Skip to content

Sharing

A share is encrypted on your machine and decrypted in the recipient’s browser. The server stores ciphertext and nothing that opens it: a share made with Claspt 4.1 or later cannot be read by us.

ShareCarriesTypical use
A pageThe page and every secret in itA credentials page for a colleague
A secretOne valueOne password, one key

Right-click a page in the sidebar and choose Share, or use the share control on a secret block.

With a code. Claspt gives you a link and a code. You pass the code on yourself, by a different channel than the link: the link by email, the code by message. The link alone opens nothing.

A link that carries its key. The key sits after the # in the link, a part of a link browsers never send to a server. Nothing to type for the recipient. Anyone holding the whole link can open it, so send it by a channel you trust.

Every share expires; choose how long when you make it. Tick burn after reading and the share is gone after it has been opened once, which suits a one-time handoff.

  • Email delivery. Give the recipient’s address and Claspt emails the link and never the code.
  • Your own mail app. Claspt opens it with the link filled in, and the server is not told who you are writing to.
  • Copy the link and send it however you like.

Settings › Account & Sync › Incoming Shares lists shares sent to you, and Share Notifications controls whether you are told about them. To take a share back, revoke it from the page or from the account portal; the link then says the share has been revoked.

  • End to end is true for shares made with 4.1 and later, not before.
  • A share password or code is never sent to the server by any path.
  • The recipient’s browser does the decryption; an old or locked-down browser that blocks scripts cannot open a share.