Self-hosted · Open source · API-first

The foundation for apps where shared data stays revocable.

Build a client onboarding portal Build a contractor access hub Build a leak-traceable data room Build a self-updating contact card Build a tenant application flow
on living links you control. Revoked stores the data, proves who is asking, and cuts access the instant you say so. Your app is a few API calls on top.

Early software, moving fast. Run it on your own server, break it, tell us what happened.

What you could build on it

Client onboarding

Collect company details and IDs. Answers stream into your CRM, and clients can withdraw them later.

request callback

Contractor access

Hand out server and API credentials. Rotate once and every link follows. Revoke them at offboarding.

link expiry handshake

Data rooms

Share contracts and PDFs stamped per recipient, with a view cap, so a leaked copy names its source.

watermark max views

Living contact card

A vCard that address books subscribe to. Change your number once and every phone updates.

link CardDAV

Tenant applications

Landlords hear from verified applicants, and applicants pull their documents once the flat is gone.

request identity

Emergency card

A QR code in your wallet that always shows your current allergies and contacts, never a stale printout.

link QR

Live status feeds

A script keeps one record current, like an on-call rota or build status. The link always shows the latest.

API key link

Your idea

Anything where someone should get data today and lose it tomorrow. The whole API is public.

See the examples

Once your data is out there, can you ever really revoke it?

Now you can.

The Problem

Scattered & Trapped

You fill out forms. Your data is permanently copied and stored in thousands of vulnerable databases.

You have zero visibility into who holds your data.
Impossible to update everywhere when your info changes.
You can't truly delete it once it's sent.
How Revoked Works

Sovereign & Revocable

You keep the master copy on your own hub. Others hold a link that resolves the current value at read time — and you hold the kill switch. Try it:

Update your info once — every live link serves the new value.
One place to see exactly who has access, right now.
One click to pause or revoke — access dies instantly, and a webhook can tell your systems.
Build on top

You write the product.
Revoked handles the trust.

Storing secrets, gating access, proving identity, revoking on demand: that's the hard part of any app that hands data to other people, and it's the part Revoked already does. The desktop app uses the same public HTTP API you get, with no private endpoints held back.

Your apps
Onboarding portal Data room Status feed Scripts & CI yours…
Revoked building blocks
records links requests identities callbacks workspaces
Your hub

One Go binary under your own domain, with its root key pinned in your DNS.

two calls, one living link
# 1. Rotate the secret. Every link to it is current.
curl -X PATCH \
  "$HUB/api/collections/records/records/$ID" \
  -H "X-API-Key: $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"value":"n3w-s3cret"}'

# 2. Anyone holding the link reads the new value
#    in the format their tooling speaks.
curl "$HUB/s/$SLUG.json"   # .csv .vcf .ics

# Revoke it, and the next read is refused.
Full reference & openapi.yaml in the docs API docs
Features · Built & working

Everything below runs today.

On a self-hosted hub that's one docker compose up away, documented at docs.revoked.link.

Living Links

Links resolve the current value at read time. Rotate a secret and every link to it updates, with nothing to resend.

Pause & Revoke

Access ends on the next read, not the next sync. Pausing can be undone. Revoking is final.

Access Gates

Passwords, expiry dates and view caps, in any combination. View counts are atomic, so concurrent readers can't slip past the cap together.

Requests

Collect data from anyone with a templated form link. Responders answer with living links of their own, and can revoke what they gave you.

Templates

Ready-made blueprints for requests and whole vault setups: onboarding, server access, tenant applications, Wi-Fi and more.

DNS Verification

A hub pins its root key in its own DNS. When someone requests your data, the app walks that chain and shows you, in red or green, who is really asking.

Cryptographic Identities

Keys are generated on your device and never leave it. Links can demand a handshake, so only a viewer who proves their key ever sees the data.

Watermarking

Images and PDFs are stamped per link as they're served. Your original never changes, and a leaked copy shows which link it came through.

Any Format

One link serves JSON, CSV, vCard or iCal, plus CardDAV, so spreadsheets, calendars and address books can subscribe directly.

API & Webhooks

Scoped API keys for automation, and callbacks that push each response to your own endpoint. Documented and hardened against SSRF.

Workspaces

Invite members with precise permissions instead of roles. One person, one hub, many contexts, with personal and organizational side by side.

Audit Log

Every write is recorded, with secret values redacted before the entry is stored.

Self-Hosted

One Go binary, one Docker Compose file, your own domain. Your data never lives on anyone else's infrastructure. That's the whole point.

Desktop Apps

Native builds for Linux and Windows, attached to every release. Deep links open straight into the app, so there's no web page for a phisher to fake.

Embeddable Button

A "Fill with revoked" button for any website. It opens your request in the app, where the server is verified before anyone types.

Honest about alpha

Revoked is young. It works, it's tested, and it still moves fast enough that things change between releases. Don't bet your only copy of anything on it yet.

Where it's heading
  • · Federation — links already name their home hub; cross-hub verification is next
  • · Mobile apps
  • · End-to-end encryption of stored records