Signed Share Links
Share one private item with someone outside the app, without giving them an account.
What it adds
Signed capability URLs scoped to a single record and a fixed set of actions, with expiry and revocation.
What your agent is told to do
5
What your agent is told to do
5-
1
Generate links as unguessable signed tokens stored server-side, so a link can be revoked without rotating a global secret.
-
2
Scope each token to one record and an explicit action set — view, comment, download — and check that scope on every request the link serves.
-
3
Require an expiry at creation with a sane default, and give the owner a list of live links showing what each grants, when it was made, and when it was last opened.
-
4
Treat anyone holding the link as the intended recipient. That is the security model; state it in the sharing UI so the owner understands what forwarding means.
-
5
Do NOT put the token in a query string that leaks through referrers, server logs, or analytics, and do NOT let a link-holder discover other records by changing an ID in the path.
Edge cases it handles
6
Edge cases it handles
6- An expired or revoked link must show the same neutral page whether or not the record ever existed — leaking that difference is an enumeration hole.
- Link previews from chat apps and mail clients will fetch the URL. Suppress metadata and thumbnails that expose contents to anyone who never opened it.
- Search engines must never index these pages; set noindex and exclude them from sitemaps.
- Deleting the underlying record must invalidate its links rather than serving a stale cached copy.
- Downgrading a link's scope has to take effect immediately for someone who already has the page open.
- Revoking the owner's own access, or deactivating their account, must revoke the links they issued.
Definition of done
8
Definition of done
8- Links are unguessable, signed, stored server-side, and individually revocable.
- Each link is scoped to one record and one action set, enforced on every request.
- Every link has an expiry, and expired or revoked links show an identical neutral state.
- Owners can list, inspect, and revoke their live links.
- Tokens do not appear in referrers, logs, or analytics.
- Shared pages are excluded from search indexing and rich previews.
- The feature matches the existing design system.
- No existing functionality is broken.
Related features
Digital Business Card
Digital Business Card
Give every member a shareable card page with their photo, links, and save-to-contacts.
What it does
A per-member public card page with photo, role, links, and a download that imports into a phone's contacts.
How it works
- 1 Build this as a presentation of the app's existing Public Profile Pages, not a second profile. One record, two layouts. A member who updates their title should not have to update it twice.
- 2 Take the photo from Avatar Upload rather than adding a new image field, and reuse the crop and compression the app already applies so a card photo is not a full-resolution original served to every visitor.
- 3 Give each card a save-to-contacts download containing the fields the member has chosen to publish, and nothing else. Everything on the card and nothing beyond it.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/digital-business-card
Share Image Generator
Share Image Generator
Give every shared link a proper preview image instead of a blank card.
What it does
Server-side generation of a per-page preview image, referenced by the page's existing share metadata.
How it works
- 1 Find where the app already sets its share metadata, most likely alongside Social Sharing or Shareable Deep Links, and point the image tag at the generated URL rather than adding a parallel metadata block.
- 2 Generate the image on the server from the record's own title, author, and a brand mark. Do not render it in the visitor's browser; the services that fetch previews do not run scripts.
- 3 Design one template that degrades well, then add variants only where the content type genuinely differs. Three good templates beat a configurable layout engine nobody tunes.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/share-image-generator
Highlight Clip Maker
Highlight Clip Maker
Turn a selected passage of a transcript into a short clip that can be shared.
What it does
Selection of transcript lines that renders a trimmed, captioned clip of the source media with a shareable link.
How it works
- 1 Build the selection on top of the app's interactive transcript. The user selects a run of lines, sees the resulting start and end time and duration, and adjusts the edges before rendering.
- 2 Render clips through the app's existing background job system so the user is not held on a progress bar, and notify them through the existing notification centre when the clip is ready or has failed.
- 3 Burn the transcript text into the clip as captions, since most places a clip is shared autoplay it silently. Give the user a way to turn captions off before rendering.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/highlight-clip-maker
How it works
-
1
Copy the link
Grab the Markdown instruction URL for this feature.
-
2
Give it to your AI
Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.
-
3
It inspects, then implements
Your agent reads your existing app first, then adds the feature to fit it.
Works with your stack
These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.
Need it tighter than that? Customize the feature and tell it exactly what you're running.