Getting started
Introduction
Share private text with one-time retrieval. Encrypt locally, send a link, and let the recipient reveal it once.
How it works#
Your app encrypts text before sending it to Xasha. The service stores the encrypted envelope and returns a reference. The encryption key stays with the sender, then travels in the share link’s URL fragment.
When the recipient chooses Reveal, Xasha returns the envelope and consumes the secret in one operation. Your app decrypts it locally.
Start here#
Follow the quickstart for a complete integration, or jump to the API reference.
| Quickstart | Create, share, reveal, and delete. |
| Encryption | A complete Web Crypto helper. |
| Errors and limits | Response codes and safe failure handling. |
Base URL#
https://api.xasha.siteNo account, API key, or SDK is required. Secret routes accept public browser requests without cookies. Use HTTPS and credentials: 'omit'.
Privacy by default#
Keep secret text, keys, complete links, and deletion tokens out of logs, analytics, and browser storage. Never send plaintext or encryption keys to the API.
Anyone with a complete share link can retrieve the secret. Browser encryption does not prevent a service that supplies the browser code from changing that code.