shortn
Docs/Accounts

Accounts

Signing in is optional. It buys a larger daily allowance, a longer life for your links, and the ability to change or delete them afterwards. It does not gate the service, and there is nothing on this site you cannot do without it.

Applies to shortn v1.2.0 · identify scope · nothing is stored but an id and a name

What signing in changes

Signed outSigned in
Links a day350
How long a link lives7 days7 days, up to 30 if it is yours
Change a link's expiryNoYes, up to 30 days
Delete a link earlyNoYes
Cost, features, rate limits——

Nothing else is different. The site is not slower signed in, does not show you more, and does not require it for anything.

A link made before you sign in belongs to nobody

This is the part worth being careful about, because it is irreversible.

A link created while you are signed out has no owner recorded on it, and signing in later does not claim it. It keeps the seven-day life it was given, it works exactly as it would have, and it expires on schedule. What it will never gain is the ability to be edited or deleted: there is no account on it to match against, and by then there never will be one.

So the order matters. If you want a link you can change later, sign in before you make it. If you already have one and want the same treatment, the answer is to make it again — which costs one of your three.

Why it is not claimed on sign-in Claiming anonymous links on sign-in would mean attaching them from whatever the browser happened to have stored, which is a way for one person to end up owning a slug they did not create and another to lose one they did. Not claiming is the only version of this that cannot go wrong.

Changing a link you own

The links page lists what this browser has made. For each one you own, there is a control for its expiry and a button to remove it. Both act on the server through /api/manage:

PATCH  /api/manage   {"slug":"launch","expiresInDays":14}
DELETE /api/manage   {"slug":"launch"}

The expiry may be set to any whole number of days between 1 and 30. It is measured from now rather than from when the link was made, so moving it from 7 to 30 gives you 30 more days, not 23.

Removing a link deletes the slug and its click counter together, immediately. Anyone holding that address gets the not found page from that moment, and the name is free for somebody else to claim.

Both endpoints answer 401 when you are signed out and 403 when the link is not yours. There is no third answer: shortn never tells you a link exists if you are not allowed to touch it.

What is actually stored

Three things, and only when you sign in:

That is the whole list. There is no email address, because Discord does not give one to an application asking only for identify, and this site does not ask for more than that. There is no session table: signing in produces a token signed with a key that never leaves the server, and every request is checked by verifying that signature locally.

Signing out clears the cookie. Because the token is self-contained, nothing is left behind to expire.

Things worth asking

No. This site has one identity provider and that is it. Adding a second would mean storing a second kind of credential for the same single question, which is the wrong trade.

Will you email me?

No. There is no email address to email, and no mailing list. Announcements go to the Discord server, which is also optional.

Does signing in work on a preview deployment?

Yes. The redirect back is built from whatever host the request arrived on, so a preview build sends you back to the preview rather than to production partway through. Discord has to have the origin registered, which is a setting on the application rather than on this site.

What stops somebody else editing my links?

The owner recorded on the link is compared with the id in your token, and the check is the only thing standing between them and it. An anonymous link has no owner at all, which is why it can be edited by nobody — including you.