dead-drop API v1 (1.0.0)

Download OpenAPI specification:

Privacy-focused, ephemeral data-sharing API v1

Drops

Drop CRUD operations

Generate a random unused drop name

Generates a random 4-word drop name using the EFF Diceware wordlist and ensures it is not already in use.

Responses

Response samples

Content type
application/json
{
  • "name": "abacus-abide-ablaze-able",
  • "id": "7c4e8d3a9f1b6e2c8d4a7f3b9e1c5d8a2f6b4e9d3c7a1f8b5e2d9c4a6f3b7e1d"
}

Check if a drop name is available

Check if a drop with the given ID exists. Returns 200 with availability status regardless of whether the drop exists.

path Parameters
id
required
string

SHA-256 hash of the drop name

Responses

Response samples

Content type
application/json
{
  • "id": "7c4e8d3a9f1b6e2c8d4a7f3b9e1c5d8a2f6b4e9d3c7a1f8b5e2d9c4a6f3b7e1d",
  • "available": true
}

Retrieve a drop

Get the current version of a drop by its ID.

path Parameters
id
required
string

SHA-256 hash of the drop name

query Parameters
I_agree_with_terms_and_conditions
required
boolean

Must be true to confirm agreement to terms and conditions

Responses

Response samples

Content type
application/json
{
  • "id": "7c4e8d3a9f1b6e2c8d4a7f3b9e1c5d8a2f6b4e9d3c7a1f8b5e2d9c4a6f3b7e1d",
  • "tier": "free",
  • "visibility": "private",
  • "payload": "string",
  • "salt": "a1b2c3d4e5f6789012345678abcdef01",
  • "iv": "00112233445566778899aabb",
  • "encryptionAlgo": "pbkdf2-aes256-gcm-v1",
  • "encryptionParams": {
    },
  • "mimeType": "text/plain",
  • "hashAlgo": "sha-256",
  • "expiresAt": "2026-04-25T12:00:00.000Z"
}

Update a drop

Update an existing drop. Authentication is required.

path Parameters
id
required
string

SHA-256 hash of the drop name

Request Body schema: application/json
payload
required
string

For private drops: hex-encoded AES-GCM ciphertext. For public drops: raw content string, interpreted by mimeType.

iv
string <hex> ^[a-f0-9]{24}$

Hex-encoded IV (12 bytes = 24 hex chars), required for private drops

mimeType
string
Value: "text/plain"

MIME type

contentHash
string <hex> ^[a-f0-9]{64}$

SHA-256 hash of OLD content payload JSON, required for private drops

newContentHash
string <hex> ^[a-f0-9]{64}$

SHA-256 hash of NEW content payload JSON, required for private drops

adminPassword
string non-empty

Admin password for authentication, required for public drops

I_agree_with_terms_and_conditions
required
boolean

Must be true to confirm agreement to terms and conditions. See https://dead-drop.xyz/terms

Responses

Request samples

Content type
application/json
{
  • "payload": "Hello, world!",
  • "iv": "00112233445566778899aabb",
  • "mimeType": "text/plain",
  • "contentHash": "7c4e8d3a9f1b6e2c8d4a7f3b9e1c5d8a2f6b4e9d3c7a1f8b5e2d9c4a6f3b7e1d",
  • "newContentHash": "7c4e8d3a9f1b6e2c8d4a7f3b9e1c5d8a2f6b4e9d3c7a1f8b5e2d9c4a6f3b7e1d",
  • "adminPassword": "my-secret-admin-password",
  • "I_agree_with_terms_and_conditions": true
}

Response samples

Content type
application/json
{
  • "success": true,
  • "version": 1
}

Delete a drop

Delete a drop permanently. Authentication is required.

path Parameters
id
required
string

SHA-256 hash of the drop name

Request Body schema: application/json
contentHash
string <hex> ^[a-f0-9]{64}$

SHA-256 hash of content payload JSON, required for private drops

adminPassword
string non-empty

Admin password for authentication, required for public drops

I_agree_with_terms_and_conditions
required
boolean

Must be true to confirm agreement to terms and conditions. See https://dead-drop.xyz/terms

Responses

Request samples

Content type
application/json
{
  • "contentHash": "7c4e8d3a9f1b6e2c8d4a7f3b9e1c5d8a2f6b4e9d3c7a1f8b5e2d9c4a6f3b7e1d",
  • "adminPassword": "my-secret-admin-password",
  • "I_agree_with_terms_and_conditions": true
}

Response samples

Content type
application/json
{
  • "success": true
}

Create a new drop

Create a new drop with the given parameters. The drop name must not already exist. For private drops, the payload must be encrypted.

