the machine that serve nfs was run on.

NFS clients can also mount a subdirectory of the served remote by including it in the mount path. For example to mount only the photos/2024 subdirectory:

-
mount -t nfs -o port=$PORT,mountport=$PORT,tcp $HOSTNAME:/photos/2024 path/to/mountpoint
+
mount -t nfs -o port=$PORT,mountport=$PORT,tcp $HOSTNAME:/photos/2024 path/to/mountpoint

The subpath is resolved within the served remote and must refer to an existing directory (not a file or a symlink). Subpath mounts are a convenience equivalent to mounting / and changing @@ -11346,7 +11434,7 @@ that will be used to buffer data in advance.

memory at all times. The buffered data is bound to one open file and won't be shared.

This flag is a upper limit for the used memory per open file. The -buffer will only use memory for data that is downloaded but not not yet +buffer will only use memory for data that is downloaded but not yet read. If the buffer is empty, only a small amount of memory will be used.

The maximum memory used by rclone for buffering can be up to @@ -11389,11 +11477,12 @@ will start with files that haven't been accessed for the longest. This cache flushing strategy is efficient and more relevant files are likely to remain cached.

The --vfs-cache-max-age will evict files from the cache -after the set time since last access has passed. The default value of 1 -hour will start evicting files from cache that haven't been accessed for -1 hour. When a cached file is accessed the 1 hour timer is reset to 0 -and will wait for 1 more hour before evicting. Specify the time with -standard notation, s, m, h, d, w .

+after the set time since last access has passed; it is based on access +time, not on when the file was first added to the cache. The default +value of 1 hour will start evicting files from cache that haven't been +accessed for 1 hour. When a cached file is accessed the 1 hour timer is +reset to 0 and will wait for 1 more hour before evicting. Specify the +time with standard notation, s, m, h, d, w .

You should not run two copies of rclone using the same VFS cache with the same or overlapping remotes if using --vfs-cache-mode > off. This can potentially cause data @@ -11992,6 +12081,11 @@ docs).

--auth-key can be repeated for multiple auth pairs. If --auth-key is not provided then serve s3 will allow anonymous access.

+

Alternatively --auth-proxy can be used to look up the +secret for each access key ID and choose the backend it maps to (see Auth Proxy below). When an auth proxy is in use +--auth-key is ignored and every request must be signed with +the secret the proxy returns for its access key ID.

Like all rclone flags --auth-key can be set via environment variables, in this case RCLONE_AUTH_KEY. Since this flag can be repeated, the input to RCLONE_AUTH_KEY is @@ -12024,9 +12118,9 @@ the server like this:

with a command like this:

rclone serve s3 --auth-key ACCESS_KEY_ID,SECRET_ACCESS_KEY local:/path/to/folder

The rclone.conf for the server could look like this:

-
[local]
-type = local
+
[local]
+type = local

The local configuration is optional though. If you run the server with a remote:path like /path/to/folder (without the local: prefix and @@ -12035,31 +12129,76 @@ default configuration, which will be visible as a warning in the logs. But it will run nonetheless.

This will be compatible with an rclone (client) remote configuration which is defined like this:

-
[serves3]
-type = s3
-provider = Rclone
-endpoint = http://127.0.0.1:8080/
-access_key_id = ACCESS_KEY_ID
-secret_access_key = SECRET_ACCESS_KEY
+
[serves3]
+type = s3
+provider = Rclone
+endpoint = http://127.0.0.1:8080/
+access_key_id = ACCESS_KEY_ID
+secret_access_key = SECRET_ACCESS_KEY
+

Object uploads (PUT)

+

A PutObject upload only ever changes the object at its +key atomically, on success, a failed or interrupted PUT neither removes +nor overwrites the object already stored at the key, and never leaves a +partial object visible at it.

+

Remotes that upload atomically (e.g. object stores such as +s3) are streamed straight to the destination. On remotes +where a partial upload would otherwise be visible (e.g. +local), and whenever --vfs-cache-mode is +writes or above, the upload is written to a temporary +object that is renamed into place on success; these remotes need to +support a server-side move or copy for this (nearly all do - without +move or copy the upload is written directly and a failed PUT may leave a +partial object at the key). If serve s3 is killed part-way +through an upload the temporary object (named with a leading +.rclone_temp_put_) may be left behind; it is hidden from S3 +listings but must be removed manually.

Multipart uploads

-

By default serve s3 streams each -multipart upload, in part-number order, into a single -PutStream upload to the underlying remote, so the whole -file is never buffered in memory - memory use stays bounded by the parts -in flight. The remote then performs its own internal upload (for example -its own multipart upload, still with bounded memory). This works for any -remote that supports PutStream, which is nearly all of -them, including through crypt.

-

The upload is atomic so the destination object only ever changes on a +

Multipart uploads are written, in part-number order, to a temporary +object which is renamed into place, server-side, on completion, so the +upload is atomic. The object at the key only ever changes on a successful completion. A failed or aborted upload never affects any -object already stored under that name. Remotes that upload atomically -already (object stores such as s3) are streamed straight to -the destination. On remotes where a partial upload would otherwise be -visible (such as local), the parts are streamed to a -temporary object that is moved into place, server-side, on completion; -these remotes therefore also need to support a server-side move or -copy.

+object already stored under that name and a partly-uploaded object never +becomes visible under it.

+

With the default --vfs-cache-mode off +serve s3 streams each multipart upload, in +part-number order, into a single streaming upload to the underlying +remote, so the whole file is never buffered in memory. Memory use stays +bounded by the parts in flight. The remote then performs its own +internal upload (for example its own multipart upload, still with +bounded memory). Remotes that don't support streaming uploads (those +that must know the file size before the upload starts, such as +onedrive, pcloud, jottacloud, +mailru, opendrive, putio, +protondrive and zoho) have the parts spooled +to a temporary file on local disk instead, and uploaded +with the size then known on completion, so they need local disk space +for the largest objects in flight rather than memory.

+

With --vfs-cache-mode writes (or full) the +parts are written to a temporary file in the VFS cache and uploaded by +the VFS write-back - see Multipart uploads and the +VFS cache below.

+

The rename into place needs the remote to support a server-side move +or copy, which nearly all do. It is a cheap rename on most remotes, but +on object stores without a real rename (such as s3 itself) +the move is performed as a server-side copy and delete of the whole +object, which can take time and API calls for large objects. Concurrent +multipart uploads of the same key (which S3 permits) are safe. Each +writes its own temporary object and the last to complete wins.

+

On the few remotes that support neither server side move nor copy, +the parts are written straight to the destination object instead and +never buffered in memory. This is at some cost in atomicity - the +incomplete object is visible under its final name while the upload is in +flight, as it also is for a plain object PUT on such remotes, and +concurrent multipart uploads of the same key write to the same object +and can interleave. A failed or aborted upload still leaves any +pre-existing object untouched provided the remote uploads atomically and +the VFS cache is off; on a remote where partial uploads are visible it +may leave partial data at the key (like a plain PUT there), and with +--vfs-cache-mode writes (or full) a write to +the cache cannot be abandoned, so an aborted upload's partial data is +written back to the remote as if it had completed.

Features

Limitations

+

Multipart uploads and the +VFS cache

+

With --vfs-cache-mode writes (or full) +multipart uploads do not stream to the remote at all. The parts are +written, in part-number order, to a temporary file in the VFS cache. On +completion the file is renamed into place and uploaded by the VFS +write-back, exactly like a plain object PUT. This needs no streaming +upload support from the remote. The rename normally happens in the cache +before the upload has started, but the VFS requires the remote to +support a server-side move or copy to rename files at all (and uses one +if the temporary file has already been written back, e.g. with +--vfs-write-back 0). On remotes without either, the parts +are written to the cache directly under the final key instead: the +upload still never touches memory, but it loses its atomicity - the +in-flight upload is visible at the key, and an aborted upload cannot be +abandoned once in the cache, so its partial data is written back to the +remote as if it were a completed object.

+

Remotes that benefit from --vfs-cache-mode writes:

+ +

The trade-offs of the VFS cache:

+ +

Cleaning up temporary +objects

+

If serve s3 is killed part-way through an upload it can +leave a temporary object behind, named with a leading +.rclone_temp_. This whole prefix is reserved: any object +whose name (the last /-separated segment of its key) starts +with .rclone_temp_ is hidden from S3 listings, so don't +give real objects such names - an existing object with such a name +disappears from listings (though it stays accessible directly by its +key: only listings hide reserved names, GET, +HEAD and DELETE of the exact key still work). +A temporary object never holds acknowledged data - uploads whose +temporary object survived were never confirmed to the client - so old +ones are safe to delete:

+
rclone delete --min-age 24h --include ".rclone_temp_*" remote:path
+

The --min-age protects uploads which are still in +progress: make sure it is longer than your longest upload, especially if +several serve s3 instances share the same remote.

+

rclone v1.75 named its temporary multipart objects +.rclone_multipart_upload_*; leftovers from an older server +are also hidden from listings and can be cleaned up the same way.

+

Abandoned uploads

+

A client which starts a multipart upload and vanishes without either +completing or aborting it would otherwise hold on to its resources +forever.

+

An incomplete multipart upload which has had no activity for +--multipart-expiry (default 24h) is therefore +aborted and cleaned up, exactly as if the client had called +AbortMultipartUpload, and a NOTICE is +logged.

+

An upload with a part still being received is never expired, however +slowly the part is arriving, and each completed part restarts the clock, +so the expiry only needs to outlast the client's pauses between +parts, not the whole upload.

+

Late operations on an expired upload fail with +NoSuchUpload, as they do on real S3 when a lifecycle rule +has aborted the upload. Set --multipart-expiry 0 to keep +incomplete uploads forever.

Disabling streaming

-

If you pass --disable-multipart-streaming, or the remote -doesn't support PutStream (or doesn't upload atomically and -can't move or copy server-side), multipart uploads are instead -buffered in memory by the underlying S3 library: every -part is held in memory and the whole object is written out in one go -when the upload completes (the previous behaviour). This removes the +

If you pass --disable-multipart-streaming, multipart +uploads are instead buffered in memory by the +underlying S3 library: every part is held in memory and the whole object +is written out in one go when the upload completes. This removes the in-order/contiguous-part restriction above, so parts can be uploaded in any order, but memory use grows with the size of the upload, so it is only suitable for small objects. A one-off -NOTICE is logged the first time this happens.

