Team folders are basically S3 buckets that you can add to your FontBase account. An S3 bucket is a file storage on a remote server, that can be accessed via API (code) or a public URL (link). Many popular websites and services use S3 compatible buckets to store lots of different information. For our purposes we don't need a public bucket, because we don't need to expose your font files publicly. But we will need API access to your bucket to provide access to font files across your team.
The biggest benefit of team folders is that the files are stored online, not on the team member's computer, so they are secure and you can stay compliant. Please note: we do recommend to look into each particular font license to make sure you are allowed to share it with your team and use it on multiple computers.
It is possible to add any S3 compatible bucket as a team folder to your account. The most popular hosted solutions are: Amazon S3, Cloudflare R2, Backblaze B2, Wasabi, Hetzner, DigitalOcean Spaces. And also self-hosted: MinIO, Ceph, Garage, SeaweedFS and many other.
Adding a team folder
To create a team folder, navigate the to Folders section of your FontBase account at web.fontba.se/account/folders. Click the Add button to start the process.
To add a folder, you will need your credentials from any compatible S3 service. If you don't have it set up yet, here are some short guides on how to create a S3 bucket across some mainstream services:
Amazon S3
1. Create an AWS account. Go to aws.amazon.com and click Create an AWS Account. Enter your email and an account name, then confirm the code AWS sends to your email and set a password. Next, fill in your contact details and add a payment card. Verify your phone number and choose the free Basic support plan. Once you're done, sign in to the AWS Console.
2. Create a bucket. Type S3 in the console search bar and open it, then click Create bucket. Pick a region near your users, for example eu-central-1, and write it down. Enter a bucket name that's unique across all of AWS, using lowercase letters, numbers and hyphens, for example my-files-2026. Keep the other defaults, including Block all public access, and click Create bucket.
3. Create an IAM user. Don't create keys for the root user. Instead, search for IAM, open Users and click Create user. Give it a name, for example s3-access, and leave console access unchecked. On the permissions step, choose Attach policies directly and select AmazonS3FullAccess, then click Create user. That policy covers every bucket in the account, so if you want access limited to one bucket, use a custom policy instead.
4. Create API keys. Open the user you just made, go to the Security credentials tab and click Create access key. Choose Application running outside AWS (or Third-party service), confirm, and click Create access key.
5. Save your credentials. Copy the Access key ID and the Secret access key, or download the .csv file, and store them somewhere safe. The secret key is shown only once. If you lose it, you'll have to create a new access key.
Cloudflare R2
1. Create a Cloudflare account. Go to dash.cloudflare.com/sign-up, enter your email and a password, and click Sign up. Confirm your address by clicking the link in the verification email. You don't need to add a website or domain, so skip that step if you're asked.
2. Enable R2. In the dashboard sidebar, open Storage & Databases and then R2 Object Storage. The first time you do this, Cloudflare asks you to add a payment method and accept the R2 terms. R2 has a free tier of 10 GB of storage per month, and you're only charged if you go over it.
3. Create a bucket. On the R2 overview page, click Create bucket and enter a name using lowercase letters, numbers and hyphens, for example my-files. Keep the default location and storage class, then click Create bucket.
4. Create API keys. Go back to the R2 overview page and click Manage API tokens, then Create API token (an Account API token is fine). Give it a name and set Permissions to Object Read. Under Specify bucket(s), choose Apply to specific buckets only and pick your bucket. Leave TTL set to Forever and click Create API Token.
5. Save your credentials. Copy the Access Key ID, the Secret Access Key and the S3 endpoint (which looks like https://<account_id>.r2.cloudflarestorage.com) and store them somewhere safe. The secret key is shown only once. If you lose it, you'll have to create a new token.
We really recommend using Cloudflare, because they have a free tier that allows to store up to 10Gb of files with over a million writes and reads per month. That should be enough for most font collections, even a very large ones.
When creating your API details, make sure to only allow read-only access. FontBase does not need write access you your bucket, and we will never ask for it. We only need read access to generate temporary links to the font files, and we don't upload any information. You will need to upload your font files to your bucket on your own.
Also make sure your bucket is not available publicly. FontBase does not require it and we strongly recommend agains it, as your fonts in public buckets can be available to anyone online if they get the URL correctly.
After you have your S3 bucket ready, you will need to get the following information: bucket name, bucket region, endpoint url, access key id and access key secret. You can enter these details in the folder creation window. Once you click Save, the bucket connection will be tested and if everything is correct, the folder will be added and displayed in the folders list.
When adding a new folder, make sure it uses a unique name that is not already in use by another folder. Also make sure to add each bucket only once, as we don't support adding the same bucket multiple times.
Managing group access
After you have added a team folder, it will appear in the list of your folders. To manage the access, click the Manage button on the folder menu. A window will appear with two sections: Available groups and Folder groups. The available groups contain all the member groups that you have created on the Team page. The folder groups contain all the groups that currently have access to the selected folder.
You can click on any group from the Available list, and it will be moved to the Folder groups section. If you click on it again, it will be moved back. Once you are done, click Save and the changes will be applied immediately across your team.
Removing a team folder
To remove a team folder, simply click the Remove button on the folder menu. The folder will be removed immediately from your team, and all team members will lose access to it. Please note: sometimes it can take up to 48 hours for the font files to be completely removed from all team members.
Team folders inside FontBase app
When any team folders are added, the members that have access to them, will see a new section Team inside the FontBase window sidebar. Each folder in that section works similarly to our Providers: the font files can be browsed freely, but they are not stored on the computer but rather just accessed over the internet using a temporary link to your S3 bucket. Only when a font is activated, it is downloaded locally and made available to the user.
If the team member is logged out, the Team section and all team fonts are completely removed and they will not be able to see or activate them in any way. In order to see and browse the fonts a constant internet conenction is required.
If the team member is removed from a group that had access to the folder, or the group containing the team member is removed from the folder, the team member will lose access to all fonts and they will be completely removed from the app.