Skip to content

Grants

Shares and requests as owned resources.

Responses collected by a request

Auth: ApiKey, Session

Parameters

Name In Required Notes
id path yes

Responses

Status Meaning
200 The grants this request has collected.
401 Refused, with a named reason.

GET /api/links/{id}/archive

Download a share's files as its recipient gets them

Auth: ApiKey, Session

The owner's copy of the share's archive: the same zip the public archive serves, stamped when the share is watermarked. It claims no view. Only files the caller may read go in.

Parameters

Name In Required Notes
id path yes

Responses

Status Meaning
200 The archive, as an attachment named after the share.
401 Refused, with a named reason.
404 link_not_found when the caller cannot see the share; archive_empty when no file could go in.
429 Too many attempts. Password gates, probes and challenges are limited per client, so a slug cannot be brute-forced.

POST /api/requests/callback-test

Send a sample delivery to a callback URL

Auth: Session

POSTs one example payload to url from this server, through the same client a real delivery uses — so the result reflects what the server can actually reach, and the SSRF policy applies exactly as it does at save time.

The sample carries test: true on top of the usual fields, so a receiving workflow can branch on it. Pass requestId to send the real request's id and slug (and its id in X-Revoked-Request); omit it to test a URL before the request is saved.

A target that is refused, unreachable, or answers an error is reported in the body with ok: false — the call itself still returns 200.

Request body

application/json

Field Type Notes
url string
requestId string

Responses

Status Meaning
200 What the target answered.
401 Refused, with a named reason.
403 Refused, with a named reason.
429 Refused, with a named reason.

Response fields

Field Type Notes
ok boolean
status integer 0 when nothing was reached.
code string (ok | blocked | unreachable | status) blocked — refused by the callback policy (loopback, private range, bad scheme). unreachable — no connection, DNS failure or timeout. status — the hook answered 4xx/5xx.
detail string