-

Alternatively, if the client is an rclone s3 remote -(like the [serves3] example above), you can set -use_multipart_uploads = false on it so it uploads each -object as a single stream and skips multipart uploads altogether.

+NOTICE is logged the first time this happens. This flag is +the only thing that makes multipart uploads buffer in memory - it is +never done because of missing remote capabilities. Consider +--vfs-cache-mode writes instead, which buffers the upload +in the VFS cache on disk and takes precedence over +--disable-multipart-streaming.

Bugs

Multipart server side copies do not work (see #7454). These @@ -12326,7 +12555,7 @@ that will be used to buffer data in advance.

memory at all times. The buffered data is bound to one open file and won't be shared.

This flag is a upper limit for the used memory per open file. The -buffer will only use memory for data that is downloaded but not not yet +buffer will only use memory for data that is downloaded but not yet read. If the buffer is empty, only a small amount of memory will be used.

The maximum memory used by rclone for buffering can be up to @@ -12369,11 +12598,12 @@ will start with files that haven't been accessed for the longest. This cache flushing strategy is efficient and more relevant files are likely to remain cached.

The --vfs-cache-max-age will evict files from the cache -after the set time since last access has passed. The default value of 1 -hour will start evicting files from cache that haven't been accessed for -1 hour. When a cached file is accessed the 1 hour timer is reset to 0 -and will wait for 1 more hour before evicting. Specify the time with -standard notation, s, m, h, d, w .

+after the set time since last access has passed; it is based on access +time, not on when the file was first added to the cache. The default +value of 1 hour will start evicting files from cache that haven't been +accessed for 1 hour. When a cached file is accessed the 1 hour timer is +reset to 0 and will wait for 1 more hour before evicting. Specify the +time with standard notation, s, m, h, d, w .

You should not run two copies of rclone using the same VFS cache with the same or overlapping remotes if using --vfs-cache-mode > off. This can potentially cause data @@ -12679,6 +12909,113 @@ total 1048578

If the file has no metadata it will be returned as {} and if there is an error reading the metadata the error will be returned as {"error":"error string"}.

+

Auth Proxy

+

If you supply the parameter +--auth-proxy /path/to/program then rclone will use that +program to generate backends on the fly which then are used to +authenticate incoming requests. This uses a simple JSON based protocol +with input on STDIN and output on STDOUT.

+

PLEASE NOTE: --auth-proxy and +--authorized-keys cannot be used together, if +--auth-proxy is set the authorized keys option will be +ignored.

+

There is an example program bin/test_proxy.py +in the rclone source code.

+

The program's job is to take a user and +pass on the input and turn those into the config for a +backend on STDOUT in JSON format. This config will have any default +parameters for the backend added, but it won't use configuration from +environment variables or command line options - it is the job of the +proxy program to make a complete config.

+

This config generated must have this extra parameter

+ +

And it may have these parameters

+ +

If password authentication was used by the client, input to the proxy +process (on STDIN) would look similar to this:

+
{
+  "user": "me",
+  "pass": "mypassword",
+  "client_ip": "192.168.1.1"
+}
+

If public-key authentication was used by the client, input to the +proxy process (on STDIN) would look similar to this:

+
{
+  "user": "me",
+  "public_key": "AAAAB3NzaC1yc2EAAAADAQABAAABAQDuwESFdAe14hVS6omeyX7edc...JQdf",
+  "client_ip": "192.168.1.1"
+}
+

If the client authenticated with an S3 access key +(rclone serve s3), the client never sends its secret, only +a signature made with it, so the input contains just the access key ID +as the user with no pass or +public_key:

+
{
+  "user": "AKIAIOSFODNN7EXAMPLE",
+  "client_ip": "192.168.1.1"
+}
+

In this case the program must look up the secret access key for that +access key ID and return it in the _secret_access_key field +of the output. Rclone then uses that secret to verify the signature on +the request, refusing the request if it does not match. This means the +proxy program is the source of truth for both the credentials and the +backend they map to. If the program does not return +_secret_access_key or returns it empty the request is +refused.

+

The program's answer for an access key ID is cached (see below) but +is checked with the program again after 5 minutes even if the access key +ID is in constant use, so revoking an access key ID in the program takes +effect within 5 minutes. A rotated secret takes effect on the first +request signed with it.

+

The client_ip key holds the IP address the client +connected from, without a port number. It can be used to restrict logins +to certain networks, or to log authentication attempts centrally. It is +omitted if the client has no IP address, for example when connecting +over a unix socket. Note that if rclone is behind a reverse proxy this +will be the address of the reverse proxy and not the original +client.

+

And as an example return this on STDOUT

+
{
+  "type": "sftp",
+  "_root": "",
+  "_obscure": "pass",
+  "user": "me",
+  "pass": "mypassword",
+  "host": "sftp.example.com"
+}
+

This would mean that an SFTP backend would be created on the fly for +the user and pass/public_key +returned in the output to the host given. Note that since +_obscure is set to pass, rclone will obscure +the pass parameter before creating the backend (which is +required for sftp backends).

+

The program can manipulate the supplied user in any way, +for example to make proxy to many different sftp backends, you could +make the user be user@example.com and then set +the host to example.com in the output and the +user to user. For security you'd probably want to restrict +the host to a limited list.

+

An internal cache of backends is keyed on the user, a +hash of the pass or public_key, and the +client_ip. This means that if a user's password or +public-key changes, the client connects from a new IP address, or the +proxy returns different config parameters (eg a rotated +api_key), a fresh backend will be created on the next +request rather than the cached one being reused.

+

This can be used to build general purpose proxies to any kind of +backend that rclone supports.

rclone serve s3 remote:path [flags]

Options

      --addr stringArray                              IPaddress:Port or :Port to bind server to (default 127.0.0.1:8080)
@@ -12690,7 +13027,7 @@ as {"error":"error string"}.

--client-ca string Client certificate authority to verify clients with --dir-cache-time Duration Time to cache directory entries for (default 5m0s) --dir-perms FileMode Directory permissions (default 777) - --disable-multipart-streaming Buffer multipart uploads in memory instead of streaming them to the backend (see the Multipart uploads docs section) + --disable-multipart-streaming Buffer multipart uploads in memory instead of streaming them to the backend --etag-hash string Which hash to use for the ETag, or auto or blank for off (default "MD5") --file-perms FileMode File permissions (default 666) --force-path-style If true use path style access if false use virtual hosted style (default true) @@ -12701,7 +13038,8 @@ as {"error":"error string"}.

--link-perms FileMode Link permissions (default 666) --max-header-bytes int Maximum size of request header (default 4096) --min-tls-version string Minimum TLS version that is acceptable (default "tls1.0") - --multipart-streaming-buffer-limit SizeSuffix Maximum memory buffered per streamed multipart upload for parts arriving out of order, 0 for unlimited (see the Multipart uploads docs section) (default 256Mi) + --multipart-expiry Duration Abort incomplete multipart uploads idle for longer than this, 0 to keep forever (default 1d) + --multipart-streaming-buffer-limit SizeSuffix Maximum memory buffered per streamed multipart upload for parts arriving out of order, 0 for unlimited (default 256Mi) --no-checksum Don't compare checksums on up/download --no-cleanup Not to cleanup empty folder after object is deleted --no-modtime Don't read/write the modification time (can speed things up) @@ -12876,7 +13214,7 @@ that will be used to buffer data in advance.

memory at all times. The buffered data is bound to one open file and won't be shared.

This flag is a upper limit for the used memory per open file. The -buffer will only use memory for data that is downloaded but not not yet +buffer will only use memory for data that is downloaded but not yet read. If the buffer is empty, only a small amount of memory will be used.

The maximum memory used by rclone for buffering can be up to @@ -12919,11 +13257,12 @@ will start with files that haven't been accessed for the longest. This cache flushing strategy is efficient and more relevant files are likely to remain cached.

The --vfs-cache-max-age will evict files from the cache -after the set time since last access has passed. The default value of 1 -hour will start evicting files from cache that haven't been accessed for -1 hour. When a cached file is accessed the 1 hour timer is reset to 0 -and will wait for 1 more hour before evicting. Specify the time with -standard notation, s, m, h, d, w .

+after the set time since last access has passed; it is based on access +time, not on when the file was first added to the cache. The default +value of 1 hour will start evicting files from cache that haven't been +accessed for 1 hour. When a cached file is accessed the 1 hour timer is +reset to 0 and will wait for 1 more hour before evicting. Specify the +time with standard notation, s, m, h, d, w .

You should not run two copies of rclone using the same VFS cache with the same or overlapping remotes if using --vfs-cache-mode > off. This can potentially cause data @@ -13229,7 +13568,7 @@ total 1048578

If the file has no metadata it will be returned as {} and if there is an error reading the metadata the error will be returned as {"error":"error string"}.

-

Auth Proxy

+

Auth Proxy

If you supply the parameter --auth-proxy /path/to/program then rclone will use that program to generate backends on the fly which then are used to @@ -13252,35 +13591,69 @@ proxy program to make a complete config.

-

And it may have this parameter

+

And it may have these parameters

If password authentication was used by the client, input to the proxy process (on STDIN) would look similar to this:

-
{
-  "user": "me",
-  "pass": "mypassword"
-}
+
{
+  "user": "me",
+  "pass": "mypassword",
+  "client_ip": "192.168.1.1"
+}

If public-key authentication was used by the client, input to the proxy process (on STDIN) would look similar to this:

-
{
-  "user": "me",
-  "public_key": "AAAAB3NzaC1yc2EAAAADAQABAAABAQDuwESFdAe14hVS6omeyX7edc...JQdf"
-}
+
{
+  "user": "me",
+  "public_key": "AAAAB3NzaC1yc2EAAAADAQABAAABAQDuwESFdAe14hVS6omeyX7edc...JQdf",
+  "client_ip": "192.168.1.1"
+}
+

If the client authenticated with an S3 access key +(rclone serve s3), the client never sends its secret, only +a signature made with it, so the input contains just the access key ID +as the user with no pass or +public_key:

+
{
+  "user": "AKIAIOSFODNN7EXAMPLE",
+  "client_ip": "192.168.1.1"
+}
+

In this case the program must look up the secret access key for that +access key ID and return it in the _secret_access_key field +of the output. Rclone then uses that secret to verify the signature on +the request, refusing the request if it does not match. This means the +proxy program is the source of truth for both the credentials and the +backend they map to. If the program does not return +_secret_access_key or returns it empty the request is +refused.

