Vercel Blob Storage
In short: A file storage service from Vercel (similar to AWS S3) for uploading and serving files such as images or downloads, connected directly to the Vercel project.
In more detail: A store is either public (anyone with the URL can see the file — suitable for product images) or private (access only via signed URLs/a dedicated checking route — suitable for confidential attachments). A project can have several stores at the same time.
Our context: Two separate stores at Emzett — a public one for product images/banners, a private one for chat and ticket attachments as well as software downloads (which are only delivered after the purchase has been checked).
In Depth
Why not simply public/?
A central advantage over “just putting files into the Next.js project’s public/ directory”: files in the public/ folder are part of the deployment itself — every new product image upload would require a complete new deploy, and over time the folder would grow arbitrarily large in the Git repo, needlessly bloating clone times and deployment size. Blob storage, by contrast, is a standalone storage service into which files can be uploaded directly from the browser at runtime, without any redeploy:
import { put } from "@vercel/blob";
const blob = await put("product-image.jpg", file, {
access: "public",
});
// blob.url -> directly usable public URLDirect client upload instead of a detour via the server
An often overlooked detail: Vercel Blob supports client-side uploads directly from the browser to the blob store, WITHOUT the file first having to pass entirely through your own server. This bypasses two practical limits: the typically limited request body size of serverless functions, and unnecessary server load from merely “passing through” large files. For this, your own server first generates a short-lived, signed upload URL, which the browser then uses directly — your own server never sees the file itself, only the confirmation that the upload succeeded.
Public vs. private in detail
With private stores, access protection doesn’t come from the URL itself (it’s deliberately unguessable, but technically still just “security through obscurity”); instead it has to go through a dedicated route checked on the server — e.g. an API route that first verifies that a user actually bought the product in question and only then returns a short-lived, signed download URL. These signed URLs are only valid for a limited time (typically minutes to a few hours) — even if a URL is passed on by mistake, it automatically loses its validity after expiry, without anyone having to intervene manually.
Compared with classic object storage services
Conceptually, Vercel Blob Storage is a simplified object store, similar to AWS S3 or Cloudflare R2 — all three store files as unstructured “objects” under a unique key/path instead of in a classic file system with real directory structures. The difference lies mainly in the depth of integration: Vercel Blob is embedded directly into the Vercel platform (no separate cloud account setup needed, billed directly through the same Vercel account), while S3, as a standalone AWS service, requires more configuration effort but also offers a larger range of functions (e.g. fine-grained IAM permissions).