Skip to content
rev0Docs

Share a deliverable publicly

Sometimes you want to send one generated deliverable (say the self-contained HTML page an agent produced) to someone who has no business touching the board. Handing them REV0_AUTH_TOKEN is the wrong tool: that token drives a board that runs shell commands. Instead, the board can mint a per-file capability link: an unguessable, read-only https://.../share/<token> URL that serves exactly that one artifact and nothing else.

What the recipient does: nothing. They open the link in any browser, on any device, with no install, login, token or account. The link is the only public surface; the rest of the board stays behind your token.

Three properties keep it safe:

  • Human-only. Sharing is a deliberate click in the UI. The mint and revoke endpoints require a logged-in browser session (the auth cookie) and reject Bearer and X-Auth-Token callers, so an agent, the runner or the CLI can never publish a file on its own.
  • Self-bounded. Each link has a lifetime you pick from a dropdown (1h, 1d, 7d, 30d or never; default 7d). Stop sharing revokes it at once: the link returns 404 and, if it was the last active link, the tunnel is torn down immediately. The managed tunnel also carries its own kill timer in a detached shell, so exposure ends on schedule even if the board is idle or shut off.
  • Board stays locked. A public tunnel is refused unless REV0_AUTH_TOKEN is set, so only /share/<token> is reachable without the token.

The same link machinery also publishes one ticket or one board, for showing a stakeholder what an agent shipped without giving them the board:

  • Share this ticket (ticket detail, Public link) renders a read-only page with the plan, the diff summary (--stat, not the patch), the artifacts and the timeline. The timeline is only the comments and status moves, never the agent’s tool transcript, permission prompts or meta blobs, and the page is built from an explicit field allow-list, so nothing else can leak into it.
  • Share this board (board settings, Public link) renders that board’s columns and cards (id, title, priority, tags) and stops there: no ticket bodies, no timelines, no drill-in.

Same properties as above: human-only minting, a lifetime you pick, instant revoke, and a token that reaches exactly the one ticket or board it was minted for. There is no reply box and no API behind the token; the ticket’s own artifacts are the only files it opens.

In Settings > Automation > Features, tick Allow sharing artifacts publicly, then pick a Public reachability provider (or set REV0_ARTIFACT_SHARE=1 and REV0_ARTIFACT_SHARE_TUNNEL=<provider> in the environment). A per-artifact Share publicly button then appears in a ticket’s Artifacts section, along with the ticket and board level Public link controls.

A link only resolves if your machine is reachable from the internet, and that comes from a tunnel. Pick one with artifact_share_tunnel_provider:

  • tailscale (recommended): tailscale funnel --bg 8000 gives a stable https://<machine>.<tailnet>.ts.net with real, auto-provisioned TLS that you control, and tailscale funnel off kills it at once. The board runs and tears this down for you. One-time setup: Tailscale 1.38.3 or newer with MagicDNS on and HTTPS certificates on (both admin console toggles), and a funnel node attribute in your tailnet policy ("nodeAttrs": [{ "target": ["autogroup:member"], "attr": ["funnel"] }]). The first tailscale funnel run provisions the certificate and adds that attribute by default, so in practice it is flipping MagicDNS and HTTPS on once. Funnel is fully public (not tailnet-private), so the capability token and lifetime still do the access control; the recipient never needs Tailscale.
  • cloudflared (zero-setup fallback): cloudflared tunnel --url http://127.0.0.1:8000 (no account; brew install cloudflared) gives a throwaway *.trycloudflare.com URL.
  • ngrok: optional; uv add pyngrok and configure an ngrok authtoken.
  • manual: you run your own tunnel (or share over LAN or Tailscale) and set artifact_share_base_url to its public base; the board only mints the link.

Other knobs, in Settings or the environment: artifact_share_default_ttl, artifact_share_ttl_options, artifact_share_tunnel_max_ttl (the cap on the tunnel’s board-independent kill timer) and artifact_share_base_url.