+

The program's answer for an access key ID is cached (see below) but +is checked with the program again after 5 minutes even if the access key +ID is in constant use, so revoking an access key ID in the program takes +effect within 5 minutes. A rotated secret takes effect on the first +request signed with it.

+

The client_ip key holds the IP address the client +connected from, without a port number. It can be used to restrict logins +to certain networks, or to log authentication attempts centrally. It is +omitted if the client has no IP address, for example when connecting +over a unix socket. Note that if rclone is behind a reverse proxy this +will be the address of the reverse proxy and not the original +client.

And as an example return this on STDOUT

-
{
-  "type": "sftp",
-  "_root": "",
-  "_obscure": "pass",
-  "user": "me",
-  "pass": "mypassword",
-  "host": "sftp.example.com"
-}
+
{
+  "type": "sftp",
+  "_root": "",
+  "_obscure": "pass",
+  "user": "me",
+  "pass": "mypassword",
+  "host": "sftp.example.com"
+}

This would mean that an SFTP backend would be created on the fly for the user and pass/public_key returned in the output to the host given. Note that since @@ -13293,12 +13666,13 @@ make the user be user@example.com and then set the host to example.com in the output and the user to user. For security you'd probably want to restrict the host to a limited list.

-

An internal cache of backends is keyed on the user and a -hash of the pass or public_key. This means -that if a user's password or public-key changes, or the proxy returns -different config parameters (eg a rotated api_key), a fresh -backend will be created on the next request rather than the cached one -being reused.

+

An internal cache of backends is keyed on the user, a +hash of the pass or public_key, and the +client_ip. This means that if a user's password or +public-key changes, the client connects from a new IP address, or the +proxy returns different config parameters (eg a rotated +api_key), a fresh backend will be created on the next +request rather than the cached one being reused.

This can be used to build general purpose proxies to any kind of backend that rclone supports.

rclone serve sftp remote:path [flags]
@@ -13720,7 +14094,7 @@ that will be used to buffer data in advance.

memory at all times. The buffered data is bound to one open file and won't be shared.

This flag is a upper limit for the used memory per open file. The -buffer will only use memory for data that is downloaded but not not yet +buffer will only use memory for data that is downloaded but not yet read. If the buffer is empty, only a small amount of memory will be used.

The maximum memory used by rclone for buffering can be up to @@ -13763,11 +14137,12 @@ will start with files that haven't been accessed for the longest. This cache flushing strategy is efficient and more relevant files are likely to remain cached.

The --vfs-cache-max-age will evict files from the cache -after the set time since last access has passed. The default value of 1 -hour will start evicting files from cache that haven't been accessed for -1 hour. When a cached file is accessed the 1 hour timer is reset to 0 -and will wait for 1 more hour before evicting. Specify the time with -standard notation, s, m, h, d, w .

+after the set time since last access has passed; it is based on access +time, not on when the file was first added to the cache. The default +value of 1 hour will start evicting files from cache that haven't been +accessed for 1 hour. When a cached file is accessed the 1 hour timer is +reset to 0 and will wait for 1 more hour before evicting. Specify the +time with standard notation, s, m, h, d, w .

You should not run two copies of rclone using the same VFS cache with the same or overlapping remotes if using --vfs-cache-mode > off. This can potentially cause data @@ -14073,7 +14448,7 @@ total 1048578

If the file has no metadata it will be returned as {} and if there is an error reading the metadata the error will be returned as {"error":"error string"}.

-

Auth Proxy

+

Auth Proxy

If you supply the parameter --auth-proxy /path/to/program then rclone will use that program to generate backends on the fly which then are used to @@ -14096,35 +14471,69 @@ proxy program to make a complete config.

-

And it may have this parameter

+

And it may have these parameters

If password authentication was used by the client, input to the proxy process (on STDIN) would look similar to this:

-
{
-  "user": "me",
-  "pass": "mypassword"
-}
+
{
+  "user": "me",
+  "pass": "mypassword",
+  "client_ip": "192.168.1.1"
+}

If public-key authentication was used by the client, input to the proxy process (on STDIN) would look similar to this:

-
{
-  "user": "me",
-  "public_key": "AAAAB3NzaC1yc2EAAAADAQABAAABAQDuwESFdAe14hVS6omeyX7edc...JQdf"
-}
+
{
+  "user": "me",
+  "public_key": "AAAAB3NzaC1yc2EAAAADAQABAAABAQDuwESFdAe14hVS6omeyX7edc...JQdf",
+  "client_ip": "192.168.1.1"
+}
+

If the client authenticated with an S3 access key +(rclone serve s3), the client never sends its secret, only +a signature made with it, so the input contains just the access key ID +as the user with no pass or +public_key:

+
{
+  "user": "AKIAIOSFODNN7EXAMPLE",
+  "client_ip": "192.168.1.1"
+}
+

In this case the program must look up the secret access key for that +access key ID and return it in the _secret_access_key field +of the output. Rclone then uses that secret to verify the signature on +the request, refusing the request if it does not match. This means the +proxy program is the source of truth for both the credentials and the +backend they map to. If the program does not return +_secret_access_key or returns it empty the request is +refused.

+

The program's answer for an access key ID is cached (see below) but +is checked with the program again after 5 minutes even if the access key +ID is in constant use, so revoking an access key ID in the program takes +effect within 5 minutes. A rotated secret takes effect on the first +request signed with it.

+

The client_ip key holds the IP address the client +connected from, without a port number. It can be used to restrict logins +to certain networks, or to log authentication attempts centrally. It is +omitted if the client has no IP address, for example when connecting +over a unix socket. Note that if rclone is behind a reverse proxy this +will be the address of the reverse proxy and not the original +client.

And as an example return this on STDOUT

-
{
-  "type": "sftp",
-  "_root": "",
-  "_obscure": "pass",
-  "user": "me",
-  "pass": "mypassword",
-  "host": "sftp.example.com"
-}
+
{
+  "type": "sftp",
+  "_root": "",
+  "_obscure": "pass",
+  "user": "me",
+  "pass": "mypassword",
+  "host": "sftp.example.com"
+}

This would mean that an SFTP backend would be created on the fly for the user and pass/public_key returned in the output to the host given. Note that since @@ -14137,12 +14546,13 @@ make the user be user@example.com and then set the host to example.com in the output and the user to user. For security you'd probably want to restrict the host to a limited list.

-

An internal cache of backends is keyed on the user and a -hash of the pass or public_key. This means -that if a user's password or public-key changes, or the proxy returns -different config parameters (eg a rotated api_key), a fresh -backend will be created on the next request rather than the cached one -being reused.

+

An internal cache of backends is keyed on the user, a +hash of the pass or public_key, and the +client_ip. This means that if a user's password or +public-key changes, the client connects from a new IP address, or the +proxy returns different config parameters (eg a rotated +api_key), a fresh backend will be created on the next +request rather than the cached one being reused.

This can be used to build general purpose proxies to any kind of backend that rclone supports.

rclone serve webdav remote:path [flags]
@@ -14837,11 +15247,11 @@ infrastructure without a proper certificate. You could supply the --no-check-certificate flag to rclone, but this will affect all the remotes. To make it just affect this remote you use an override. You could put this in the config file:

-
[remote]
-type = XXX
-...
-override.no_check_certificate = true
+
[remote]
+type = XXX
+...
+override.no_check_certificate = true

or use it in the connection string remote,override.no_check_certificate=true: (or just remote,override.no_check_certificate:).

@@ -14885,11 +15295,11 @@ as an override. For example, say you have a remote where you would always like to use the --checksum flag. You could supply the --checksum flag to rclone on every command line, but instead you could put this in the config file:

-
[remote]
-type = XXX
-...
-global.checksum = true
+
[remote]
+type = XXX
+...
+global.checksum = true

or use it in the connection string remote,global.checksum=true: (or just remote,global.checksum:). This is equivalent to using the @@ -14925,13 +15335,13 @@ shell.

Windows

If your names have spaces in you need to put them in ", e.g.

-
rclone copy "E:\folder name\folder name\folder name" remote:backup
+
rclone copy "E:\folder name\folder name\folder name" remote:backup

If you are using the root directory on its own then don't quote it (see #464 for why), e.g.

-
rclone copy E:\ remote:backup
+
rclone copy E:\ remote:backup

Copying files or directories with : in the names

rclone uses : to mark a remote name. This is, however, a @@ -15360,7 +15770,7 @@ effect at the start of the transfer.

--transfer will use this much memory for buffering.

When using mount or cmount each open file descriptor will use this much memory for buffering. See the mount +href="https://rclone.org/commands/rclone_mount/#vfs-file-buffering">mount documentation for more details.

Set to 0 to disable the buffering for the minimum memory usage.

@@ -15544,11 +15954,11 @@ value is the internal lowercase name as returned by command rclone help backends. Comments are indicated by ; or # at the beginning of a line.

Example:

-
[megaremote]
-type = mega
-user = you@example.com
-pass = PDPcQVVjVtzFY-GTdDFozqBhTdsPg3qH
+
[megaremote]
+type = mega
+user = you@example.com
+pass = PDPcQVVjVtzFY-GTdDFozqBhTdsPg3qH

Note that passwords are in obscured form. Also, many storage systems uses token-based authentication instead of @@ -16069,49 +16479,49 @@ complete log file is not strictly valid JSON and needs a parser that can handle it.

The JSON logs will be printed on a single line, but are shown expanded here for clarity.

-
{
-  "time": "2025-05-13T17:30:51.036237518+01:00",
-  "level": "debug",
-  "msg": "4 go routines active\n",
-  "source": "cmd/cmd.go:298"
-}
+
{
+  "time": "2025-05-13T17:30:51.036237518+01:00",
+  "level": "debug",
+  "msg": "4 go routines active\n",
+  "source": "cmd/cmd.go:298"
+}

Completed data transfer logs will have extra size information. Logs which are about a particular object will have object and objectType fields also.

