Docs
Publish a self-contained HTML or Markdown page, get an unguessable link, share it. No account. Push updated content under the same key and it becomes a new version at the same URL.
- The link is the permission.Ids carry ~79 bits of entropy. There is no listing endpoint and no index — an artifact is reachable only by someone holding its link.
- The edit token is the ownership.Creating an artifact returns a token exactly once. It is the only way to publish a new version, roll back, or delete. There is no recovery if you lose it.
- Nothing is public by accident.Every artifact is served with
noindexand a strict CSP that blocks any external host.
Publish something
One request. content is the body of your page — no
<html> or <head> needed.
curl -X POST https://artifact.optimasolutions.io/api/artifacts \
-H 'content-type: application/json' \
-d '{
"title": "Q3 Revenue",
"favicon": "📊",
"content": "<h1>Revenue</h1><p>Up 12% on the quarter.</p>"
}'You get back the share link and your one-and-only edit token:
{
"id": "bg7m3gvh836jmats",
"url": "https://artifact.optimasolutions.io/a/bg7m3gvh836jmats",
"version": 1,
"edit_token": "kQ8x..."
}
You can mint more tokens later — one per person or tool — and revoke them one at a time. See letting someone else edit.
Send "kind": "markdown" to write Markdown instead of HTML.
Publish an update
Same key, same link — the content becomes version 2. Whoever already has your link sees the new version on refresh.
curl -X PUT https://artifact.optimasolutions.io/api/artifacts/$ID \
-H "authorization: Bearer $EDIT_TOKEN" \
-H 'content-type: application/json' \
-d '{"label": "fixed the chart", "content": "<h1>Revenue</h1><p>Up 14%.</p>"}'Older versions stay reachable forever at their own pinned URLs
(/a/$ID/v/1/), so a link you shared to a specific version keeps
showing what you shared. title, description and
favicon are only changed when you include them.
Changed your mind? Point the key back at an earlier version:
curl -X POST https://artifact.optimasolutions.io/api/artifacts/$ID/rollback \
-H "authorization: Bearer $EDIT_TOKEN" \
-H 'content-type: application/json' \
-d '{"version": 1}'Let someone else edit it
Mint them their own token instead of handing over yours. Same full rights, but you can take it back without breaking your own copy — or the one you pasted into an editor or an agent.
curl -X POST https://artifact.optimasolutions.io/api/artifacts/$ID/tokens \
-H "authorization: Bearer $EDIT_TOKEN" \
-H 'content-type: application/json' \
-d '{"label": "teammate@example.com"}'The new token comes back once, like the first one. To take it back, revoke it
by the id from that response:
curl -X DELETE https://artifact.optimasolutions.io/api/artifacts/$ID/tokens/$TOKEN_ID \
-H "authorization: Bearer $EDIT_TOKEN"GET /api/artifacts/$ID/tokens lists who holds what — labels
and dates, never the tokens themselves — and marks which one you are using.
It needs a token, because labels name people and a link holder is not an editor.
The last remaining token can’t be revoked; that would leave an artifact
nobody can ever edit, so delete the artifact instead.
Publish with images and CSS
Send it as multipart. The filename becomes the path inside your artifact, so
relative references like <img src="assets/logo.png"> resolve.
curl -X POST https://artifact.optimasolutions.io/api/artifacts \
-F 'title=Bundle' \
-F 'entry=@index.html' \
-F 'asset=@style.css' \
-F 'asset=@logo.png;filename=assets/logo.png'Paths are sanitised: no ../, no absolute paths, no dotfiles, at
most 8 levels deep. A leading v/ is rejected because it collides
with version URLs.
What happens to your HTML
Diagrams and tables in Markdown
A mermaid fence is rendered as a diagram, by mermaid
11.16.1 served from this origin — nothing is fetched from a CDN,
and it is only loaded by pages that actually contain a diagram.
curl -X POST https://artifact.optimasolutions.io/api/artifacts \
-H 'content-type: application/json' \
-d '{"title": "Flow", "kind": "markdown", "content": "```mermaid\nflowchart LR\n A[Upload] --> B[Link]\n```"}'That publishes this:
flowchart LR
A[Upload] --> B(Unguessable link)
B --> C{Share it}
C -->|open| D[Rendered page]
C -->|push v2| A
Diagrams follow the page theme and are re-drawn when a reader flips it. If the
renderer can’t load, the diagram source stays visible as a code block. In
hand-written HTML the same thing works with
<pre class="mermaid">...</pre> — but only in a
fragment, since a full document is served untouched.
Markdown tables get a scroll container, so a wide one scrolls inside itself instead of pushing the page sideways.
Every endpoint
The token goes in Authorization: Bearer <token> or
X-Edit-Token. The live version cannot be deleted — roll back
first. Version numbers are never reused, so a pruned version's URL stays dead
rather than later resolving to different content.
Limits
- Up to 16 MB and 64 files per version.
- Artifacts cannot reach any external host — no CDN scripts, no remote
fonts or images, no
fetchoff-origin. Inline everything and embed assets asdata:URIs or upload them alongside. - Inline
<script>and<style>are allowed, as are scripts and styles you upload alongside your page.