Uploads and keys
Authenticates keys, stores uploads made through the API with an expiry, and serves share links. Workspace transfers never pass through it.
Mint a key without signing up, upload with one HTTP call from any language, and get a share link back
Checking the API…
No sign-up. Clex mints the key on the server and stores only its SHA-256 hash, so you see it exactly once. Send it as a Bearer token
export CLEX_API_KEY='<YOUR_API_KEY>'
Device—
This sends a real request to clex.in/vault/api/uploads with the key above and hands back a working share link, the same one the curl example returns
The body is the raw file. Metadata travels in headers. The response carries the share link
# Upload a file, get a share link
curl -X POST https://clex.in/vault/api/uploads \
-H "Authorization: Bearer $CLEX_API_KEY" \
-H "X-Filename: report.pdf" \
-H "X-Expires-In: 86400" \
--data-binary @report.pdfimport os, requests
with open("report.pdf", "rb") as f:
r = requests.post(
"https://clex.in/vault/api/uploads",
headers={
"Authorization": f"Bearer {os.environ['CLEX_API_KEY']}",
"X-Filename": "report.pdf",
},
data=f,
)
r.raise_for_status()
print(r.json()["shareUrl"])import { readFile } from 'node:fs/promises'
const res = await fetch('https://clex.in/vault/api/uploads', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.CLEX_API_KEY}`,
'X-Filename': 'report.pdf',
},
body: await readFile('report.pdf'),
})
if (!res.ok) throw new Error(`upload failed: ${res.status}`)
console.log((await res.json()).shareUrl)/vault/api/uploadsUpload a fileBody is the raw bytes. Headers: X-Filename (required), Content-Type, and X-Expires-In in seconds, from 5 minutes to 7 days, 24 hours by default. Responds 201 with the share link and rate limit headers.
{
"id": "8f3c…",
"shareToken": "K9M3JX72A8DR",
"shareUrl": "https://clex.in/share/K9M3JX72A8DR",
"downloadUrl": "https://clex.in/vault/api/uploads/K9M3JX72A8DR/download",
"filename": "report.pdf",
"sizeBytes": 524288,
"expiresAt": 1790670227000
}
/vault/api/uploadsList your uploadsReturns the key owner's live uploads, newest first. Authenticate with the same Bearer key.
/vault/api/uploads/:tokenShare detailsPublic. Returns the filename, size, type, expiry and the download URL for a share token. Expired or revoked shares answer 410. This is what clex.in/share pages use.
/vault/api/uploads/:token/downloadThe bytesStreams the file as an attachment. Revocation and expiry are checked on every request, so a revoked link stops working at once.
/vault/api/uploads/:idRevoke an uploadDeletes the stored bytes and revokes the share. Later hits on the link answer 410.
The Clex CLI wraps the same API: send files, list them, fetch by link and revoke, from any terminal
clex loginStore your API keyclex send report.pdfUpload and print the share linkclex lsList your uploadsclex get K9M3JX72A8DRDownload from a link or tokenclex rm 8f3c…Revoke an uploadInstall from the repository today; the npm package is on its way.
Authenticates keys, stores uploads made through the API with an expiry, and serves share links. Workspace transfers never pass through it.
Introduces two browsers by relaying WebRTC offers, answers and ICE candidates over a WebSocket. It never sees file data.
Records anonymous transfer metadata in a hash linked chain anyone can browse on the Chain page.