Access modes
Private, password, allow-list, and public — the four levels every page, file, and link enforces.
Access modes
Every page and uploaded file has an access level, enforced by
sherlink — the single policy owner behind all three public hosts (p.,
f., sl.).
private(default) — reachable only by your own account. A stranger gets a plain404, not a "this is private" message — the resource's existence is never leaked.password— anyone with the URL and the password can view it, once per browser (an unlock cookie remembers it after that).allow_list— reachable by specific accounts or email addresses, granted individually. An unauthenticated visitor is asked to sign in; a signed-in visitor who isn't on the list gets no access, not a sign-in prompt.public— anyone with the URL, no sign-in or password required.
Setting it
At creation:
sherpage_publish({ title, files, access: "public" })
Or after the fact — a page's own access is changed with
sherpage_set_access; an uploaded file's access lives on its short
link, changed with link_set_access, since a sherserve object doesn't
carry its own policy, only sherlink does:
link_set_access({ code_or_id: "<code>", access: "password", password: "…" })
Expiry and view budgets stack on top
expires_at and max_views apply regardless of access level — an
expired or budget-spent resource answers as expired, checked before
the access level itself, so a dead allow-listed resource never demands a
sign-in only to refuse afterward.
Next
Rate limits and quotas — the last
thing standing between a call and a 429.