
Sharing is easy. Deciding who a link is for is the part people skip. shareHub makes that choice explicit for every share, and you can change your mind later: close the link, rotate a PIN, or shorten the session.
Three ways to open a link
| Mode | Who gets in | Use it for |
|---|---|---|
Email code (otp) | Only the addresses you list, or everyone at a domain you name, after entering a code sent to that address. | Client proposals, internal documents, anything addressed to specific people. |
PIN (pin) | Anyone who knows a fixed 4-digit PIN. | Simple sharing outside your organization, when you cannot list addresses. |
Public (public) | Anyone who has the link. | Content that is fine for anyone who is handed the address. |
AI agents publishing through MCP get the narrowest option by default: if accessMode is not set, a share is created as email code, and an email-code share with no recipients is refused rather than published open.
What a PIN does not prove
A PIN lets in whoever knows it. It does not verify who that person is, and it travels with the link if you send both in the same message. Send the PIN through a different channel, such as a phone call or a message app. If it leaks, change it: rotating the PIN also signs out every device that had already entered the old one, because a browser that is already inside no longer cares what the PIN is.
How email codes and domain rules work
With email verification, the reader enters their address, and if it is on your list they receive a six-digit code that is valid for 15 minutes. Add addresses one by one, or add a rule such as *@yourcompany.com to let everyone at a domain in. Forwarding the link does not help someone who is not on the list: only a code sent to an allowed address opens it.
The response to a wrong or unlisted address is deliberately neutral, so the allow list cannot be probed from the outside to find out who is on it.
Sessions and end dates
After a reader verifies, their browser stays signed in for a period you control. The default is 12 hours; you can set anything from 1 hour to 720 hours (30 days). A long session means fewer codes for people you work with often; a short one means a shared computer cannot reopen the link tomorrow. Every share also has an end date, 90 days by default and 365 at most.
Closing access
Revoking a share closes it at once. Revocation and expiry are checked on every request and nothing is cached, so a valid session cannot reopen a revoked or expired link. Published content is also never indexed by search engines: public means “no code needed”, not “listed on the web”.
How to set all of this from code or from an agent is in the developer documentation.
Frequently asked questions
What is the difference between a PIN and email verification?
A PIN lets in anyone who knows it and does not verify who they are. Email verification sends a code to an address you approved.
Can I let a whole company open a link?
Yes. On an email-code share you can add a domain rule such as *@yourcompany.com, and people who verify an address at that domain can open it.
What happens to open sessions if I change the PIN?
Changing the PIN signs out every device that entered the old one, so readers must enter the new PIN.
Turn your document into a live link and decide who can open it.
Create account

