hashes.sh

How hashes.sh works

Scheduled messages with verifiable content and timestamps.

Publishing and reveal

Sign in with GitHub, write Markdown or LaTeX, and choose a reveal time up to 365 days away. Publishing freezes the exact source, optional title, and time. Share the link immediately. Until the deadline, visitors see the author, hash, and timestamps. At the deadline, anyone with the link can read the message and verify its hash.

What the hash proves

One SHA-256 hash covers the title, exact Markdown, publication and reveal times, and a random 256-bit nonce. The title, body, and nonce stay private until reveal.

The UTF-8 payload uses PUBLISH, REVEAL, NONCE, and TITLE header lines, followed by BODY on its own line. Timestamps use UTC ISO format with milliseconds. The title is a single line; an omitted title leaves the TITLE value empty. Everything after the BODY line is the exact Markdown, preserved without trimming or Unicode normalization. Revealed pages show the exact payload and let you verify its hash. Titles support one line of text, up to 512 UTF-8 bytes.

The hash proves the inputs match. It does not encrypt the message, prove who wrote it, or independently certify the publication timestamp. Markdown rendering is a presentation of the source; external images and raw HTML are disabled.

Privacy & trust

We store your title, source, and nonce in a private Supabase database. Database access rules and the database clock control reveal; changing a browser clock cannot unlock a message. You trust the service operators and hosting providers to protect the stored source before reveal. Do not use this service for passwords, credentials, or material that must remain confidential after the deadline.

GitHub supplies account information for sign-in. Your account identifier links your posts to your dashboard; public pages show your GitHub username and avatar, linked to your public hashes.sh profile, even before reveal. Your email and internal account identifier stay private. Authentication uses cookies. Vercel provides hosting and aggregate site analytics; Supabase provides authentication and storage. Application error messages exclude message source and nonces.

Sharing & retention

Your public profile lists your hashes and publication/reveal times. It never includes sealed titles or message text. Profile and message pages request no search indexing and are not listed in the sitemap. Anyone can visit your profile or share a message link. These are not access controls, and revealed content may be copied permanently.

Published messages cannot be edited or deleted by their authors in this first version. We intend to retain them while the service operates, without guaranteeing indefinite availability. Keep your own copy. We may remove abusive or unlawful content; a removed commitment becomes unavailable and can never be replaced at its old hash. Removal clears active message storage, while provider backups can retain data until their normal expiry.

Limits & abuse

Messages may contain up to 32 KiB of UTF-8 source. Publishing is limited to 10 messages per hour and 100 per day per account. Do not publish unlawful material, private information about others without permission, threats, or harassment. To report a link or request help with account data, contact the maintainer on GitHub and include the commitment URL. Never send sealed source in a public report.