Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

osbytes/crypt.fyi

Open more actions menu

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

439 Commits
439 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

logo

crypt.fyi - A zero-knowledge, end-to-end encrypted secret sharing platform that enables secure and private transmission of sensitive data.

osbytes — open source bytes CI Security Headers Mozilla HTTP Observatory Grade CII Best Practices i18n

Features

  • 🔐 End-to-end encryption using ML-KEM post-quantum cryptography
  • 🛡️ Strict Content Security Policy (CSP) to prevent XSS attacks and unauthorized resource loading
  • 🛡️ Strict rate limits to mitigate brute-force attacks
  • 🤫 Zero-knowledge architecture - server never sees unencrypted data or decryption keys
  • 🔥 Burn after reading w/ provisions to prevent erroneous burns from bots or url introspection
  • 🔥 Burn after n read failures
  • ⏰ Automatic expiration (Time-To-Live)
  • 🗝️ Password protection
  • 📁 File sharing support w/ drag and drop
  • 🪝 Webhook notifications for read success, read failure, and burn events
  • 🌐 IP/CIDR allow-listing
  • 🔢 Read count limits
  • 📱 QR code generation
  • ⌨️ CLI for interacting with the API
  • 🧩 Chrome Extension
  • 🐳 Docker images for the api server and web client
  • 🌐 Internationalization support for multiple languages

How It Works

  1. Encryption key is generated on the client
  2. Password is optionally provided
  3. Encryption key and password are used to encrypt the secret
  4. Encryption key and password are hashed and stored along with the encrypted secret for verification on retrieval - the raw key and password are never stored or transmitted on/to the server
  5. The unique URL containing the decryption key is generated on the client
  6. Share the URL with your recipient and separately the password if specified
  7. When accessed, only when the decryption key and password match via server-side verification of the hashes, the encrypted secret is shared and decrypted in the recipient's browser
  8. Optionally, the secret is automatically destroyed after being read in an atomic read & delete operation guaranteeing only one person can access the secret
  9. If retrieval doesn't happen within the TTL, the secret is automatically destroyed

RFC

API Usage

OpenAPI Specification

Deployment

Docker

API_URL=https://{your-domain-here} docker compose up --build

Important

--build is required if API_URL is changed to ensure nginx and the web client are rebuilt with the correct configuration.

Railway

Deploy on Railway

Development

  1. Clone the repository
  2. Enable Corepack (uses the packageManager field → pnpm):
    corepack enable
  3. Install dependencies:
    pnpm install
  4. Set up environment variables (see .env.example)
  5. Start the development server:
    pnpm dev

Releasing packages

Publishable packages: @crypt.fyi/core and @crypt.fyi/cli (npm), plus the Chrome extension.

  1. Record changes: pnpm changeset
  2. Merge to main — the Release workflow opens a Version Packages PR (or publishes when that PR is merged)
  3. Required GitHub secrets for publishing:
    • NPM_TOKEN
    • CHROME_EXTENSION_ID, CHROME_CLIENT_ID, CHROME_CLIENT_SECRET, CHROME_REFRESH_TOKEN, CHROME_PUBLISHER_ID

Technical Stack

Known Issues & Development Considerations

Content Security Policy

  • The toast notification library (sonner) requires specific style-src hashes in the CSP configuration
  • These hashes are defined in nginx/nginx.conf
  • Updates to sonner may require updating these hashes
  • Reference: sonner#449

Development Environment

  • Ensure Redis is running locally when developing the server
  • The web client expects the API to be available at http://localhost:4321 by default
  • CSP headers in development may differ from production configuration

Security Considerations

  • Always test encryption/decryption flows thoroughly when making changes
  • Ensure no sensitive data is logged or exposed in error messages
  • Maintain strict CSP headers to prevent XSS vulnerabilities
  • Keep dependencies updated for security patches

Contributing

Contributions are welcome! Please feel free to submit an Issue or Pull Request on GitHub.

Morty Proxy This is a proxified and sanitized view of the page, visit original site.