Links and URLs
Links are immutable account-owned mappings from an eight-character short code to an HTTP or HTTPS destination.
Accepted destinations
Section titled “Accepted destinations”POST /api/v1/links accepts one required url field. The value must:
- be valid UTF-8;
- be no longer than 4096 UTF-8 bytes;
- be an absolute
httporhttpsURL; - include a hostname; and
- contain no username or password information.
Surrounding whitespace is removed before the value is stored. The remaining
spelling—including hostname casing and an explicit default port—is preserved in
target_url and used in the redirect’s Location header.
Duplicate detection
Section titled “Duplicate detection”The service derives a separate canonical comparison key. It:
- lowercases the scheme and hostname;
- removes port
80from HTTP URLs and port443from HTTPS URLs; and - treats an empty path as
/.
It preserves path casing, query parameter order, query values, and fragments. Consequently, these are duplicates for the same account:
https://Example.com:443https://example.com/These are distinct because canonicalization does not reorder the query:
https://example.com/?a=1&b=2https://example.com/?b=2&a=1Duplicate detection is per account. Different accounts may shorten the same destination.
Short codes
Section titled “Short codes”Codes contain exactly eight case-sensitive characters from this Base62 set:
0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyzCodes are generated with cryptographic randomness and are unique across the
service. A code is not a Sonyflake and must not be substituted for the link
id in delete requests.
Limits and ordering
Section titled “Limits and ordering”- An account may own at most 50 links.
- Links cannot be edited. Delete and recreate a link to change its destination.
GET /api/v1/linksreturns every owned link with no pagination.- Results are sorted by
created_atdescending and theniddescending. - Deleting another account’s link returns
404 LINK_NOT_FOUND.
Public redirects
Section titled “Public redirects”GET /r/{code} requires no authentication. A known code returns HTTP 302
with the stored destination in Location; an unknown code returns the normal
JSON 404 LINK_NOT_FOUND envelope.