Links in detail
The four things a link can carry, and the rules on each: a slug, a title, a note and a password. One of them is optional in every case.
Slugs
A generated slug is seven characters drawn from abcdefghijkmnopqrstuvwxyz23456789. Lowercase only, no lookalike characters, nothing that reads ambiguously when written down or read aloud.
A custom slug has to be 3 to 32 characters of a-z, 0-9, _ and -, and must start with a letter or a digit. Anything else is rejected before storage is touched, with the reason given.
Lookups try the lowercase form first and then the raw form, so a slug created before lowercase-only was enforced still resolves. This is a courtesy to links that already existed; new custom slugs are lowercased on the way in.
Reserved slugs
Some slugs cannot be claimed because the site needs them for its own pages. The list is fixed and mirrored between the API and the slug checker, so the two can never disagree about what is available.
Asking for one returns slug reserved rather than slug taken. That difference is deliberate: someone has this and nobody can ever have this need different answers, and a caller retrying on one should not retry on the other.
Titles and notes
A link can carry a short title and a longer note. Both are optional, both are plain text, both are stripped of markup, and both exist so a link is findable later in the table and on the reveal page.
Neither is shown to whoever opens the link. The note is only ever visible to someone looking the link up, which makes it a private label rather than a description.
Passwords
A link can be created with a password of 4 to 64 characters. When it has one, the redirect is replaced by a gate: a server-rendered page asking for the word.
What that means in practice:
- The gate is served with status
200, not a redirect. Nothing about the destination appears in the response, so the gate cannot be read past. - The destination is not recorded, counted or revealed until the password has been accepted.
- The password itself is never stored. What is stored is a SHA-256 digest, in the link's metadata.
- Getting it right sets a cookie named
snk_plus the slug, holding the same digest, withHttpOnly,SameSite=Lax,Secureand a lifetime matching the link's. A forged cookie fails and you get the gate again. - Twelve attempts a minute per address. Beyond that you get
429and a minute to wait.
How long a link lasts
Seven days, counted from creation. Not from first use, not from last use.
You can create a link with a shorter life than seven days if you want it gone sooner. You cannot create one with a longer life and you cannot extend one afterwards. There is no renewal endpoint, and that is on purpose: a service that keeps links forever needs a way to be told to delete them, and this one has one endpoint for removal instead.
An expired slug is claimable again, and asking for it deletes the old record so the name is genuinely free rather than merely unreachable. You can see that distinction on the slug checker.