A share link hands one secret's value in one environment to someone, without giving them access to your Burrow. It opens a set number of times, for a set time, and can ask for a passphrase or a signed-in member. Canary secrets can't be shared.
Create a share link#
Open the project and environment the secret is in, open the menu at the end of the secret's row, and select Share.
Set Maximum views, from 1 to 1,000, and Expires after, in minutes, hours or days, from 5 minutes to 30 days.
Turn on Require a passphrase or Members of this Burrow only if you want either, then select Create link.
Copy the link and send it. If you asked for a passphrase, copy it too and send it another way, since it is shown only this once.
The link shows the value as it was when you made it. Changing the secret afterwards doesn't change what the link shows. For a structured secret, it shows every field.
Opening a link#
The link opens a page that shows how many views are left and when the link expires. Selecting Reveal secret uses one view and shows the value, with a copy button beside it. A view counts only when the value is revealed, so opening the page to look costs nothing.
With a passphrase. The page asks for it before revealing. The passphrase is generated for you, so it's never a weak one. After five wrong passphrases, the link is destroyed.
Members of this Burrow only. The page asks the person to sign in with their RatelKey account, and reveals the value only to a member of your Burrow.
See and revoke live links#
A secret with live share links has a small marker beside its name in the list. Select it to see each link, with how many views it has left, when it expires, whether it has a passphrase or is for members only, and who made it. Copy a link again from there, or revoke it with the delete icon beside it.
When a link ends#
A link stops working the moment any of these happens:
its last view is used;
it expires;
it's revoked;
someone enters five wrong passphrases;
the secret, or the environment it's in, is deleted.
An ended link shows Link unavailable, with the same message whatever the reason.
Permissions and the audit log#
Share links have their own permissions in Roles: read to see a secret's links, write to create them, and delete to revoke them. Seeing and creating links also need permission to read secrets, since a link carries the value. Revoking doesn't.
Every link that's created, listed, opened, refused, revoked, expired or destroyed is recorded in the audit log. A link opened by someone who isn't signed in shows as Someone with the link.