Signed Share Links
Share one private item with someone outside the app, without giving them an account.
What it adds
Signed capability URLs scoped to a single record and a fixed set of actions, with expiry and revocation.
What your agent is told to do
5
What your agent is told to do
5-
1
Generate links as unguessable signed tokens stored server-side, so a link can be revoked without rotating a global secret.
-
2
Scope each token to one record and an explicit action set — view, comment, download — and check that scope on every request the link serves.
-
3
Require an expiry at creation with a sane default, and give the owner a list of live links showing what each grants, when it was made, and when it was last opened.
-
4
Treat anyone holding the link as the intended recipient. That is the security model; state it in the sharing UI so the owner understands what forwarding means.
-
5
Do NOT put the token in a query string that leaks through referrers, server logs, or analytics, and do NOT let a link-holder discover other records by changing an ID in the path.
Edge cases it handles
6
Edge cases it handles
6- An expired or revoked link must show the same neutral page whether or not the record ever existed — leaking that difference is an enumeration hole.
- Link previews from chat apps and mail clients will fetch the URL. Suppress metadata and thumbnails that expose contents to anyone who never opened it.
- Search engines must never index these pages; set noindex and exclude them from sitemaps.
- Deleting the underlying record must invalidate its links rather than serving a stale cached copy.
- Downgrading a link's scope has to take effect immediately for someone who already has the page open.
- Revoking the owner's own access, or deactivating their account, must revoke the links they issued.
Definition of done
8
Definition of done
8- Links are unguessable, signed, stored server-side, and individually revocable.
- Each link is scoped to one record and one action set, enforced on every request.
- Every link has an expiry, and expired or revoked links show an identical neutral state.
- Owners can list, inspect, and revoke their live links.
- Tokens do not appear in referrers, logs, or analytics.
- Shared pages are excluded from search indexing and rich previews.
- The feature matches the existing design system.
- No existing functionality is broken.
Related features
Social Sharing
Social Sharing
Make your links look good when someone posts them.
What it does
Open Graph tags, share buttons, and preview images so shared links don't render as bare URLs.
How it works
- 1 Add Open Graph and Twitter Card tags to every publicly shareable page, with a title, description, and image.
- 2 Generate a preview image per record where it makes sense, rather than one generic image for the whole site.
- 3 Add share actions that use the native share sheet on mobile and copy-link on desktop.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/social-sharing
Share Image Generator
Share Image Generator
Give every shared link a proper preview image instead of a blank card.
What it does
Server-side generation of a per-page preview image, referenced by the page's existing share metadata.
How it works
- 1 Find where the app already sets its share metadata, most likely alongside Social Sharing or Shareable Deep Links, and point the image tag at the generated URL rather than adding a parallel metadata block.
- 2 Generate the image on the server from the record's own title, author, and a brand mark. Do not render it in the visitor's browser; the services that fetch previews do not run scripts.
- 3 Design one template that degrades well, then add variants only where the content type genuinely differs. Three good templates beat a configurable layout engine nobody tunes.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/share-image-generator
Ratings and Reviews
Ratings and Reviews
Show real customer opinion on an item instead of asking buyers to take your word.
What it does
A star rating and written review per item, with a stored aggregate shown alongside the item and a moderation step before publication.
How it works
- 1 Show the aggregate where the item appears: an average, a count, and a breakdown by star level. Read that from a stored aggregate on the item, updated as reviews change, not from an aggregate query over the review table on every page render.
- 2 Decide who is allowed to review and enforce it server-side. Restricting reviews to verified purchasers is the single change that most improves trust and most reduces spam.
- 3 Route new reviews through the app's existing Moderation Queue and reuse AI Text Content Moderation if it is present, rather than adding a second approval inbox. Do not build a parallel review-approval screen.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/ratings-and-reviews
How it works
-
1
Copy the link
Grab the Markdown instruction URL for this feature.
-
2
Give it to your AI
Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.
-
3
It inspects, then implements
Your agent reads your existing app first, then adds the feature to fit it.
Works with your stack
These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.
Need it tighter than that? Customize the feature and tell it exactly what you're running.