Skip to content
xashadocs
Tab to a result · Enter to open · Esc to close

Getting started

Sharing links

Keep the read link and the private delete link separate. Each grants a different capability.

text
https://xasha.site/s/{id}#{key}

The recipient needs the entire link. The fragment contains the encryption key. Never put it in a query string or API body.

text
https://xasha.site/delete/{id}#{deleteToken}

Save this privately. The token authorizes deletion but cannot decrypt the secret. It is returned once and cannot be recovered.

Build links in your app#

javascript
const shareLink = new URL(`/s/${id}`, 'https://xasha.site')
shareLink.hash = keyFragment

const privateDeleteLink = new URL(`/delete/${id}`, 'https://xasha.site')
privateDeleteLink.hash = deleteToken

// Show links privately with separate copy buttons. Do not log them.

Opening a link#

Validate the path and fragment locally, then wait for an explicit Reveal or Delete confirmation.