Developers

The API, simply

Mint a key without signing up, upload with one HTTP call from any language, and get a share link back

Checking the API…

API access

Your key, in one click

No sign-up. Clex mints the key on the server and stores only its SHA-256 hash, so you see it exactly once. Send it as a Bearer token

  1. 1Generate a key
  2. 2Export it as CLEX_API_KEY
  3. 3Upload and get a share link
Click Generate to mint a key No sign-up · 60 requests a minute · 100 MB per file
export CLEX_API_KEY='<YOUR_API_KEY>'

Device—

Try it here

Upload with your key, right now

This sends a real request to clex.in/vault/api/uploads with the key above and hands back a working share link, the same one the curl example returns

Needs a key from the card above. Nothing is sent until you press upload.

Quickstart

Upload from anywhere

The body is the raw file. Metadata travels in headers. The response carries the share link

# Upload a file, get a share link
curl -X POST https://clex.in/vault/api/uploads \
  -H "Authorization: Bearer $CLEX_API_KEY" \
  -H "X-Filename: report.pdf" \
  -H "X-Expires-In: 86400" \
  --data-binary @report.pdf
Reference

Five endpoints, that's all

POST/vault/api/uploadsUpload a file

Body is the raw bytes. Headers: X-Filename (required), Content-Type, and X-Expires-In in seconds, from 5 minutes to 7 days, 24 hours by default. Responds 201 with the share link and rate limit headers.

{
  "id": "8f3c…",
  "shareToken": "K9M3JX72A8DR",
  "shareUrl": "https://clex.in/share/K9M3JX72A8DR",
  "downloadUrl": "https://clex.in/vault/api/uploads/K9M3JX72A8DR/download",
  "filename": "report.pdf",
  "sizeBytes": 524288,
  "expiresAt": 1790670227000
}
GET/vault/api/uploadsList your uploads

Returns the key owner's live uploads, newest first. Authenticate with the same Bearer key.

GET/vault/api/uploads/:tokenShare details

Public. Returns the filename, size, type, expiry and the download URL for a share token. Expired or revoked shares answer 410. This is what clex.in/share pages use.

GET/vault/api/uploads/:token/downloadThe bytes

Streams the file as an attachment. Revocation and expiry are checked on every request, so a revoked link stops working at once.

DELETE/vault/api/uploads/:idRevoke an upload

Deletes the stored bytes and revokes the share. Later hits on the link answer 410.

Limits

Key without an account
100 MB per file · 60 requests a minute · 3 keys per device
Signed in on the account page
Higher limits · keys across devices
Link expiry
5 minutes to 7 days · default 24 hours
Key storage
SHA-256 hash only · plaintext shown once
Command line

Or just clex send

The Clex CLI wraps the same API: send files, list them, fetch by link and revoke, from any terminal

  • clex loginStore your API key
  • clex send report.pdfUpload and print the share link
  • clex lsList your uploads
  • clex get K9M3JX72A8DRDownload from a link or token
  • clex rm 8f3c…Revoke an upload

Install from the repository today; the npm package is on its way.

Under the hood

Three small services

API

Uploads and keys

Authenticates keys, stores uploads made through the API with an expiry, and serves share links. Workspace transfers never pass through it.

Signal

Signaling

Introduces two browsers by relaying WebRTC offers, answers and ICE candidates over a WebSocket. It never sees file data.

Chain

Public ledger

Records anonymous transfer metadata in a hash linked chain anyone can browse on the Chain page.