-
{
-  "time": "2025-05-13T17:38:05.540846352+01:00",
-  "level": "info",
-  "msg": "Copied (new) to: file2.txt",
-  "size": 6,
-  "object": "file.txt",
-  "objectType": "*local.Object",
-  "source": "operations/copy.go:368"
-}
+
{
+  "time": "2025-05-13T17:38:05.540846352+01:00",
+  "level": "info",
+  "msg": "Copied (new) to: file2.txt",
+  "size": 6,
+  "object": "file.txt",
+  "objectType": "*local.Object",
+  "source": "operations/copy.go:368"
+}

Stats logs will contain a stats field which is the same as returned from the rc call core/stats.

-
{
-  "time": "2025-05-13T17:38:05.540912847+01:00",
-  "level": "info",
-  "msg": "...text version of the stats...",
-  "stats": {
-    "bytes": 6,
-    "checks": 0,
-    "deletedDirs": 0,
-    "deletes": 0,
-    "elapsedTime": 0.000904825,
-    ...truncated for clarity...
-    "totalBytes": 6,
-    "totalChecks": 0,
-    "totalTransfers": 1,
-    "transferTime": 0.000882794,
-    "transfers": 1
-  },
-  "source": "accounting/stats.go:569"
-}
+
{
+  "time": "2025-05-13T17:38:05.540912847+01:00",
+  "level": "info",
+  "msg": "...text version of the stats...",
+  "stats": {
+    "bytes": 6,
+    "checks": 0,
+    "deletedDirs": 0,
+    "deletes": 0,
+    "elapsedTime": 0.000904825,
+    ...truncated for clarity...
+    "totalBytes": 6,
+    "totalChecks": 0,
+    "totalTransfers": 1,
+    "transferTime": 0.000882794,
+    "transfers": 1
+  },
+  "source": "accounting/stats.go:569"
+}

--low-level-retries int

This controls the number of low level retries rclone does.

A low level retry is used to retry a failing operation - typically @@ -16266,63 +16676,63 @@ known.

  • Metadata is the backend specific metadata as described in the backend docs.
  • -
    {
    -  "SrcFs": "gdrive:",
    -  "SrcFsType": "drive",
    -  "DstFs": "newdrive:user",
    -  "DstFsType": "onedrive",
    -  "Remote": "test.txt",
    -  "Size": 6,
    -  "MimeType": "text/plain; charset=utf-8",
    -  "ModTime": "2022-10-11T17:53:10.286745272+01:00",
    -  "IsDir": false,
    -  "ID": "xyz",
    -  "Metadata": {
    -    "btime": "2022-10-11T16:53:11Z",
    -    "content-type": "text/plain; charset=utf-8",
    -    "mtime": "2022-10-11T17:53:10.286745272+01:00",
    -    "owner": "user1@domain1.com",
    -    "permissions": "...",
    -    "description": "my nice file",
    -    "starred": "false"
    -  }
    -}
    +
    {
    +  "SrcFs": "gdrive:",
    +  "SrcFsType": "drive",
    +  "DstFs": "newdrive:user",
    +  "DstFsType": "onedrive",
    +  "Remote": "test.txt",
    +  "Size": 6,
    +  "MimeType": "text/plain; charset=utf-8",
    +  "ModTime": "2022-10-11T17:53:10.286745272+01:00",
    +  "IsDir": false,
    +  "ID": "xyz",
    +  "Metadata": {
    +    "btime": "2022-10-11T16:53:11Z",
    +    "content-type": "text/plain; charset=utf-8",
    +    "mtime": "2022-10-11T17:53:10.286745272+01:00",
    +    "owner": "user1@domain1.com",
    +    "permissions": "...",
    +    "description": "my nice file",
    +    "starred": "false"
    +  }
    +}

    The program should then modify the input as desired and send it to STDOUT. The returned Metadata field will be used in its entirety for the destination object. Any other fields will be ignored. Note in this example we translate user names and permissions and add something to the description:

    -
    {
    -  "Metadata": {
    -    "btime": "2022-10-11T16:53:11Z",
    -    "content-type": "text/plain; charset=utf-8",
    -    "mtime": "2022-10-11T17:53:10.286745272+01:00",
    -    "owner": "user1@domain2.com",
    -    "permissions": "...",
    -    "description": "my nice file [migrated from domain1]",
    -    "starred": "false"
    -  }
    -}
    +
    {
    +  "Metadata": {
    +    "btime": "2022-10-11T16:53:11Z",
    +    "content-type": "text/plain; charset=utf-8",
    +    "mtime": "2022-10-11T17:53:10.286745272+01:00",
    +    "owner": "user1@domain2.com",
    +    "permissions": "...",
    +    "description": "my nice file [migrated from domain1]",
    +    "starred": "false"
    +  }
    +}

    Metadata can be removed here too.

    An example python program might look something like this to implement the above transformations.

    -
    import sys, json
    -
    -i = json.load(sys.stdin)
    -metadata = i["Metadata"]
    -# Add tag to description
    -if "description" in metadata:
    -    metadata["description"] += " [migrated from domain1]"
    -else:
    -    metadata["description"] = "[migrated from domain1]"
    -# Modify owner
    -if "owner" in metadata:
    -    metadata["owner"] = metadata["owner"].replace("domain1.com", "domain2.com")
    -o = { "Metadata": metadata }
    -json.dump(o, sys.stdout, indent="\t")
    +
    import sys, json
    +
    +i = json.load(sys.stdin)
    +metadata = i["Metadata"]
    +# Add tag to description
    +if "description" in metadata:
    +    metadata["description"] += " [migrated from domain1]"
    +else:
    +    metadata["description"] = "[migrated from domain1]"
    +# Modify owner
    +if "owner" in metadata:
    +    metadata["owner"] = metadata["owner"].replace("domain1.com", "domain2.com")
    +o = { "Metadata": metadata }
    +json.dump(o, sys.stdout, indent="\t")

    You can find this example (slightly expanded) in the rclone source code at bin/test_metadata_mapper.py.

    @@ -16405,7 +16815,7 @@ at maximum --transfers * --multi-thread-chunk-size * --multi-thread-streams or specifically for the s3 backend --transfers * --s3-chunk-size * ---s3-concurrency. However you can use the the --s3-concurrency
    . However you can use the --max-buffer-memory flag to control the maximum memory used here.

    NB that this only works with @@ -17137,11 +17547,11 @@ password, in which case it will be used for decrypting the configuration.

    You can set this for a session from a script. For unix like systems save this to a file called set-rclone-password:

    -
    #!/bin/echo Source this file don't run it
    -
    -read -s RCLONE_CONFIG_PASS
    -export RCLONE_CONFIG_PASS
    +
    #!/bin/echo Source this file don't run it
    +
    +read -s RCLONE_CONFIG_PASS
    +export RCLONE_CONFIG_PASS

    Then source the file when you want to use it. From the shell you would do source set-rclone-password. It will then ask you for the password and set it in the environment variable.

    @@ -17213,11 +17623,11 @@ a password store: pass init rclone.

    Windows

    Encrypt the config file (all systems)

    @@ -19006,11 +19416,11 @@ href="#option-blocks">the options blocks section for more info).

    For example, if you wished to run a sync with the --checksum parameter, you would pass this parameter in your JSON blob.

    -
    "_config":{"CheckSum": true}
    +
    "_config":{"CheckSum": true}

    Or pass it flat at the top level:

    -
    "checksum": true
    +
    "checksum": true

    If using rclone rc this could be passed as

    rclone rc sync/sync ... _config='{"CheckSum": true}'

    Or simply flat:

    @@ -19024,13 +19434,13 @@ which were set with command line flags or environment variables.

    see data types for more info. Here is an example setting the equivalent of --buffer-size in string or integer format.

    -
    "_config":{"BufferSize": "42M"}
    -"_config":{"BufferSize": 44040192}
    +
    "_config":{"BufferSize": "42M"}
    +"_config":{"BufferSize": 44040192}

    Or flat:

    -
    "buffer_size": "42M"
    -"buffer_size": 44040192
    +
    "buffer_size": "42M"
    +"buffer_size": 44040192

    If you wish to check the _config assignment has worked properly then calling options/local will show what the value got set to.

    @@ -19052,11 +19462,11 @@ href="#option-blocks">the options blocks section for more info).

    For example, if you wished to run a sync with these flags

    --max-size 1M --max-age 42s --include "a" --include "b"

    you would pass this parameter in your JSON blob.

    -
    "_filter":{"MaxSize":"1M", "IncludeRule":["a","b"], "MaxAge":"42s"}
    +
    "_filter":{"MaxSize":"1M", "IncludeRule":["a","b"], "MaxAge":"42s"}

    Or pass them flat at the top level:

    -
    "max_size":"1M", "include":["a","b"], "max_age":"42s"
    +
    "max_size":"1M", "include":["a","b"], "max_age":"42s"

    If using rclone rc this could be passed as

    rclone rc ... _filter='{"MaxSize":"1M", "IncludeRule":["a","b"], "MaxAge":"42s"}'

    Or simply flat:

    @@ -19070,12 +19480,12 @@ which were set with command line flags or environment variables.

    see data types for more info. Here is an example setting the equivalent of --buffer-size in string or integer format.

    -
    "_filter":{"MinSize": "42M"}
    -"_filter":{"MinSize": 44040192}
    +
    "_filter":{"MinSize": "42M"}
    +"_filter":{"MinSize": 44040192}

    Or flat:

    -
    "min_size": "42M"
    +
    "min_size": "42M"

    If you wish to check the _filter assignment has worked properly then calling options/local will show what the value got set to.

    @@ -19255,36 +19665,36 @@ allowed unless Required or Default is set)

    An example of this might be the --log-level flag. Note that the Name of the option becomes the command line flag with _ replaced with -.

