Share Links
A share link gives someone a temporary, encrypted view of specific secret values, whether or not they have an Envshed account. Use it to hand a contractor an API key, send a teammate a database URL, or pass a set of credentials to a vendor without pasting them into chat or email.
A share link is a snapshot: it captures the values at the moment it is created. Later changes to the secrets do not affect the link, and revoking the link does not touch the secrets.
Creating a link
Dashboard. Open a secret's action menu and choose Create share link, or select several secrets and use Share link in the bulk action bar. This works on the project secrets panel, the cross-environment view, and the environment pivot (/{org}/_env/{env}).
CLI.
envshed share DATABASE_URL --expires 1h --burn
See envshed share for the full option reference.
Creating a link requires read access to the secrets, the same permission needed to export them. The team value is shared; personal overrides are not.
Options
| Option | What it does | Default |
|---|---|---|
| Expires in | The link stops working after this time, opened or not. Presets from 15 minutes to 30 days. | 24 hours |
| One-time link (burn after read) | The link self-destructs after the first successful open. | on (dashboard) |
| Maximum views | Alternative to one-time: allow up to N opens before the link is used up. | unlimited until expiry |
| Password | The recipient must enter a password to open the link. Share it through a different channel. | none |
| Note | Free text shown to the recipient and in your share links list. | none |
Only secrets with a real value are included. Placeholders, disabled secrets, and values that cannot be decrypted are skipped and reported back when the link is created.
What the recipient sees
The link opens a public page (/s/{id}) that shows who shared the secrets, from which organization, how many there are, and when the link expires. Nothing is revealed until the recipient clicks Reveal secrets (and enters the password, if any), so link previews and scanners never consume a one-time link.
After revealing, each value can be shown, hidden, and copied individually, or the whole set can be copied or downloaded as a .env file. Recipients without a browser can run:
envshed share open "https://app.envshed.com/s/<id>#<key>"
How links are protected
- The URL looks like
https://app.envshed.com/s/<id>#<key>. The<key>is 32 random bytes that live only in the URL fragment, which browsers never send to the server during navigation, so it stays out of access logs and referrers. - Envshed stores only a hash of the key. The payload is encrypted with AES-256-GCM using a key derived from the URL key and the optional password. The database alone cannot decrypt a share, and Envshed cannot reconstruct a lost link.
- A wrong password fails decryption and is counted; after 10 wrong attempts the link locks itself and its payload is wiped. The open endpoint is also rate limited per IP.
- One-time and max-view links are consumed atomically, so two people opening a one-time link at the same instant cannot both succeed.
- When a link is revoked, used up, locked, or expired, its encrypted payload is wiped. The row stays so the list and audit trail keep their history.
Managing links
Organization settings › Share links lists links with their status (active, expired, used up, revoked), view counts, expiry, and creator. Owners and admins see every link in the organization; other members see the links they created.
A link can be revoked at any time by its creator or an organization owner/admin. Revocation is immediate and cannot be undone.
Audit trail
Every share link event is recorded in the organization's audit log:
| Action | When |
|---|---|
share_link.create | A link is created (keys, projects, environments, expiry, options; never values) |
share_link.open | A recipient reveals the secrets (view count, whether the link burned) |
share_link.revoke | A link is revoked |
share_link.locked | A link locked itself after too many wrong passwords |
REST API
The CLI is built on these endpoints; personal API tokens can use them directly.
| Method | Path | Auth | Purpose |
|---|---|---|---|
POST | /api/v1/share-links/{org} | Bearer (user token) | Create a link for keys in projectSlug/envSlug (omit keys for all) |
GET | /api/v1/share-links/{org} | Bearer (user token) | List links visible to the caller |
DELETE | /api/v1/share-links/{org}/{id} | Bearer (user token) | Revoke a link |
GET | /api/v1/shared/{id} | none | Public status and metadata of a link |
POST | /api/v1/shared/{id} | none | Open a link: body { "key": "...", "password": "..." } |
Service tokens cannot create share links.