End-to-end encrypted, self-hostable file and note sharing, built for speed and security.
Website • Documentation • Quick Start • Public Instances • Changelog • Roadmap
SkySend shares files and notes so that only the recipient can read them. Everything is encrypted in the browser before it leaves the device, and the key travels in the fragment of the share link, which browsers never send to a server. The server stores ciphertext and nothing else.
It runs as one Docker container with SQLite and needs no accounts. Host your own instance, or use one of the public instances, and if you run one yourself, you can add it to the list.
Inspired by timvisee/send, the community fork of Mozilla Send, and by PrivateBin, SkySend is built from scratch with higher security standards, more features and a minimal, maintainable codebase. Its whole crypto design is documented.
- Zero knowledge - AES-256-GCM in the browser, and the key never leaves the share link
- Files and folders - single files, several at once or a whole folder, zipped in the browser, with size and file limits you set yourself
- Notes made of blocks - text and Markdown, passwords with a generator, code with highlighting and SSH keys, combined in one note
- File and note requests - send someone an upload link, and the files or the note they send are encrypted for you alone
- Shares that delete themselves - expiry times, download and view limits, and burn after reading
- Password protection - an optional password on top of the link, derived with Argon2id
- A CLI for the terminal - upload, download and notes with the same encryption, plus an interactive TUI
- No accounts - My Links lives in the browser, and optional OIDC sign-in limits who may share
- Runs anywhere - local storage or any S3-compatible bucket, 13 languages and three themes
| Component | Algorithm |
|---|---|
| Secret key | 256-bit random, in the URL fragment only |
| Key derivation | HKDF-SHA256, a separate key for content, metadata and auth |
| File encryption | AES-256-GCM, streamed in 64 KB records |
| Note and metadata encryption | AES-256-GCM with a random IV |
| Auth token | HMAC-SHA256 |
| Password KDF | Argon2id (WASM) |
| File requests | HPKE (RFC 9180), P-256 and AES-256-GCM |
# docker-compose.yml
services:
skysend:
image: skyfay/skysend:latest
container_name: skysend
restart: always
ports:
- "3000:3000"
volumes:
- ./data:/data
- ./uploads:/uploads
environment:
- BASE_URL=http://localhost:3000docker compose up -dOpen http://localhost:3000. The documentation covers every environment variable, reverse proxies and S3 storage. Images are built for AMD64 and ARM64.
The CLI client installs with one line, on Linux and macOS:
curl -fsSL https://skysend.app/install.sh | shOn Windows, in PowerShell:
irm https://skysend.app/install.ps1 | iexSkySend is free and open source. Sponsoring it keeps it that way, and from $15 a month or $100 once your name shows up here by itself.
🏆 Patrons · $500 once

Kay van Aarssen
Pull requests go into the dev branch, never into main. CONTRIBUTING.md explains the setup and the workflow, and the Developer Guide the architecture, the crypto library and the tests. Please read PHILOSOPHY.md before proposing a feature.
- 💬 Discord: dc.skyfay.ch
- 🐛 Issues: bugs and feature requests on GitHub Issues
- 📧 Support: support@skysend.app
- 🔒 Security: report vulnerabilities privately as described in SECURITY.md, never in a public issue
The architecture, the cryptographic design, the technology stack and the feature specifications of SkySend were designed and directed by a human system engineer. The code is written by AI coding agents that follow those specifications and the guidelines of the project. Every feature is tested by hand, backed by unit tests with coverage tracking, CodeQL and security audits run by AI agents.
A formal security audit by an external firm has not been done yet. Independent security researchers have reviewed parts of the code and reported vulnerabilities privately. Every report was fixed in a release and published as an advisory that credits the reporter, see Security Advisories. The crypto design is publicly documented to make a full review easy. If you review code or work in security, your findings are very welcome, see SECURITY.md for how to report them.
GNU Affero General Public License v3.0. Any hosted instance must release its source code.