Request Body schema: application/json
id
required
string <hex> ^[a-f0-9]{64}$

SHA-256 hash of normalized drop name

nameLength
required
integer >= 3

Length of normalized name for validation (min 3 for Deep, 12 for Free)

tier
string
Enum: "free" "deep"

Drop tier, defaults to free

visibility
required
string
Enum: "private" "public"

Drop visibility type

payload
required
string

For private drops: hex-encoded AES-GCM ciphertext. For public drops: raw content string, interpreted by mimeType.

salt
required
string <hex> ^[a-f0-9]{32}$

Hex-encoded salt (16 bytes = 32 hex characters)

iv
string <hex> ^[a-f0-9]{24}$

Hex-encoded IV (12 bytes = 24 hex chars), required for private drops

encryptionAlgo
string
Value: "pbkdf2-aes256-gcm-v1"

Encryption algorithm, defaults to pbkdf2-aes256-gcm-v1 for private drops

object

Encryption parameters (JSON object)

mimeType
string
Value: "text/plain"

MIME type, defaults to text/plain

hashAlgo
string
Value: "sha-256"

Hash algorithm for admin authentication, defaults to sha-256 (v1.1+)

contentHash
string <hex> ^[a-f0-9]{64}$

SHA-256 hash of content payload JSON, required for private drops

adminHash
string <hex> ^[a-f0-9]{64}$

SHA-256(adminPassword + salt), required for public drops

I_agree_with_terms_and_conditions
required
boolean

Must be true to confirm agreement to terms and conditions. See https://dead-drop.xyz/terms

Responses

Request samples

Content type
application/json
{
  • "id": "7c4e8d3a9f1b6e2c8d4a7f3b9e1c5d8a2f6b4e9d3c7a1f8b5e2d9c4a6f3b7e1d",
  • "nameLength": 12,
  • "tier": "free",
  • "visibility": "private",
  • "payload": "Hello, world!",
  • "salt": "a1b2c3d4e5f6789012345678abcdef01",
  • "iv": "00112233445566778899aabb",
  • "encryptionAlgo": "pbkdf2-aes256-gcm-v1",
  • "encryptionParams": {
    },
  • "mimeType": "text/plain",
  • "hashAlgo": "sha-256",
  • "contentHash": "7c4e8d3a9f1b6e2c8d4a7f3b9e1c5d8a2f6b4e9d3c7a1f8b5e2d9c4a6f3b7e1d",
  • "adminHash": "7c4e8d3a9f1b6e2c8d4a7f3b9e1c5d8a2f6b4e9d3c7a1f8b5e2d9c4a6f3b7e1d",
  • "I_agree_with_terms_and_conditions": true
}

Response samples

Content type
application/json
{
  • "success": true,
  • "version": 1,
  • "tier": "free"
}

History

Drop version history

List drop history

Get a list of all versions of a drop.

path Parameters
id
required
string

SHA-256 hash of the drop name

query Parameters
I_agree_with_terms_and_conditions
required
boolean

Must be true to confirm agreement to terms and conditions

Responses

Response samples

Content type
application/json
{
  • "versions": [
    ],
  • "current": 3,
  • "maxVersions": 10
}

Get specific drop version

Get a specific version of a drop.

path Parameters
id
required
string

SHA-256 hash of the drop name

version
required
integer >= 1

Version number

query Parameters
I_agree_with_terms_and_conditions
required
boolean

Must be true to confirm agreement to terms and conditions

Responses

Response samples

Content type
application/json
{
  • "version": 2,
  • "payload": "string",
  • "iv": "00112233445566778899aabb",
  • "createdAt": "2026-04-18T10:30:00.000Z"
}

Health

Health check endpoints

Health check

Returns the health status of the API

Responses

Response samples

Content type
application/json
{
  • "status": "ok",
  • "timestamp": "2026-04-18T12:00:00.000Z"
}

Documentation

OpenAPI specification

Returns the OpenAPI 3.1 specification for the v1 API

Responses

Response samples

Content type
application/json
{
  • "property1": null,
  • "property2": null
}

Swagger UI

Interactive API documentation using Swagger UI

Responses