    -
    {
    -    "Advanced": false,
    -    "Default": 5,
    -    "DefaultStr": "NOTICE",
    -    "Examples": [
    -        {
    -            "Help": "",
    -            "Value": "EMERGENCY"
    -        },
    -        {
    -            "Help": "",
    -            "Value": "ALERT"
    -        },
    -        ...
    -    ],
    -    "Exclusive": true,
    -    "FieldName": "LogLevel",
    -    "Groups": "Logging",
    -    "Help": "Log level DEBUG|INFO|NOTICE|ERROR",
    -    "Hide": 0,
    -    "IsPassword": false,
    -    "Name": "log_level",
    -    "NoPrefix": true,
    -    "Required": true,
    -    "Sensitive": false,
    -    "Type": "LogLevel",
    -    "Value": null,
    -    "ValueStr": "NOTICE"
    -},
    +
    {
    +    "Advanced": false,
    +    "Default": 5,
    +    "DefaultStr": "NOTICE",
    +    "Examples": [
    +        {
    +            "Help": "",
    +            "Value": "EMERGENCY"
    +        },
    +        {
    +            "Help": "",
    +            "Value": "ALERT"
    +        },
    +        ...
    +    ],
    +    "Exclusive": true,
    +    "FieldName": "LogLevel",
    +    "Groups": "Logging",
    +    "Help": "Log level DEBUG|INFO|NOTICE|ERROR",
    +    "Hide": 0,
    +    "IsPassword": false,
    +    "Name": "log_level",
    +    "NoPrefix": true,
    +    "Required": true,
    +    "Sensitive": false,
    +    "Type": "LogLevel",
    +    "Value": null,
    +    "ValueStr": "NOTICE"
    +},

    Note that the Help may be multiple lines separated by \n. The first line will always be a short sentence and this is the sentence shown when running rclone help flags.

    @@ -19310,25 +19720,25 @@ set. If the local backend is desired then type should be set to local. If _root isn't specified then it defaults to the root of the remote.

    For example this JSON is equivalent to remote:/tmp

    -
    {
    -    "_name": "remote",
    -    "_root": "/tmp"
    -}
    +
    {
    +    "_name": "remote",
    +    "_root": "/tmp"
    +}

    And this is equivalent to :sftp,host='example.com':/tmp

    -
    {
    -    "type": "sftp",
    -    "host": "example.com",
    -    "_root": "/tmp"
    -}
    +
    {
    +    "type": "sftp",
    +    "host": "example.com",
    +    "_root": "/tmp"
    +}

    And this is equivalent to /tmp/dir

    -
    {
    -    "type": "local",
    -    "_root": "/tmp/dir"
    -}
    +
    {
    +    "type": "local",
    +    "_root": "/tmp/dir"
    +}

    Supported commands

    backend/command: Runs a backend command.

    @@ -19928,12 +20338,12 @@ concurrently.
  • inputs - an list of inputs to the commands with an extra _path parameter
  • -
    {
    -    "_path": "rc/path",
    -    "param1": "parameter for the path as documented",
    -    "param2": "parameter for the path as documented, etc",
    -}
    +
    {
    +    "_path": "rc/path",
    +    "param1": "parameter for the path as documented",
    +    "param2": "parameter for the path as documented, etc",
    +}

    The inputs may use _async, _group, _config and _filter as normal when using the rc.

    @@ -19943,37 +20353,37 @@ rc.

    each in inputs.

    For example:

    -
    rclone rc job/batch --json '{
    -  "inputs": [
    -    {
    -      "_path": "rc/noop",
    -      "parameter": "OK"
    -    },
    -    {
    -      "_path": "rc/error",
    -      "parameter": "BAD"
    -    }
    -  ]
    -}
    -'
    +
    rclone rc job/batch --json '{
    +  "inputs": [
    +    {
    +      "_path": "rc/noop",
    +      "parameter": "OK"
    +    },
    +    {
    +      "_path": "rc/error",
    +      "parameter": "BAD"
    +    }
    +  ]
    +}
    +'

    Gives the result:

    -
    {
    -  "results": [
    -    {
    -      "parameter": "OK"
    -    },
    -    {
    -      "error": "arbitrary error on input map[parameter:BAD]",
    -      "input": {
    -        "parameter": "BAD"
    -      },
    -      "path": "rc/error",
    -      "status": 500
    -    }
    -  ]
    -}
    +
    {
    +  "results": [
    +    {
    +      "parameter": "OK"
    +    },
    +    {
    +      "error": "arbitrary error on input map[parameter:BAD]",
    +      "input": {
    +        "parameter": "BAD"
    +      },
    +      "path": "rc/error",
    +      "status": 500
    +    }
    +  ]
    +}

    job/list: Lists the IDs of the running jobs

    Parameters: None.

    Results:

    @@ -20731,25 +21141,25 @@ Useful for testing error handling.

    Eg

    rclone rc serve/list

    Returns

    -
    {
    -    "list": [
    -        {
    -            "addr": "[::]:4321",
    -            "id": "nfs-ffc2a4e5",
    -            "params": {
    -                "fs": "remote:",
    -                "opt": {
    -                    "ListenAddr": ":4321"
    -                },
    -                "type": "nfs",
    -                "vfsOpt": {
    -                    "CacheMode": "full"
    -                }
    -            }
    -        }
    -    ]
    -}
    +
    {
    +    "list": [
    +        {
    +            "addr": "[::]:4321",
    +            "id": "nfs-ffc2a4e5",
    +            "params": {
    +                "fs": "remote:",
    +                "opt": {
    +                    "ListenAddr": ":4321"
    +                },
    +                "type": "nfs",
    +                "vfsOpt": {
    +                    "CacheMode": "full"
    +                }
    +            }
    +        }
    +    ]
    +}

    serve/start: Create a new server

    Create a new server with the specified parameters.

    This takes the following parameters:

    @@ -20782,11 +21192,11 @@ above.

    rclone rc serve/start --json '{"type":"nfs","fs":"remote:","addr":":1234","vfs_cache_mode":"full"}' rclone rc serve/start type=webdav fs=remote: vfsOpt='{"CacheMode": 2}' proxyOpt='{"AuthProxy": "http://127.0.0.1:8080"}'

    This will give the reply

    -
    {
    -    "addr": "[::]:4321", // Address the server was started on
    -    "id": "nfs-ecfc6852" // Unique identifier for the server instance
    -}
    +
    {
    +    "addr": "[::]:4321", // Address the server was started on
    +    "id": "nfs-ecfc6852" // Unique identifier for the server instance
    +}

    Or an error if it failed to start.

    Stop the server with serve/stop and list the running servers with serve/list.

    @@ -20815,14 +21225,14 @@ be passed to serve/start as the serveType parameter.

    Eg

    rclone rc serve/types

    Returns

    -
    {
    -    "types": [
    -        "http",
    -        "sftp",
    -        "nfs"
    -    ]
    -}
    +
    {
    +    "types": [
    +        "http",
    +        "sftp",
    +        "nfs"
    +    ]
    +}

    sync/bisync: Perform bidirectional synchronization between two paths.

    @@ -21119,16 +21529,16 @@ formatted to be reasonably human-readable.

    If an error occurs then there will be an HTTP error status (e.g. 500) and the body of the response will contain a JSON encoded error object, e.g.

    -
    {
    -    "error": "Expecting string value for key \"remote\" (was float64)",
    -    "input": {
    -        "fs": "/tmp",
    -        "remote": 3
    -    },
    -    "status": 400,
    -    "path": "operations/rmdir"
    -}
    +
    {
    +    "error": "Expecting string value for key \"remote\" (was float64)",
    +    "input": {
    +        "fs": "/tmp",
    +        "remote": 3
    +    },
    +    "status": 400,
    +    "path": "operations/rmdir"
    +}

    The keys in the error response are:

  • TestPcloud (pcloud)
  • -
  • Updated: 2026-07-31-010017 +
  • Updated: 2026-09-04-010006
  • The following backends either have not been tested recently or have @@ -25640,19 +26052,19 @@ versions I manually run the following command:

  • The Dropbox client then syncs the changes with Dropbox.
  • rclone.conf snippet

    -
    [Dropbox]
    -type = dropbox
    -...
    -
    -[Dropcrypt]
    -type = crypt
    -remote = /path/to/DBoxroot/crypt          # on the Linux server
    -remote = C:\Users\MyLogin\Dropbox\crypt   # on the Windows notebook
    -filename_encryption = standard
    -directory_name_encryption = true
    -password = ...
    -...
    +
    [Dropbox]
    +type = dropbox
    +...
    +
    +[Dropcrypt]
    +type = crypt
    +remote = /path/to/DBoxroot/crypt          # on the Linux server
    +remote = C:\Users\MyLogin\Dropbox\crypt   # on the Windows notebook
    +filename_encryption = standard
    +directory_name_encryption = true
    +password = ...
    +...

    Testing

    You should read this section only if you are developing for rclone. You need to have rclone source code locally to work with bisync @@ -26045,7 +26457,8 @@ changes

    uncertainty, essentially marking the file as needing to be rechecked next time.

  • A few basic terminal colors are now supported, controllable with ---color +--color (AUTO|NEVER|ALWAYS)

  • Initial listing snapshots of Path1 and Path2 are now generated concurrently, using the same "march" infrastructure as @@ -26090,7 +26503,8 @@ allows more control over which version of a file gets kept during a --resync.

  • Bisync now supports --retries -and --retries-sleep +and --retries-sleep (when --resilient is set.)

  • @@ -27345,24 +27759,24 @@ An external ID is provided for additional security as required by the role's trust policy

    The target role's trust policy in the destination account must allow the source account or user to assume it. Example trust policy:

    -
    {
    -  "Version": "2012-10-17",
    -  "Statement": [
    -    {
    -      "Effect": "Allow",
    -      "Principal": {
    -        "AWS": "arn:aws:iam::SOURCE-ACCOUNT-ID:root"
    -      },
    -      "Action": "sts:AssumeRole",
    -      "Condition": {
    -        "StringEquals": {
    -          "sts:ExternalID": "unique-role-external-id-12345"
    -        }
    -      }
    -    }
    -  ]
    -}
    +
    {
    +  "Version": "2012-10-17",
    +  "Statement": [
    +    {
    +      "Effect": "Allow",
    +      "Principal": {
    +        "AWS": "arn:aws:iam::SOURCE-ACCOUNT-ID:root"
    +      },
    +      "Action": "sts:AssumeRole",
    +      "Condition": {
    +        "StringEquals": {
    +          "sts:ExternalID": "unique-role-external-id-12345"
    +        }
    +      }
    +    }
    +  ]
    +}

    S3 Permissions

    When using the sync subcommand of rclone the following minimum permissions are required to be available on the @@ -27379,34 +27793,34 @@ href="#s3-no-check-bucket">s3-no-check-bucket)

    When using the lsd subcommand, the ListAllMyBuckets permission is required.

