Share a deliverable publicly
Sometimes you want to send one generated deliverable (say the self-contained HTML page
an agent produced) to someone who has no business touching the board. Handing them
REV0_AUTH_TOKEN is the wrong tool: that token drives a board that runs shell commands.
Instead, the board can mint a per-file capability link: an unguessable, read-only
https://.../share/<token> URL that serves exactly that one artifact and nothing else.
What the recipient does: nothing. They open the link in any browser, on any device, with no install, login, token or account. The link is the only public surface; the rest of the board stays behind your token.
Three properties keep it safe:
- Human-only. Sharing is a deliberate click in the UI. The mint and revoke endpoints
require a logged-in browser session (the auth cookie) and reject Bearer and
X-Auth-Tokencallers, so an agent, the runner or the CLI can never publish a file on its own. - Self-bounded. Each link has a lifetime you pick from a dropdown (1h, 1d, 7d, 30d or never; default 7d). Stop sharing revokes it at once: the link returns 404 and, if it was the last active link, the tunnel is torn down immediately. The managed tunnel also carries its own kill timer in a detached shell, so exposure ends on schedule even if the board is idle or shut off.
- Board stays locked. A public tunnel is refused unless
REV0_AUTH_TOKENis set, so only/share/<token>is reachable without the token.
Share a whole ticket or a whole board
Section titled “Share a whole ticket or a whole board”The same link machinery also publishes one ticket or one board, for showing a stakeholder what an agent shipped without giving them the board:
- Share this ticket (ticket detail, Public link) renders a read-only page with the
plan, the diff summary (
--stat, not the patch), the artifacts and the timeline. The timeline is only the comments and status moves, never the agent’s tool transcript, permission prompts ormetablobs, and the page is built from an explicit field allow-list, so nothing else can leak into it. - Share this board (board settings, Public link) renders that board’s columns and cards (id, title, priority, tags) and stops there: no ticket bodies, no timelines, no drill-in.
Same properties as above: human-only minting, a lifetime you pick, instant revoke, and a token that reaches exactly the one ticket or board it was minted for. There is no reply box and no API behind the token; the ticket’s own artifacts are the only files it opens.
Turn it on
Section titled “Turn it on”In Settings > Automation > Features, tick Allow sharing artifacts publicly, then
pick a Public reachability provider (or set REV0_ARTIFACT_SHARE=1 and
REV0_ARTIFACT_SHARE_TUNNEL=<provider> in the environment). A per-artifact Share
publicly button then appears in a ticket’s Artifacts section, along with the ticket and
board level Public link controls.
Pick a reachability provider
Section titled “Pick a reachability provider”A link only resolves if your machine is reachable from the internet, and that comes from a
tunnel. Pick one with artifact_share_tunnel_provider:
tailscale(recommended):tailscale funnel --bg 8000gives a stablehttps://<machine>.<tailnet>.ts.netwith real, auto-provisioned TLS that you control, andtailscale funnel offkills it at once. The board runs and tears this down for you. One-time setup: Tailscale 1.38.3 or newer with MagicDNS on and HTTPS certificates on (both admin console toggles), and afunnelnode attribute in your tailnet policy ("nodeAttrs": [{ "target": ["autogroup:member"], "attr": ["funnel"] }]). The firsttailscale funnelrun provisions the certificate and adds that attribute by default, so in practice it is flipping MagicDNS and HTTPS on once. Funnel is fully public (not tailnet-private), so the capability token and lifetime still do the access control; the recipient never needs Tailscale.cloudflared(zero-setup fallback):cloudflared tunnel --url http://127.0.0.1:8000(no account;brew install cloudflared) gives a throwaway*.trycloudflare.comURL.ngrok: optional;uv add pyngrokand configure an ngrok authtoken.manual: you run your own tunnel (or share over LAN or Tailscale) and setartifact_share_base_urlto its public base; the board only mints the link.
Other knobs, in Settings or the environment: artifact_share_default_ttl,
artifact_share_ttl_options, artifact_share_tunnel_max_ttl (the cap on the tunnel’s
board-independent kill timer) and artifact_share_base_url.