Reusable until revoked
Each six-character code belongs to one encrypted recipient email and can be disabled instantly by an authorized API client.
- Cryptographic code hashing
- Optional client-supplied codes
- One-time full-code response
01 Product features
Focused capabilities for teams that want a clean public handoff without operating a document repository.
Open with a code →
02 Detail
Each six-character code belongs to one encrypted recipient email and can be disabled instantly by an authorized API client.
Public responses use masked email values. The database stores encrypted recipient content plus keyed lookup hashes.
Timestamped HMAC payloads carry an encrypted legacy UID to the dedicated Zulde identity at the shared service.
Per-network and per-code rate buckets slow automated guessing while keeping the public response deliberately non-specific.
API secrets are high-entropy, stored as hashes, shown only when created, and restricted to create, read, or revoke operations.
Events capture validation and handoff outcomes with request IDs and hashed network identifiers.