Pinata documents uploads and gateway retrieval; Filebase documents a distinct IPFS storage tier; Lighthouse documents IPFS and Filecoin storage with encryption options. Compare the complete upload, retention and retrieval workflow. A content identifier is not a service-level promise that someone will retain and serve the file forever.


Choose an operational service, not just a storage network
Token metadata often needs a stable reference, but the application also needs dependable retrieval, correct content types and a way to update its own records. The asset owner's expectations can be much longer than the engineering team's subscription cycle.
This article compares managed upload and retrieval services. Our Arweave, Filecoin and Storj comparison concerns a different network-level choice. Do not assume that selecting a network settles the gateway, retention and account-exit decisions.
Comparison table: managed service starting points
| Decision | Pinata | Filebase | Lighthouse |
|---|---|---|---|
| Evidence reviewed | Public upload and gateway quickstart | IPFS tier overview | IPFS/Filecoin introduction |
| Integration starting point | Upload API and SDK | IPFS buckets and pinning interfaces | Storage SDKs and retrieval workflows |
| First pilot | Upload and retrieve the CID | Confirm tier and retrieve a pinned file | Upload, retrieve and inspect access model |
| Contract check | Retention and gateway terms | IPFS-specific storage and bandwidth | Active-plan storage and access terms |
The table summarizes selected documentation, not a feature-exclusion chart or uptime ranking. Unknown contractual details remain not verified. The three providers are a purposeful service cohort, not an exhaustive market survey.
Pinata
Pinata's quickstart documents obtaining an API key, uploading a public file and retrieving content using its CID through a gateway. It warns that the JWT is secret and should be handled in a secure environment.
Buyer interpretation: test public upload and retrieval without exposing server credentials in a browser. Confirm account permissions, file lifecycle and the gateway arrangement required by your production application. The public-upload example is not evidence of private-document suitability.
Filebase
Filebase's IPFS tier overview documents IPFS-backed buckets, pinning interfaces, IPNS names and dedicated gateways. It explicitly separates this tier from general S3-compatible storage, including different endpoints.
Buyer interpretation: ensure the selected integration actually produces the CIDs your application needs. Obtain the IPFS-specific bandwidth and retention terms rather than borrowing assumptions from the general object-storage tier.
Lighthouse
Lighthouse's IPFS/Filecoin introduction describes decentralized storage, dedicated gateways and encryption/access-control features. The current page states that data remains stored while the plan is active.
Buyer interpretation: do not describe the arrangement as unconditional permanent storage. Review renewal, account closure, key management and recovery for the chosen product. Encryption and access controls need implementation-level examination, not just a feature label.
A retrieval and exit pilot
Upload a small image and metadata file, record the returned identifier and retrieve both through the intended production route. Check whether the application receives the expected bytes and content type. Try an unknown identifier and an unavailable gateway; provide an honest unavailable state instead of displaying unrelated metadata.
Document which components point to a CID and which point to a provider-specific domain. A fixed CID may preserve content identity while a changed gateway still requires application updates. Test how the team would move its approved files to a second arrangement before cancelling anything.
For confidential material, use a separate threat model. Ask who holds encryption keys, which metadata is public and what revocation actually prevents. A removal action in one dashboard should not be treated as proof that no other copy exists.
Procurement checklist
- Who retains the file, and for how long under the contract?
- Which gateway, access restrictions and traffic limits apply?
- How do we export our file inventory and original content?
- Which actions change content, references or access rights?
- What happens on missed renewal or account closure?
- Who owns recovery and incident support?
No independently tested durability, performance or confidentiality guarantee is claimed. Combine this brief with application secrets management, and email contact@fluidrwa.com for a direct enquiry.
Verification and scope
Last checked: October 10, 2026. Reviewed by FluidRWA Research Team. Product statements are company evidence; the pilot and checklist are editorial recommendations, not an independent storage audit.
FAQ
Does an IPFS CID guarantee permanent storage?
No. Content addressing identifies data; retention and retrieval depend on the storage and serving arrangements. Verify both before making permanence claims.
Is Filebase object storage identical to its IPFS tier?
No. Its current documentation separates general S3-compatible storage from IPFS-backed buckets and lists different endpoints. Select the tier your application actually requires.
Should identity documents be publicly pinned?
Do not treat public content-addressed storage as a private document vault. Assess confidentiality, encryption, key management, deletion requirements and access controls before uploading sensitive information.
Define the storage requirement
Share your file types, access model and retention requirements. Or email contact@fluidrwa.com.