postrundocs Back to siteSign in
Browse docsShare links

Share links

A share link is the same redacted report that export writes, uploaded to app.postrun.app so you can send a link instead of a file. You choose to share one session at a time. Nothing else leaves your machine, and recording never needs an account.

Needs Postrun 0.2.0 or newer

postrun login, postrun share and the Share link button arrived in 0.2.0. Check with postrun version, and update with npm install -g postrun@latest, then postrun setup.

Each link is:

  • Unlisted. The address has a random 16-character id. Only people you send it to can open it, and search engines are told not to index it.
  • Expiring. It works for 1, 7, 30 or 90 days (30 by default), then stops, and the report is deleted soon after.
  • Easy to turn off. Turning a link off deletes the report straight away.
  • Counted. You can see how many times each link was opened.

Connect this computer, once

Sharing needs a Postrun account. Sign in at app.postrun.app with GitHub or an email link: either one creates the account the first time. There are no passwords. The email link opens a page with a Sign in button; it works once and expires after 10 minutes.

The quickest way to connect is from the review app: Settings → Account → Connect account, or the Connect account button the first time you share. The terminal works too:

postrun login

Your browser opens app.postrun.app. Sign in if you need to, check the computer's name, and click Connect. The terminal then says who you are signed in as.

Behind the scenes the browser hands the terminal a one-time code, never the sign-in itself. The terminal swaps the code for a token by proving it started the login, as OAuth apps do (PKCE). The code works once, within two minutes, so one left in your browser history is useless.

The sign-in is saved in ~/.postrun/account.json, readable only by you. It can upload share links and nothing else: it cannot read your other links or change your account. Each connected computer is listed in Settings at app.postrun.app, where you can sign it out.

A computer without a browser

On a server you reach over SSH, make a token in Settings → Computers → Connect a computer without a browser at app.postrun.app. Then, on that computer:

postrun login --with-token

and paste the token when it asks. It is read from the terminal (or stdin), never the command line, so it stays out of your shell history. The token is shown once. Keep it out of chats and screenshots.

From the review app

  1. Open the session and click Share.
  2. Check what redaction masked, as you would for a file.
  3. Not connected yet? Click Connect account, sign in at app.postrun.app in the tab that opens, and approve this computer. The panel updates by itself.
  4. Choose how long the link works and click Create link.
  5. Copy the link and send it.

You can also connect or sign out under Settings → Account.

The background process uploads the report with this computer's sign-in. The page itself never sees the token.

From the terminal

postrun sessions                      # find the session id
postrun share <session-id>            # asks before uploading
postrun share <session-id> --expires 7 --yes

It lists what redaction masked, asks before uploading, and prints the link:

Redaction: masked 1 value(s) and 14 home path(s):
  anthropic-key   step 41 · command · stdout
Upload this redacted report to app.postrun.app? Anyone with the link can open it for 30 days. [Y/n]

  https://app.postrun.app/s/Xb3kP9qLmT2vR8wN

Expires 5 Nov 2026. See opens or turn it off: https://app.postrun.app/shares

Share links at app.postrun.app lists every link you made: whether it is live, expired or turned off, when it expires, its size and how many times it was opened. Opens count each time the report loads, yours included.

  • Turn off stops the link at once and deletes the report.
  • Remove takes an expired or turned-off link off the list.
  • Delete account in Settings deletes every link and every computer's sign-in. Sessions on your machine are not touched.

What someone sees

The link opens a page with a slim Postrun bar (the session title and when the link expires) above the report. Nothing about who shared it is shown. The reader does not need an account.

The report is served the way an untrusted file should be. It runs in a sandbox with no scripts, forms, popups or network requests. The browser treats it as coming from nowhere (an opaque origin), so it cannot read app.postrun.app cookies or pages, or reach anything else. It is never cached.

The email that signs you in opens a page with a Sign in button rather than signing you in straight away, because some mail scanners open every link in an email and would use up a one-time link before you click it.

Limits

LimitValue
Report size4 MB compressed (reports are sent gzipped; most are well under 1 MB)
Links made per hour30
Live links at once200
Connected computers20
Sign-in emails5 an hour to one address, 3 a minute from one network
Shared reports opened120 a minute from one network

Only reports made by Postrun can be uploaded, so a share link can't be used to host anything else, such as a fake sign-in page. A shared report never asks you to sign in or type anything; if one does, use Report in its top bar.

Redaction still applies

A share link holds exactly what the exported file would. Redaction is a safety net, not a guarantee, so skim the report before you send the link. If you sent something you shouldn't have, turn the link off: the report is deleted at once.

Sign out

postrun logout

Signs this computer out on app.postrun.app too, so its token stops working, and deletes ~/.postrun/account.json. Links you already made keep working until they expire or you turn them off.