onelink.ninja logo onelink.ninja

Secret links and editing

Every list has exactly two states, and they behave differently.

Unclaimed: the token is the key

A list published without an account gets one secret token. Anyone holding it can edit or delete the list — that is the whole security model, and it is the same trade every “secret URL” service makes.

What follows from that:

  • Treat the edit URL like a password. Anyone you send it to can change the list.
  • There is no recovery. We cannot email it to you, because we have no idea who you are.
  • Sharing the public URL is safe. /l/{id} never contains the token, and the token is not derivable from the id.

You can edit the title, description, and links, reorder them, and delete the whole list from /l/{id}/edit?token=….

Claimed: your session is the key

Once you claim a list, the token is destroyed. From then on:

  • The old edit URL stops working, immediately and permanently.
  • Editing requires being signed in as the owner.
  • Anyone else who had the old link loses access — which is the point, if you shared it carelessly.

Claiming is one-way. There is no un-claim.

Deleting

/l/{id}/delete asks for confirmation, then removes the list and every link in it. The URL stops resolving for everyone you shared it with. It cannot be undone — there is no trash.

Access to the delete page follows the same rule as editing: a valid token while unclaimed, the owning session once claimed. Anyone else is sent to the public page rather than shown an error, because there is nothing secret about the list existing.