    Example policy:

    -
    {
    -  "Version": "2012-10-17",
    -  "Statement": [
    -    {
    -      "Effect": "Allow",
    -      "Principal": {
    -        "AWS": "arn:aws:iam::USER_SID:user/USER_NAME"
    -      },
    -      "Action": [
    -        "s3:ListBucket",
    -        "s3:DeleteObject",
    -        "s3:GetObject",
    -        "s3:PutObject",
    -        "s3:PutObjectAcl"
    -      ],
    -      "Resource": [
    -        "arn:aws:s3:::BUCKET_NAME/*",
    -        "arn:aws:s3:::BUCKET_NAME"
    -      ]
    -    },
    -    {
    -      "Effect": "Allow",
    -      "Action": "s3:ListAllMyBuckets",
    -      "Resource": "arn:aws:s3:::*"
    -    }
    -  ]
    -}
    +
    {
    +  "Version": "2012-10-17",
    +  "Statement": [
    +    {
    +      "Effect": "Allow",
    +      "Principal": {
    +        "AWS": "arn:aws:iam::USER_SID:user/USER_NAME"
    +      },
    +      "Action": [
    +        "s3:ListBucket",
    +        "s3:DeleteObject",
    +        "s3:GetObject",
    +        "s3:PutObject",
    +        "s3:PutObjectAcl"
    +      ],
    +      "Resource": [
    +        "arn:aws:s3:::BUCKET_NAME/*",
    +        "arn:aws:s3:::BUCKET_NAME"
    +      ]
    +    },
    +    {
    +      "Effect": "Allow",
    +      "Action": "s3:ListAllMyBuckets",
    +      "Resource": "arn:aws:s3:::*"
    +    }
    +  ]
    +}

    Notes on above:

    1. This is a policy that can be used when creating bucket. It assumes @@ -29668,59 +30082,74 @@ tenant name. Do not select this directly
    2. Fortaleza, CE (BR), br-ne1
    3. Provider: Magalu
    4. -
    5. "s3.eu-amsterdam.megas4.com" +
    6. "s3.eu-luxembourg-1.megas4.com"
    7. -
    8. "s3.eu-luxembourg.megas4.com" +
    9. "s3.eu-luxembourg-2.megas4.com"
    10. -
    11. "s3.eu-paris.megas4.com" +
    12. "s3.eu-amsterdam-1.megas4.com"
    13. -
    14. "s3.eu-barcelona.megas4.com" +
    15. "s3.eu-amsterdam-2.megas4.com"
    16. -
    17. "s3.ca-montreal.megas4.com" +
    18. "s3.eu-paris-1.megas4.com"
    19. -
    20. "s3.ca-vancouver.megas4.com" +
    21. "s3.eu-paris-2.megas4.com"
    22. -
    23. "s3.ap-tokyo.megas4.com" +
    24. "s3.eu-barcelona-1.megas4.com"
    25. -
    26. "s3.eu-central-1.s4.mega.io" +
    27. "s3.eu-barcelona-2.megas4.com"
    28. -
    29. "s3.eu-central-2.s4.mega.io" +
    30. "s3.ca-montreal-1.megas4.com"
    31. -
    32. "s3.ca-central-1.s4.mega.io" +
    33. "s3.ca-montreal-2.megas4.com"
    34. -
    35. "s3.ca-west-1.s4.mega.io" +
    36. "s3.ca-vancouver-1.megas4.com"
    37. +
    38. "s3.ca-vancouver-2.megas4.com" +
    39. +
    40. "s3.ap-tokyo-1.megas4.com" +
    41. +
    42. "s3.ap-tokyo-2.megas4.com" +
    43. "oos.eu-west-2.outscale.com" @@ -32484,17 +32913,17 @@ rclone backend restore s3:bucket/path/to/directory -o priority=PRIORITYIt returns a list of status dictionaries with Remote and Status keys. The Status will be OK if it was successful or an error message if not.

      -
      [
      -    {
      -        "Status": "OK",
      -        "Remote": "test.txt"
      -    },
      -    {
      -        "Status": "OK",
      -        "Remote": "test/file4.txt"
      -    }
      -]
      +
      [
      +    {
      +        "Status": "OK",
      +        "Remote": "test.txt"
      +    },
      +    {
      +        "Status": "OK",
      +        "Remote": "test/file4.txt"
      +    }
      +]

      Options:

    1) Create a bucket.
    @@ -34377,15 +34806,15 @@ s) Set configuration password
     q) Quit config
     e/n/d/r/c/s/q> 

    This will leave the config file looking like this.

    -
    [my-impossible-cloud]
    -type = s3
    -provider = ImpossibleCloud
    -access_key_id = ACCESS_KEY
    -secret_access_key = SECRET_KEY
    -region = eu-central-2
    -endpoint = eu-central-2.storage.impossibleapi.net
    -acl = private
    +
    [my-impossible-cloud]
    +type = s3
    +provider = ImpossibleCloud
    +access_key_id = ACCESS_KEY
    +secret_access_key = SECRET_KEY
    +region = eu-central-2
    +endpoint = eu-central-2.storage.impossibleapi.net
    +acl = private

    Intercolo Object Storage

    Intercolo Object Storage offers GDPR-compliant, transparently priced, S3-compatible @@ -34496,14 +34925,14 @@ e) Edit this remote d) Delete this remote y/e/d> y

    This will leave the config file looking like this.

    -
    [intercolo]
    -type = s3
    -provider = Intercolo
    -access_key_id = ACCESS_KEY
    -secret_access_key = SECRET_KEY
    -region = de-fra
    -endpoint = de-fra.i3storage.com
    +
    [intercolo]
    +type = s3
    +provider = Intercolo
    +access_key_id = ACCESS_KEY
    +secret_access_key = SECRET_KEY
    +region = de-fra
    +endpoint = de-fra.i3storage.com

    IONOS Cloud

    IONOS S3 Object Storage is a service offered by IONOS for storing and @@ -34811,19 +35240,19 @@ e) Edit this remote d) Delete this remote y/e/d> y

    This will leave the config file looking like this.

    -
    [Liara]
    -type = s3
    -provider = Liara
    -env_auth = false
    -access_key_id = YOURACCESSKEY
    -secret_access_key = YOURSECRETACCESSKEY
    -region =
    -endpoint = storage.iran.liara.space
    -location_constraint =
    -acl =
    -server_side_encryption =
    -storage_class =
    +
    [Liara]
    +type = s3
    +provider = Liara
    +env_auth = false
    +access_key_id = YOURACCESSKEY
    +secret_access_key = YOURSECRETACCESSKEY
    +region =
    +endpoint = storage.iran.liara.space
    +location_constraint =
    +acl =
    +server_side_encryption =
    +storage_class =

    Linode

    Here is an example of making a Linode Object @@ -34963,13 +35392,13 @@ e) Edit this remote d) Delete this remote y/e/d> y

    This will leave the config file looking like this.

    -
    [linode]
    -type = s3
    -provider = Linode
    -access_key_id = ACCESS_KEY
    -secret_access_key = SECRET_ACCESS_KEY
    -endpoint = eu-central-1.linodeobjects.com
    +
    [linode]
    +type = s3
    +provider = Linode
    +access_key_id = ACCESS_KEY
    +secret_access_key = SECRET_ACCESS_KEY
    +endpoint = eu-central-1.linodeobjects.com

    Magalu

    Here is an example of making a Magalu Object Storage @@ -35071,13 +35500,13 @@ e) Edit this remote d) Delete this remote y/e/d> y

    This will leave the config file looking like this.

    -
    [magalu]
    -type = s3
    -provider = Magalu
    -access_key_id = ACCESS_KEY
    -secret_access_key = SECRET_ACCESS_KEY
    -endpoint = br-ne1.magaluobjects.com
    +
    [magalu]
    +type = s3
    +provider = Magalu
    +access_key_id = ACCESS_KEY
    +secret_access_key = SECRET_ACCESS_KEY
    +endpoint = br-ne1.magaluobjects.com

    MEGA S4

    MEGA S4 Object Storage is an S3 compatible object storage system. It has a single pricing tier @@ -35170,13 +35599,13 @@ e) Edit this remote d) Delete this remote y/e/d> y

    This will leave the config file looking like this.

    -
    [megas4]
    -type = s3
    -provider = Mega
    -access_key_id = XXX
    -secret_access_key = XXX
    -endpoint = s3.eu-central-1.s4.mega.io
    +
    [megas4]
    +type = s3
    +provider = Mega
    +access_key_id = XXX
    +secret_access_key = XXX
    +endpoint = s3.eu-central-1.s4.mega.io

    Minio

    Minio is an object storage server built for cloud application developers and devops.

    @@ -35215,17 +35644,17 @@ endpoint> http://192.168.1.106:9000 location_constraint> server_side_encryption>

    Which makes the config file look like this

    -
    [minio]
    -type = s3
    -provider = Minio
    -env_auth = false
    -access_key_id = USWUXHGYZQYFYFFIT3RE
    -secret_access_key = MOJRH0mkL1IPauahWITSVvyDrQbEEIwljvmxdq03
    -region = us-east-1
    -endpoint = http://192.168.1.106:9000
    -location_constraint =
    -server_side_encryption =
    +
    [minio]
    +type = s3
    +provider = Minio
    +env_auth = false
    +access_key_id = USWUXHGYZQYFYFFIT3RE
    +secret_access_key = MOJRH0mkL1IPauahWITSVvyDrQbEEIwljvmxdq03
    +region = us-east-1
    +endpoint = http://192.168.1.106:9000
    +location_constraint =
    +server_side_encryption =

    So once set up, for example, to copy files into a bucket

    rclone copy /path/to/files minio:bucket

    Netease NOS

    @@ -35243,16 +35672,16 @@ href="https://docs.outscale.com/en/userguide/OUTSCALE-Object-Storage-OOS.html">o documentation.

