Docs

Documentation

ShareShield's public API lets scripts, CI pipelines and other tools create, reveal and manage self-destructing secrets and files, with the same plan limits and organisation policies as the web app.

Base URL
https://app.shareshield.net/api/v2
Auth
x-api-key header
Current version
v2

Start here

  1. IntegrationsCreate a scoped API key, call the v2 API with the x-api-key header, and use it from CI.Getting started
  2. Browser extensionWhy the 3.x key handoff was removed in 4.0, what happens to existing installs, and the move to OAuth sign-in.Security
  3. API v2 referenceEvery endpoint, schema, scope and error code, in the app next to the API it describes.In the app
  4. OpenAPI 3.1 specThe same API as a machine-readable OpenAPI 3.1 description, served by the app.In the app

Your first call

Create a key under Dashboard → Profile → API keys and send it in the x-api-key header. GET /api/v2/me tells you who the key belongs to.

Terminalbash
export SHARESHIELD_URL=https://app.shareshield.net
export SHARESHIELD_API_KEY=shs_…

curl -sS "$SHARESHIELD_URL/api/v2/me" -H "x-api-key: $SHARESHIELD_API_KEY"

Keys, scopes and errors

What the API offers

  • Secrets and files

    Create one-time links with an expiry, a view limit and an optional passcode; reveal, download, check or burn them; and list the ones you created.

  • Email recipients

    Send the link straight to people's inboxes and, if you want, require them to prove their address before the secret opens.

  • Secret requests

    Ask someone to send you a secret, and list your open requests.

  • Account and limits

    Read who a key belongs to and which plan and policy limits apply.

Every call runs against one organisation, under that organisation's policies, and counts against its plan. API keys are scoped, so a CI job can be given exactly the permissions it needs and nothing else.

API versions

v2/api/v2/*
The public API, and the one to build on. Every response carries X-API-Version: 2.
v1Deprecated
API-key calls to it get Deprecation and Sunset headers, and its removal is planned 60 days after the 4.0 release. If you still call v1, the API reference is the migration guide.