Share Links
Share links provide public, unauthenticated access to project findings or individual issues. Use them to share security assessment results with stakeholders who don't have a Hashiro account.
What Can Be Shared
| Type | Content |
|---|---|
| Project | All findings within a project, including severity, status, and details |
| Individual Issue | A single vulnerability finding with its full detail |
Creating a Share Link
- Navigate to the project or issue you want to share
- Create a new share link with:
- Label: a descriptive name (e.g., "Q3 Report for Stakeholders")
- Expiry: when the link should stop working
- Copy the generated URL
The link can be sent to anyone. No login is required to view the shared content.
Security
- Token-based: each link contains a unique, cryptographically generated token
- Hashed storage: tokens are stored as hashes in the database, not in plain text
- Expiry: links automatically expire after the configured date
- Revocable: links can be revoked at any time, immediately disabling access
- Read-only: shared content is strictly view-only
WARNING
Share links provide unauthenticated access to potentially sensitive vulnerability data. Use expiry dates and revoke links when no longer needed.
Managing Share Links
From the management view, you can:
- List all active share links for a project or issue
- Revoke links that are no longer needed
- View labels and expiry dates