Frequently asked questions

Can the server read my pastes?

No. Content is encrypted in your browser before upload. The decryption key is stored in the URL fragment, which is never sent to the server.

What is the URL fragment and why does it matter?

The part after # in a URL is called the fragment. Browsers never send it to the server. This means the decryption key in the link stays between you and whoever you share it with.

What is the difference between open and sealed mode?

Open mode uses X25519 + HKDF-SHA-256 and creates shorter share links. Sealed mode combines ML-KEM-1024 with X25519, so the URL fragment is much larger and best shared by copying the link.

What is burn-after-read?

The paste is permanently deleted from the server the moment it is read. Use this for one-time sharing where the recipient should not be able to reopen the link.

Do I need an account?

No. Nobins works without registration. Create and share pastes instantly.

What happens when a paste expires?

Expired pastes are deleted the next time someone tries to open them. Once deleted, the ciphertext is gone permanently.

Is there a file size limit?

Nobins currently accepts text pastes only and does not enforce a custom app-level size limit. Your browser, network, and database still have practical limits.

Can I password-protect a paste?

Not yet. Current paste links rely on the secret URL fragment as the decryption key.