    Here is an example of an OOS configuration that you can paste into your rclone configuration file:

    -
    [outscale]
    -type = s3
    -provider = Outscale
    -env_auth = false
    -access_key_id = ABCDEFGHIJ0123456789
    -secret_access_key = XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
    -region = eu-west-2
    -endpoint = oos.eu-west-2.outscale.com
    -acl = private
    +
    [outscale]
    +type = s3
    +provider = Outscale
    +env_auth = false
    +access_key_id = ABCDEFGHIJ0123456789
    +secret_access_key = XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
    +region = eu-west-2
    +endpoint = oos.eu-west-2.outscale.com
    +acl = private

    You can also run rclone config to go through the interactive setup process:

    No remotes found, make a new one\?
    @@ -35546,15 +35975,15 @@ e) Edit this remote
     d) Delete this remote
     y/e/d> y

    Your configuration file should now look like this:

    -
    [ovhcloud-rbx]
    -type = s3
    -provider = OVHcloud
    -access_key_id = my_access
    -secret_access_key = my_secret
    -region = rbx
    -endpoint = s3.rbx.io.cloud.ovh.net
    -acl = private
    +
    [ovhcloud-rbx]
    +type = s3
    +provider = OVHcloud
    +access_key_id = my_access
    +secret_access_key = my_secret
    +region = rbx
    +endpoint = s3.rbx.io.cloud.ovh.net
    +acl = private

    Petabox

    Here is an example of making a Petabox configuration. First run:

    @@ -35695,14 +36124,14 @@ e) Edit this remote d) Delete this remote y/e/d> y

    This will leave the config file looking like this.

    -
    [My Petabox Storage]
    -type = s3
    -provider = Petabox
    -access_key_id = YOUR_ACCESS_KEY_ID
    -secret_access_key = YOUR_SECRET_ACCESS_KEY
    -region = us-east-1
    -endpoint = s3.petabox.io
    +
    [My Petabox Storage]
    +type = s3
    +provider = Petabox
    +access_key_id = YOUR_ACCESS_KEY_ID
    +secret_access_key = YOUR_SECRET_ACCESS_KEY
    +region = us-east-1
    +endpoint = s3.petabox.io

    Pure Storage FlashBlade

    Pure @@ -35797,13 +36226,13 @@ d) Delete this remote y/e/d> y

    This results in the following configuration being stored in ~/.config/rclone/rclone.conf:

    -
    [flashblade]
    -type = s3
    -provider = FlashBlade
    -access_key_id = ACCESS_KEY_ID
    -secret_access_key = SECRET_ACCESS_KEY
    -endpoint = https://s3.flashblade.example.com
    +
    [flashblade]
    +type = s3
    +provider = FlashBlade
    +access_key_id = ACCESS_KEY_ID
    +secret_access_key = SECRET_ACCESS_KEY
    +endpoint = https://s3.flashblade.example.com

    Note: The FlashBlade endpoint should be the S3 data VIP. For virtual-hosted style requests, ensure proper DNS configuration: subdomains of the endpoint hostname should resolve to a FlashBlade data @@ -36080,13 +36509,13 @@ e) Edit this remote d) Delete this remote y/e/d> y

    This will leave the config file looking like this.

    -
    [s5lu]
    -type = s3
    -provider = FileLu
    -access_key_id = XXX
    -secret_access_key = XXX
    -endpoint = s5lu.com
    +
    [s5lu]
    +type = s3
    +provider = FileLu
    +access_key_id = XXX
    +secret_access_key = XXX
    +endpoint = s5lu.com

    Rabata

    Rabata is an S3-compatible secure cloud storage service that offers flat, transparent pricing (no API @@ -36223,16 +36652,16 @@ details are required for the next steps of configuration, when rclone config asks for your access_key_id and secret_access_key.

    Your config should end up looking a bit like this:

    -
    [RCS3-demo-config]
    -type = s3
    -provider = RackCorp
    -env_auth = true
    -access_key_id = YOURACCESSKEY
    -secret_access_key = YOURSECRETACCESSKEY
    -region = au-nsw
    -endpoint = s3.rackcorp.com
    -location_constraint = au-nsw
    +
    [RCS3-demo-config]
    +type = s3
    +provider = RackCorp
    +env_auth = true
    +access_key_id = YOURACCESSKEY
    +secret_access_key = YOURSECRETACCESSKEY
    +region = au-nsw
    +endpoint = s3.rackcorp.com
    +location_constraint = au-nsw

    Rclone Serve S3

    Rclone can serve any remote over the S3 protocol. For details see the rclone serve @@ -36242,14 +36671,14 @@ server like this:

    rclone serve s3 --auth-key ACCESS_KEY_ID,SECRET_ACCESS_KEY remote:path

    This will be compatible with an rclone remote which is defined like this:

    -
    [serves3]
    -type = s3
    -provider = Rclone
    -endpoint = http://127.0.0.1:8080/
    -access_key_id = ACCESS_KEY_ID
    -secret_access_key = SECRET_ACCESS_KEY
    -use_multipart_uploads = false
    +
    [serves3]
    +type = s3
    +provider = Rclone
    +endpoint = http://127.0.0.1:8080/
    +access_key_id = ACCESS_KEY_ID
    +secret_access_key = SECRET_ACCESS_KEY
    +use_multipart_uploads = false

    Note that setting use_multipart_uploads = false is to work around a bug which @@ -36262,20 +36691,20 @@ Scaleway console or transferred through our API and CLI or using any S3-compatible tool.

    Scaleway provides an S3 interface which can be configured for use with rclone like this:

    -
    [scaleway]
    -type = s3
    -provider = Scaleway
    -env_auth = false
    -endpoint = s3.nl-ams.scw.cloud
    -access_key_id = SCWXXXXXXXXXXXXXX
    -secret_access_key = 1111111-2222-3333-44444-55555555555555
    -region = nl-ams
    -location_constraint = nl-ams
    -acl = private
    -upload_cutoff = 5M
    -chunk_size = 5M
    -copy_cutoff = 5M
    +
    [scaleway]
    +type = s3
    +provider = Scaleway
    +env_auth = false
    +endpoint = s3.nl-ams.scw.cloud
    +access_key_id = SCWXXXXXXXXXXXXXX
    +secret_access_key = 1111111-2222-3333-44444-55555555555555
    +region = nl-ams
    +location_constraint = nl-ams
    +acl = private
    +upload_cutoff = 5M
    +chunk_size = 5M
    +copy_cutoff = 5M

    Scaleway Glacier is the low-cost S3 Glacier alternative from Scaleway and it works the same way as on S3 by accepting the "GLACIER" @@ -36390,13 +36819,13 @@ e) Edit this remote d) Delete this remote y/e/d> y

    This will leave the config file looking like this.

    -
    [scality]
    -type = s3
    -provider = Scality
    -access_key_id = S3_ACCESS_KEY
    -secret_access_key = S3_SECRET_KEY
    -endpoint = https://s3.example.com
    +
    [scality]
    +type = s3
    +provider = Scality
    +access_key_id = S3_ACCESS_KEY
    +secret_access_key = S3_SECRET_KEY
    +endpoint = https://s3.example.com

    Seagate Lyve Cloud

    Seagate @@ -36489,13 +36918,13 @@ Press Enter to leave empty. [snip] acl>

    And the config file should end up looking like this:

    -
    [remote]
    -type = s3
    -provider = LyveCloud
    -access_key_id = XXX
    -secret_access_key = YYY
    -endpoint = s3.us-east-1.lyvecloud.seagate.com
    +
    [remote]
    +type = s3
    +provider = LyveCloud
    +access_key_id = XXX
    +secret_access_key = YYY
    +endpoint = s3.us-east-1.lyvecloud.seagate.com

    SeaweedFS

    SeaweedFS is a distributed storage system for blobs, objects, files, and data lake, @@ -36531,13 +36960,13 @@ such:

    }

    To use rclone with SeaweedFS, above configuration should end up with something like this in your config:

    -
    [seaweedfs_s3]
    -type = s3
    -provider = SeaweedFS
    -access_key_id = any
    -secret_access_key = any
    -endpoint = localhost:8333
    +
    [seaweedfs_s3]
    +type = s3
    +provider = SeaweedFS
    +access_key_id = any
    +secret_access_key = any
    +endpoint = localhost:8333

    So once set up, for example to copy files into a bucket

    rclone copy /path/to/files seaweedfs_s3:foo

    Selectel

    @@ -36640,14 +37069,14 @@ e) Edit this remote d) Delete this remote y/e/d> y

    And your config should end up looking like this:

    -
    [selectel]
    -type = s3
    -provider = Selectel
    -access_key_id = ACCESS_KEY
    -secret_access_key = SECRET_ACCESS_KEY
    -region = ru-1
    -endpoint = s3.ru-1.storage.selcloud.ru
    +
    [selectel]
    +type = s3
    +provider = Selectel
    +access_key_id = ACCESS_KEY
    +secret_access_key = SECRET_ACCESS_KEY
    +region = ru-1
    +endpoint = s3.ru-1.storage.selcloud.ru

    Servercore

    Servercore Object Storage is an S3 compatible object storage system that @@ -36840,13 +37269,13 @@ e) Edit this remote d) Delete this remote y/e/d> y

    And your config should end up looking like this:

    -
    [spectratest]
    -type = s3
    -provider = SpectraLogic
    -access_key_id = ACCESS_KEY
    -secret_access_key = SECRET_ACCESS_KEY
    -endpoint = https://bp.example.com
    +
    [spectratest]
    +type = s3
    +provider = SpectraLogic
    +access_key_id = ACCESS_KEY
    +secret_access_key = SECRET_ACCESS_KEY
    +endpoint = https://bp.example.com

    Storj

    Storj is a decentralized cloud storage which can be used through its native protocol or an S3 compatible gateway.

    @@ -37395,19 +37824,19 @@ e) Edit this remote d) Delete this remote y/e/d> y

    This will leave the config file looking like this.

    -
    [wasabi]
    -type = s3
    -provider = Wasabi
    -env_auth = false
    -access_key_id = YOURACCESSKEY
    -secret_access_key = YOURSECRETACCESSKEY
    -region =
    -endpoint = s3.wasabisys.com
    -location_constraint =
    -acl =
    -server_side_encryption =
    -storage_class =
    +
    [wasabi]
    +type = s3
    +provider = Wasabi
    +env_auth = false
    +access_key_id = YOURACCESSKEY
    +secret_access_key = YOURSECRETACCESSKEY
    +region =
    +endpoint = s3.wasabisys.com
    +location_constraint =
    +acl =
    +server_side_encryption =
    +storage_class =

    Zadara Object Storage

    Zadara Object Storage is a fully-managed, enterprise-grade, S3-compatible storage solution that @@ -37507,13 +37936,13 @@ e) Edit this remote d) Delete this remote y/e/d> y

    This will leave the config file looking like this.

