← artishare

Docs

There is a web UI at /app — publish, keep your artifacts in one place, copy an edit token out, share or revoke access. Sign in with Google.

Publish a self-contained HTML or Markdown page, get an unguessable link, share it. No account. Push updated content under the same key and it becomes a new version at the same URL.

Publish something

One request. content is the body of your page — no <html> or <head> needed.

curl -X POST https://artifact.optimasolutions.io/api/artifacts \
  -H 'content-type: application/json' \
  -d '{
    "title": "Q3 Revenue",
    "favicon": "📊",
    "content": "<h1>Revenue</h1><p>Up 12% on the quarter.</p>"
  }'

You get back the share link and your one-and-only edit token:

{
  "id": "bg7m3gvh836jmats",
  "url": "https://artifact.optimasolutions.io/a/bg7m3gvh836jmats",
  "version": 1,
  "edit_token": "kQ8x..."
}
Save the edit token now. It is shown once and never again. Without it the artifact can still be viewed by anyone with the link, but it can never be updated or deleted.

You can mint more tokens later — one per person or tool — and revoke them one at a time. See letting someone else edit.

Send "kind": "markdown" to write Markdown instead of HTML.

Publish an update

Same key, same link — the content becomes version 2. Whoever already has your link sees the new version on refresh.

curl -X PUT https://artifact.optimasolutions.io/api/artifacts/$ID \
  -H "authorization: Bearer $EDIT_TOKEN" \
  -H 'content-type: application/json' \
  -d '{"label": "fixed the chart", "content": "<h1>Revenue</h1><p>Up 14%.</p>"}'

Older versions stay reachable forever at their own pinned URLs (/a/$ID/v/1/), so a link you shared to a specific version keeps showing what you shared. title, description and favicon are only changed when you include them.

Changed your mind? Point the key back at an earlier version:

curl -X POST https://artifact.optimasolutions.io/api/artifacts/$ID/rollback \
  -H "authorization: Bearer $EDIT_TOKEN" \
  -H 'content-type: application/json' \
  -d '{"version": 1}'

Let someone else edit it

Mint them their own token instead of handing over yours. Same full rights, but you can take it back without breaking your own copy — or the one you pasted into an editor or an agent.

curl -X POST https://artifact.optimasolutions.io/api/artifacts/$ID/tokens \
  -H "authorization: Bearer $EDIT_TOKEN" \
  -H 'content-type: application/json' \
  -d '{"label": "teammate@example.com"}'

The new token comes back once, like the first one. To take it back, revoke it by the id from that response:

curl -X DELETE https://artifact.optimasolutions.io/api/artifacts/$ID/tokens/$TOKEN_ID \
  -H "authorization: Bearer $EDIT_TOKEN"

GET /api/artifacts/$ID/tokens lists who holds what — labels and dates, never the tokens themselves — and marks which one you are using. It needs a token, because labels name people and a link holder is not an editor. The last remaining token can’t be revoked; that would leave an artifact nobody can ever edit, so delete the artifact instead.

Publish with images and CSS

Send it as multipart. The filename becomes the path inside your artifact, so relative references like <img src="assets/logo.png"> resolve.

curl -X POST https://artifact.optimasolutions.io/api/artifacts \
  -F 'title=Bundle' \
  -F 'entry=@index.html' \
  -F 'asset=@style.css' \
  -F 'asset=@logo.png;filename=assets/logo.png'

Paths are sanitised: no ../, no absolute paths, no dotfiles, at most 8 levels deep. A leading v/ is rejected because it collides with version URLs.

What happens to your HTML

You sendYou get
A fragment (<h1>...)Wrapped in a page skeleton: CSS reset, light/dark theming with a toggle, your emoji favicon, prose styles for tables and code
A full document (<!doctype html>)Served byte-for-byte. Nothing injected
MarkdownRendered (tables, diagrams, footnotes, task lists, smart quotes) then wrapped

Diagrams and tables in Markdown

A mermaid fence is rendered as a diagram, by mermaid 11.16.1 served from this origin — nothing is fetched from a CDN, and it is only loaded by pages that actually contain a diagram.

curl -X POST https://artifact.optimasolutions.io/api/artifacts \
  -H 'content-type: application/json' \
  -d '{"title": "Flow", "kind": "markdown", "content": "```mermaid\nflowchart LR\n  A[Upload] --> B[Link]\n```"}'

That publishes this:

flowchart LR
  A[Upload] --> B(Unguessable link)
  B --> C{Share it}
  C -->|open| D[Rendered page]
  C -->|push v2| A

Diagrams follow the page theme and are re-drawn when a reader flips it. If the renderer can’t load, the diagram source stays visible as a code block. In hand-written HTML the same thing works with <pre class="mermaid">...</pre> — but only in a fragment, since a full document is served untouched.

Markdown tables get a scroll container, so a wide one scrolls inside itself instead of pushing the page sideways.

Every endpoint

MethodPathNeedsDoes
POST/api/artifacts—Publish; returns the edit token
GET/api/artifacts/{id}linkMetadata and version history
PUT/api/artifacts/{id}tokenNew version under the same key
DEL/api/artifacts/{id}tokenDelete the artifact and all versions
GET/api/artifacts/{id}/versionslinkVersion history
DEL/api/artifacts/{id}/versions/{n}tokenPrune one old version
POST/api/artifacts/{id}/rollbacktokenRepoint the key at version n
GET/api/artifacts/{id}/tokenstokenWho can edit: labels and dates
POST/api/artifacts/{id}/tokenstokenMint another labelled token
DEL/api/artifacts/{id}/tokens/{tid}tokenRevoke one token
GET/a/{id}/linkThe current version, rendered
GET/a/{id}/v/{n}/linkA pinned, immutable version
GET/a/{id}/{path}linkAn asset of the current version
GET/health—Liveness

The token goes in Authorization: Bearer <token> or X-Edit-Token. The live version cannot be deleted — roll back first. Version numbers are never reused, so a pruned version's URL stays dead rather than later resolving to different content.

Limits