Getting started
Sharing links
Keep the read link and the private delete link separate. Each grants a different capability.
Share link#
https://xasha.site/s/{id}#{key}The recipient needs the entire link. The fragment contains the encryption key. Never put it in a query string or API body.
Private delete link#
https://xasha.site/delete/{id}#{deleteToken}Save this privately. The token authorizes deletion but cannot decrypt the secret. It is returned once and cannot be recovered.
Build links in your app#
const shareLink = new URL(`/s/${id}`, 'https://xasha.site')
shareLink.hash = keyFragment
const privateDeleteLink = new URL(`/delete/${id}`, 'https://xasha.site')
privateDeleteLink.hash = deleteToken
// Show links privately with separate copy buttons. Do not log them.Opening a link#
Validate the path and fragment locally, then wait for an explicit Reveal or Delete confirmation.