Self-hostable, end-to-end encrypted file and note sharing. Zero-knowledge server.
100K+
End-to-end encrypted, self-hostable file and note sharing service built for speed and security.
Website • Documentation • Quick Start • Public Instances • Changelog • Roadmap
SkySend is a minimalist, self-hostable file and note sharing service with end-to-end encryption. Files and notes are encrypted entirely in the browser using AES-256-GCM before they ever reach the server - the server stores only encrypted blobs and never has access to the decryption key. No accounts, no tracking, no analytics just Open Source.
This Project is community ready to get self hosted and for those who don't want or could not host their own instance, there are public instances available. If you want to make the internet safer, you can host your own instance and add it to the public instances list by creating a Issue with your instance details or a PR Instances List.
Inspired by timvisee/send (the community fork of Mozilla Send) and PrivateBin, SkySend is built from scratch with higher security standards, more features, and a minimal, maintainable codebase.
We used a leightweight tech stack (Node.js, Hono, Vite, React) and modern security practices to create a fast, secure, and user-friendly experience. Check out our Benchmarks.
#) and never leaves the browserOIDC_PROTECT_FILES / OIDC_PROTECT_NOTES~/.config/skysend/docker compose up -d/api/healthPUID/PGID for proper volume permissionsskysend upload <files...> - upload single or multiple files with progress barskysend download <url> - download and decrypt filesskysend note <text> - create encrypted notes (text, password, code, markdown, sshkey)skysend note:view <url> - view encrypted notesskysend update - self-update from GitHub Releases with checksum verificationskysend auth login - authenticate against an OIDC-protected serverskysend auth logout - remove the stored session tokenskysend auth status - show the current session state--json flag for machine-readable outputskysend-cli list - show active uploadsskysend-cli delete <id> - delete an uploadskysend-cli stats - storage overviewskysend-cli cleanup - trigger manual cleanupskysend-cli config - show current configurationSupported Platforms: AMD64 (x86_64) • ARM64 (aarch64)
# docker-compose.yml
services:
skysend:
image: skyfay/skysend:latest
container_name: skysend
restart: always
ports:
- "3000:3000"
volumes:
- ./data:/data
- ./uploads:/uploads
environment:
- BASE_URL=http://localhost:3000
# All environment variables: https://docs.skysend.app/user-guide/configuration/environment-variables
# There are a lot of customization options available, so make sure to check the documentation for more details.
docker compose up -d
Open http://localhost:3000 in your browser.
📖 Full installation guide: docs.skysend.app/user-guide/getting-started
Upload and download files from the terminal with the same end-to-end encryption as the web interface.
Install (Linux/macOS):
curl -fsSL https://skysend.app/install.sh | sh
Install (Windows PowerShell):
irm https://skysend.app/install.ps1 | iex
Usage:
# Set your server
skysend config set-server https://your-instance.com
# Upload a file
skysend upload ./document.pdf
# Upload with password and expiry
skysend upload ./secret.zip --password --expires 1h --downloads 5
# Download a file
skysend download https://your-instance.com/file/abc123#secret
# Create an encrypted note
skysend note "This is a secret message" --type text --expires 24h
# Login to an OIDC-protected server
skysend auth login
# Self-update
skysend update
📖 Full CLI documentation: docs.skysend.app/user-guide/client-cli
| Component | Algorithm |
|---|---|
| Secret Key | 256-bit Random (32 Bytes) |
| Key Derivation | HKDF-SHA256 |
| File Encryption | AES-256-GCM, 64KB Record Size |
| Note Encryption | AES-256-GCM + Random IV |
| Metadata Encryption | AES-256-GCM + Random IV |
| Nonce Handling | Counter-based (XOR) |
| Auth Token | HMAC-SHA256 |
| Password KDF | Argon2id (WASM) |
The complete crypto design is publicly documented at docs.skysend.app/developer-guide/crypto.
| Area | Technology |
|---|---|
| Runtime | Node.js 24 LTS |
| Backend | Hono |
| Frontend | Vite + React 19 + Shadcn UI |
| CLI Client | Commander.js + Bun compile |
| Database | SQLite (Drizzle ORM) |
| Crypto | Web Crypto API + Argon2id (WASM) |
| Validation | Zod |
| i18n | react-i18next |
| Docs | VitePress |
| Monorepo | pnpm Workspaces |
Full documentation is available at docs.skysend.app:
# Clone & install
git clone https://github.com/Skyfay/SkySend.git && cd SkySend
pnpm install
# Start dev server (all packages in parallel)
pnpm dev
# Run all checks (lint, typecheck, tests)
pnpm validate
For contribution guidelines, see the CONTRIBUTING.md.
The system architecture, cryptographic design, strict technology stack selection, and feature specifications for SkySend were entirely conceptualized and directed by a human System Engineer to solve real-world privacy challenges in file sharing.
The application code was generated by AI coding agents following detailed architectural specifications and coding guidelines. All features were manually tested for correctness, stability, and real-world reliability. Automated unit tests (Vitest) with coverage tracking via Codecov, CodeQL static analysis, and security audits complement the manual QA process.
SkySend is thoroughly tested and used in production, but a formal manual security audit by an external developer has not yet been completed. The entire cryptographic design is publicly documented to facilitate independent review. If you are a software developer or cybersecurity professional, your expertise is highly welcome! We invite the open-source community to review the code, submit PRs, and help us elevate SkySend to a fully verified standard.
Security Disclosure: If you discover a security vulnerability, please do not open a public GitHub issue. Instead, report it responsibly via email to [email protected].
GNU Affero General Public License v3.0 - Any hosted instance must release its source code.
Content type
Image
Digest
sha256:837d0be47…
Size
87.7 MB
Last updated
11 days ago
docker pull skyfay/skysend