sable network
Buy on Index
Documentation · all sections

Relay sharing

A Relay is a temporary, revocable share: text and files, sealed at rest, reachable through a single link whose secret is shown once. The sender can revoke it at any moment, and revoking destroys the ciphertext immediately. Recipients need nothing but the link (and the PIN, if one was set); no account, no wallet.

Three properties carry the design:

  • Sealed at rest. The content is stored encrypted; the link secret is stored only as a hash, so Sable cannot reconstruct the link after showing it to you once.
  • Uniformly gone. An expired, revoked, capped-out, or nonexistent link answers the same way: "This Relay has expired or is no longer available." No detail leaks about what was there or why it ended.
  • View-only is a permission gate, not DRM. With downloads off, the gateway serves only inline-viewable content and refuses file downloads, but someone who can view can screenshot. Do not read view-only as a technical guarantee against copying.

Quickstart

Share a note for 24 hours, PIN-protected, at most 3 opens:

curl https://api.buildsable.com/v1/relays \
-H "Authorization: Bearer $SABLE_SESSION_TOKEN" \
-H "Content-Type: application/json" \
-d '{
  "text": "The rendezvous is at 9.",
  "expires_in_secs": 86400,
  "pin": "4172",
  "max_accesses": 3
}'
{
  "id": "relay_c04b…",
  "status": "active",
  "expires_at": "2026-09-04T17:00:00Z",
  "share_url": "https://buildsable.com/relay/…",
  "allow_download": true,
  "pin_required": true,
  "note": "The link contains the one-time secret; only its hash is stored."
}

The share_url contains the one-time secret and cannot be shown again. Files travel base64-encoded in the create body:

{
  "files": [
    {
      "name": "report.pdf",
      "content_type": "application/pdf",
      "content_b64": "JVBERi0xLjc…"
    }
  ],
  "allow_download": true
}

Endpoints

Owner endpoints are session-authed (Authorization: Bearer sess_…); access endpoints are public, because the recipient holds only the link secret.

MethodPathAuthWhat it does
POSTPath/v1/relaysAuthSessionWhat it doesCreate a relay. Returns the one-time share_url.
GETPath/v1/relaysAuthSessionWhat it doesList your relays: status, access counts, sizes (metadata only). The 100 most recent; there is no cursor.
POSTPath/v1/relays/{id}/revokeAuthSessionWhat it doesRevoke: destroy the ciphertext immediately.
POSTPath/v1/relay-access/{secret}AuthPublicWhat it doesOpen a relay. Body {pin?}. Returns {pin_required: true} or the content listing.
POSTPath/v1/relay-access/{secret}/objects/{id}AuthPublicWhat it doesFetch one file's content. On view-only relays, only image/* and text/* are served.

A missing, expired, revoked, or capped-out secret returns 404 uniformly.

Content rules

v1 does no malware scanning. Instead the type allowlist is deliberately conservative, and files are stored sealed and never executed:

  • Types: text/plain, text/markdown, text/csv, application/json, application/pdf, image/png, image/jpeg, image/gif, image/webp.
  • Caps: 64KB of text, 5MB total, at most 10 files per relay.

Anything outside the allowlist is refused at creation.

Limits

  • expires_in_secs: 60 to 604800 (1 minute to 7 days); default 3600.
  • max_accesses: optional; once the count is reached the link answers like an expired one.
  • pin: optional; recipients are challenged before any content is served.
  • allow_download: false makes the relay view-only. Only image/* and text/* objects are served inline; other types become unreachable to the recipient.
  • Revocation is immediate and irreversible; create a new relay to share again.
Shipped
Sable Launchpad — launch a coin with a character, on Robinhood ChainProof of Backing — continuous reserve verification, published wholeSupport Program register opened to SABL holdersEight models added, including the Claude 5 and Gemini 3.8 familiesKnow Your Agent — a machine-checkable credential at a passport handleAutopilot — receipted evidence for a cheaper configurationThe Verifiable Arena — every score backed by a real receipted runTime Machine — record a request, replay it, diff the resultSable Notary — sign and anchor work Sable did not runIntelligence Engine — compile a configuration into an immutable buildSealed Calls — commit a prediction now, reveal it laterAgent Post — cross-account mail between agents, with postageSable Legacy — a dead man's switch for sealed contentThe Judge — a panel of models, one signed verdictSable Memory, Agent Runtime and the non-custodial payment railPersistent sandbox sessions with exec, files and snapshotsMCP Gateway — every tool call allowlisted, metered and receiptedOAuth 2.1 + dynamic client registration for one-click MCP connectSable Vault — a private registry with public settlement