# L-Share > L-Share is a single-purpose file sharing tool. It uploads one file directly > from the browser to object storage (Vercel Blob or S3), returns a public > link, and keeps the per-file delete capability in the uploading browser's > local storage only. ## Facts - No accounts, no server-side upload history, no database. - Uploads are validated client- and server-side: extension allowlist (images, documents, text, audio, video, ZIP), non-empty size, and a configurable size limit (default 50 MiB, max 5120 MiB). - Each upload gets a random 256-bit delete key. Its SHA-256 hash is embedded in the object path; the raw key never leaves the browser except to delete. - Files are public by URL. There is no encryption, expiry, or malware scanning. Do not share sensitive data. - Delete controls live in the originating browser only and are lost when site data is cleared. The storage owner can always delete objects directly. - An optional deployment-wide access key (`L_SHARE_ACCESS_KEY`) can gate who may start uploads. ## Endpoints - `/` — the upload interface. - `/terms` — terms of service for this deployment. - `/privacy` — privacy policy for this deployment. - `POST /api/uploads` — issues Vercel Blob client upload tokens (same-origin JSON only). - `DELETE /api/uploads` — deletes an object when the submitted delete key hashes to the ownership hash embedded in the pathname. - `POST /api/s3/uploads` — issues a five-minute presigned S3 PutObject URL bound to key, content type, and length (same-origin JSON only). - `/robots.txt`, `/sitemap.xml` — crawler directives. - `GET /api/s3/download` — 302 to a one-minute S3 GET URL with `Content-Disposition: attachment`. Accepts `pathname` and an optional original `name` (validated against the stored extension). ## Limits - One file at a time, single-part transfer. - Upload authorization expires after five minutes; overwrites are disabled. - Deleting requires the delete key from the uploading browser.