Your files. Under control.
Manage uploads, access links and encryption.
Sign in
File activity
New server-encrypted and browser-to-server uploads decrypt automatically on download. Blindfolded and legacy age files need the offline private key. Administrator downloads, deletion, link creation, settings and key changes require fresh verification. Verification remains valid for two minutes.
| File | Owner / token creator | Protection | State / integrity | Received | Actions |
|---|
Create an upload link
Upload links work in token-only and token-free modes. Files uploaded through a user-created link are visible and downloadable only by that user and the administrator. Sharing the link permits uploads, not downloads. Anonymous and administrator-created uploads are visible only to the administrator. Standard administrator links require session and CSRF; elevated links require fresh TOTP. User links require password verification. User links last at most 24 hours and permit at most ten uploads. A token controls access; file encryption is a separate choice.
Storage and notifications
Storage values use gigabytes (GB; 1 GB = 1,000,000,000 bytes), rounded to the nearest whole number. Quota usage includes outstanding uploads and conservative encryption reservations. Filesystem usage includes other data on each filesystem; shared filesystems appear more than once and must not be added together.
Upload policy
Start with the access mode, then choose the upload clients and encryption options. Blindfolded uploads also require a public key on the Encryption keys tab.
Anonymous unencrypted uploads are enabled. Anyone can upload files stored without file encryption. Access control and encrypted host storage are the only protection at rest; keep retention short and encrypt backups or exclude this volume.
Encryption keys
The database file master key and server private key are encrypted with the Docker wrapping secret. Their public status is shown below; private keys are never returned to this page.
Blindfolded uploads
Generate a key pair on the machine that will decrypt files. Keep private-key.txt there. Send only the public key to this server.
Replacing the public key affects new uploads. Keep every old private key needed to decrypt existing files.
Install age and use Python 3 on the computer that holds your private key. Put the downloaded .age file anywhere on your own computer, for example your Downloads folder. Replace /path/to/filedrop/filedrop/unpack.py with the full path to the standalone script downloaded using the link above. Replace downloaded.age with your encrypted file path. Run the Python command once: it calls age, decrypts privately and restores the original filename under restored/ in your current directory. It uses private-key.txt in that directory by default; add --identity "/path/to/private-key.txt" for a key elsewhere and --output-directory "/path/to/restored" to choose the output folder. Quote paths containing spaces. For direct execution of the updated downloaded helper, run chmod +x unpack.py once, then ./unpack.py downloaded.age. Browser downloads do not preserve executable permissions. No FileDrop package or server dependencies are needed. Already decrypted FileDrop envelopes are also accepted. Keep your private key offline; do not upload it.
Users
Users can view and download stored files. They can change their own password and choose to enable TOTP. Only administrators can manage users and system settings.
| Username | Status | TOTP | Reserved / quota | Actions |
|---|
Email configuration
Configure SMTP to send welcome, password reset, upload notification, storage threshold and failed-login alert emails. Failed-login alerts go to the administrator email address set above. You can always copy a link for manual delivery.
My account
Audit trail
| Time | Action | Severity | Object / attempted username | Actor | Source address |
|---|
Set your password
This welcome or reset link can be used once. After saving, sign in with your username and new password.