    -
    [Zadara-Object-Storage]
    -type = s3
    -provider = Zadara
    -access_key_id = S3_ACCESS_KEY
    -secret_access_key = S3_SECRET_KEY
    -endpoint = https://vsa-00000001-public-zadara-cloud-01.zadarazios.com
    +
    [Zadara-Object-Storage]
    +type = s3
    +provider = Zadara
    +access_key_id = S3_ACCESS_KEY
    +secret_access_key = S3_SECRET_KEY
    +endpoint = https://vsa-00000001-public-zadara-cloud-01.zadarazios.com

    Zata Object Storage

    Zata Object Storage provides a secure, S3-compatible cloud storage solution designed for scalability and @@ -37649,14 +38078,14 @@ e) Edit this remote d) Delete this remote y/e/d>

    This will leave the config file looking like this.

    -
    [my zata storage]
    -type = s3
    -provider = Zata
    -access_key_id = xxx
    -secret_access_key = xxx
    -region = us-east-1
    -endpoint = idr01.zata.ai
    +
    [my zata storage]
    +type = s3
    +provider = Zata
    +access_key_id = xxx
    +secret_access_key = xxx
    +region = us-east-1
    +endpoint = idr01.zata.ai

    Zero Services (ZERO-Z3)

    Zero Services GmbH offers ZERO-Z3, S3-compatible object storage hosted in the EU on its own @@ -38693,15 +39122,15 @@ bucket.

    To show the current lifecycle rules:

    rclone backend lifecycle b2:bucket

    This will dump something like this showing the lifecycle rules.

    -
    [
    -    {
    -        "daysFromHidingToDeleting": 1,
    -        "daysFromUploadingToHiding": null,
    -        "daysFromStartingToCancelingUnfinishedLargeFiles": null,
    -        "fileNamePrefix": ""
    -    }
    -]
    +
    [
    +    {
    +        "daysFromHidingToDeleting": 1,
    +        "daysFromUploadingToHiding": null,
    +        "daysFromStartingToCancelingUnfinishedLargeFiles": null,
    +        "fileNamePrefix": ""
    +    }
    +]

    If there are no lifecycle rules (the default) then it will just return [].

    To reset the current lifecycle rules:

    @@ -41620,6 +42049,14 @@ on the cloud storage system.

  • filenames with the same name will encrypt the same
  • filenames which start the same won't have a common prefix
  • +

    A version string of the form -vYYYY-MM-DD-HHMMSS-NNN on +the end of a file name (as added by --b2-versions / +--s3-versions) is left in plain text so that versioned +files can be found. Directory names are encrypted in full. Rclone before +v1.76 left such a suffix in plain text on directory names too, so a +directory named like this created by an older rclone will appear in +listings with a warning but can't be opened or removed until renamed on +the underlying remote to the name given in the warning.

    This uses a 32 byte key (256 bits) and a 16 byte (128 bits) IV both of which are derived from the user password.

    After encryption they are written out using a modified version of @@ -41921,18 +42358,18 @@ the shared drives you have access to.

    drive: you would run

    rclone backend -o config drives drive:

    This would produce something like this:

    -
    [My Drive]
    -type = alias
    -remote = drive,team_drive=0ABCDEF-01234567890,root_folder_id=:
    -
    -[Test Drive]
    -type = alias
    -remote = drive,team_drive=0ABCDEFabcdefghijkl,root_folder_id=:
    -
    -[AllDrives]
    -type = combine
    -upstreams = "My Drive=My Drive:" "Test Drive=Test Drive:"
    +
    [My Drive]
    +type = alias
    +remote = drive,team_drive=0ABCDEF-01234567890,root_folder_id=:
    +
    +[Test Drive]
    +type = alias
    +remote = drive,team_drive=0ABCDEFabcdefghijkl,root_folder_id=:
    +
    +[AllDrives]
    +type = combine
    +upstreams = "My Drive=My Drive:" "Test Drive=Test Drive:"

    If you then add that config to your config file (find it with rclone config file) then you can access all the shared drives in one place with the AllDrives: remote.

    @@ -47184,34 +47621,34 @@ account.

    Usage example:

    rclone backend [-o config] drives drive:

    This will return a JSON list of objects like this:

    -
    [
    -    {
    -        "id": "0ABCDEF-01234567890",
    -        "kind": "drive#teamDrive",
    -        "name": "My Drive"
    -    },
    -    {
    -        "id": "0ABCDEFabcdefghijkl",
    -        "kind": "drive#teamDrive",
    -        "name": "Test Drive"
    -    }
    -]
    +
    [
    +    {
    +        "id": "0ABCDEF-01234567890",
    +        "kind": "drive#teamDrive",
    +        "name": "My Drive"
    +    },
    +    {
    +        "id": "0ABCDEFabcdefghijkl",
    +        "kind": "drive#teamDrive",
    +        "name": "Test Drive"
    +    }
    +]

    With the -o config parameter it will output the list in a format suitable for adding to a config file to make aliases for all the drives found and a combined drive.

    -
    [My Drive]
    -type = alias
    -remote = drive,team_drive=0ABCDEF-01234567890,root_folder_id=:
    -
    -[Test Drive]
    -type = alias
    -remote = drive,team_drive=0ABCDEFabcdefghijkl,root_folder_id=:
    -
    -[AllDrives]
    -type = combine
    -upstreams = "My Drive=My Drive:" "Test Drive=Test Drive:"
    +
    [My Drive]
    +type = alias
    +remote = drive,team_drive=0ABCDEF-01234567890,root_folder_id=:
    +
    +[Test Drive]
    +type = alias
    +remote = drive,team_drive=0ABCDEFabcdefghijkl,root_folder_id=:
    +
    +[AllDrives]
    +type = combine
    +upstreams = "My Drive=My Drive:" "Test Drive=Test Drive:"

    Adding this to the rclone config file will cause those team drives to be accessible with the aliases shown. Any illegal characters will be substituted with "_" and duplicate names will have numbers suffixed. It @@ -47230,11 +47667,11 @@ use via the API.

    Use the --interactive/-i or --dry-run flag to see what would be restored before restoring it.

    Result:

    -
    {
    -    "Untrashed": 17,
    -    "Errors": 0
    -}
    +
    {
    +    "Untrashed": 17,
    +    "Errors": 0
    +}

    copyid

    Copy files by ID.

    rclone backend copyid remote: [options] [<arguments>+]
    @@ -47290,32 +47727,32 @@ escaped with  characters. "'" becomes "'" and "" becomes "\", for example to match a file named "foo ' .txt":

    rclone backend query drive: "name = 'foo \' \\\.txt'"

    The result is a JSON array of matches, for example:

    -
    [
    -    {
    -        "createdTime": "2017-06-29T19:58:28.537Z",
    -        "id": "0AxBe_CDEF4zkGHI4d0FjYko2QkD",
    -        "md5Checksum": "68518d16be0c6fbfab918be61d658032",
    -        "mimeType": "text/plain",
    -        "modifiedTime": "2024-02-02T10:40:02.874Z",
    -        "name": "foo ' \\.txt",
    -        "parents": [
    -            "0BxAe_BCDE4zkFGZpcWJGek0xbzC"
    -        ],
    -        "resourceKey": "0-ABCDEFGHIXJQpIGqBJq3MC",
    -        "sha1Checksum": "8f284fa768bfb4e45d076a579ab3905ab6bfa893",
    -        "size": "311",
    -        "webViewLink": "https://drive.google.com/file/d/0AxBe_CDEF4zkGHI4d0FjYko2QkD/view?usp=drivesdk\u0026resourcekey=0-ABCDEFGHIXJQpIGqBJq3MC"
    -    }
    -]
    -```console
    -
    -### rescue
    -
    -Rescue or delete any orphaned files.
    -
    -```console
    -rclone backend rescue remote: [options] [<arguments>+]
    +
    [
    +    {
    +        "createdTime": "2017-06-29T19:58:28.537Z",
    +        "id": "0AxBe_CDEF4zkGHI4d0FjYko2QkD",
    +        "md5Checksum": "68518d16be0c6fbfab918be61d658032",
    +        "mimeType": "text/plain",
    +        "modifiedTime": "2024-02-02T10:40:02.874Z",
    +        "name": "foo ' \\.txt",
    +        "parents": [
    +            "0BxAe_BCDE4zkFGZpcWJGek0xbzC"
    +        ],
    +        "resourceKey": "0-ABCDEFGHIXJQpIGqBJq3MC",
    +        "sha1Checksum": "8f284fa768bfb4e45d076a579ab3905ab6bfa893",
    +        "size": "311",
    +        "webViewLink": "https://drive.google.com/file/d/0AxBe_CDEF4zkGHI4d0FjYko2QkD/view?usp=drivesdk\u0026resourcekey=0-ABCDEFGHIXJQpIGqBJq3MC"
    +    }
    +]
    +```console
    +
    +### rescue
    +
    +Rescue or delete any orphaned files.
    +
    +```console
    +rclone backend rescue remote: [options] [<arguments>+]

    This command rescues or deletes any orphaned files or directories.

    Sometimes files can get orphaned in Google Drive. This means that @@ -47441,7 +47878,7 @@ remove scopes" and select the three above and press update or go to the press add to table then update.

    You should now see the three scopes on your Data access page. Now press save at the bottom!

    -
  • After adding scopes, click Audience Scroll down and click "+ Add +

  • After adding scopes, click Audience. Scroll down and click "+ Add users". Add yourself as a test user and press save.

  • Go to Overview on the left panel, click "Create OAuth client". Choose an application type of "Desktop app" and click "Create". (the @@ -48130,18 +48567,18 @@ y/e/d> y config file, usually YOURHOME/.config/rclone/rclone.conf. Open it in your favorite text editor, find section for the base remote and create new section for hasher like in the following examples:

    -
    [Hasher1]
    -type = hasher
    -remote = myRemote:path
    -hashes = md5
    -max_age = off
    -
    -[Hasher2]
    -type = hasher
    -remote = /local/path
    -hashes = dropbox,sha1
    -max_age = 24h
    +
    [Hasher1]
    +type = hasher
    +remote = myRemote:path
    +hashes = md5
    +max_age = off
    +
    +[Hasher2]
    +type = hasher
    +remote = /local/path
    +hashes = dropbox,sha1
    +max_age = 24h

    Hasher takes basically the following parameters: