Skip to main content
tc share publishes files from your space as links that open in the Share viewer at share.tinycloud.xyz. A link is either a bearer link that anyone holding the URL can read, or an addressed link that only a named email address or email domain can open.

Enable publishing

Publishing needs a session that can write to Share’s paths in your space. Approve that scope once through OpenKey, preferably on a dedicated profile so your existing app profiles keep their sessions:
tc enable share is the same as tc auth login --device --manifest builtin:share-publishing. It opens an OpenKey device approval for a narrow scope: capabilities/read on the space, kv/get and kv/put on xyz.tinycloud.share/shares/ (bearer-link files), and kv/get, kv/metadata, kv/put, and kv/list on shares/ (addressed shares). Add --replace-session only if you mean to replace the profile’s current session with the narrower one.

Publish

Human output is exactly one URL. Use --json for versioned, redacted metadata.

Expiry

Without --expires, publish requests seven days. A session-only profile cannot grant longer than its own session, so the CLI clamps the request, prints a notice to stderr, and reports "expiryClamped": true in JSON. An explicit --expires past the session’s end fails with SESSION_LIFETIME_EXCEEDED.

Filenames

A filename with characters other than A-Z a-z 0-9 . _ -, a leading character that is not a letter or digit, .., or more than 128 characters is stored under a readable URI-safe name: Q3 plan (draft).md becomes Q3-plan-draft.md, and .env becomes share.env. Bearer links show the stored name; addressed links keep the original. Names with control or invisible characters are refused with UNSAFE_FILENAME. The part after # is the read authority. Browsers never send it to a server, but keep complete URLs out of logs, analytics, and issue trackers. Email recipients claim an addressed link in the Share viewer by entering an 8-digit code sent to that mailbox. A domain: target accepts any verified mailbox at exactly that domain; subdomains do not match.
The CLI can publish to a DID (--to did:...), but the Share viewer cannot open DID-addressed links yet. Use an email address or domain for links people open in a browser.

Email invitations

--notify sends the recipient an invitation email with the link. It applies to exact-email targets. Invitations can be sent until the earlier of the share’s expiry or five minutes after publication. If delivery fails within that window, publish exits 9 and you can retry without republishing:
After the window closes, send the link yourself or publish again.
@tinycloud/cli 1.1.0 beta adds domain invitations (--to domain:example.com --notify --notify-to [email protected]) and reports a repeat invitation as already-delivered.

Inspect and receive

receive reads bearer links without a TinyCloud account. For an addressed link it exits 6 with CLAIM_REQUIRED: the recipient opens it in the Share viewer instead. receive writes a sanitized filename and will not overwrite an existing file unless you pass --force. Older ?tc2 links and pre-1.0 blob-backed links are not accepted.

History and revoke

Sender history is an encrypted file in the profile’s local cache, so list, show, notify, and revoke only know about shares published from that profile on that machine.

Errors

tc share uses its own exit codes. Read the structured error.code in JSON output rather than relying on the exit status alone. A session whose Share authority carries signed restrictions (caveats) cannot publish a bearer link, because the link’s delegation cannot carry them. The CLI refuses with PERMISSION_DENIED before uploading anything. Approve Share publishing on a fresh profile without restrictions.
In @tinycloud/cli 1.1.0 beta, a full space exits 10 with STORAGE_QUOTA_EXCEEDED or STORAGE_LIMIT_REACHED, matching the rest of the CLI. See When storage is full.