Rush links · browser to browser
Leave the door open.
A Rush is a link that carries your code. The source lives after the URL’s #, which browsers never send in a request, so sharing a snippet does not mean uploading one. It opens in the other person’s pad and runs there.
- Public, private or password
- Up to 64 KB of source
- No server copy to leak
How a Rush actually travels
The fragment is the whole mechanism.
Press Share in the pad and CodeRush builds a URL whose fragment holds your source. A fragment is client-side by definition: it is not in the request line, not in the server log, not in a bucket. The recipient’s browser gets the link, the pad reads the fragment, and the snippet runs locally.
There are three modes. Public encodes the source so anyone with the link can open it. Private encrypts it with AES-GCM and puts the key in the fragment too, so only the exact link works. Password derives a key from a password you choose with 250,000 rounds of PBKDF2, so the link alone is not enough — send the password separately.
<!doctype html>
<title>Follow your what if</title>
<h1>There's something here.</h1>
<p>Edit this line in the pad, press Run, and the preview follows.</p>
It runs on arrival and is not written into the recipient’s history unless they edit it.
What that design gives you, and what it costs
Both halves, plainly.
What you get: nothing to sign up for, no snippet database to be breached, no dashboard of other people’s code, and a link that still works when the recipient has never heard of CodeRush. A private Rush is unreadable to anyone who does not have the exact URL, including us, because there is nothing of it on our side to read.
What it costs: there is no remote revoke. A link that has been sent cannot be withdrawn, because no server holds the copy that would be deleted. Long sources make long URLs, and the cap is 64 KB — past that, download the file and send it. A Rush is also a snapshot in time; editing your pad afterwards does not change the link you already sent.
Opening a Rush with ?view=preview shows the result first rather than the editor, which is the friendlier shape when you are sending something to look at instead of something to change.
Snapshots, files and the rest of the exits
Sharing is one of four.
Local snapshots keep up to 24 named versions in your browser, pinnable and exportable as one JSON backup you can import on another machine. Download gives you the exact source as a file. The Chrome extension runs code blocks on sites you enable. The local agent service turns source into a PNG or console JSON for scripts.
The privacy notes state each boundary precisely, and the guide shows where Share sits in the workflow.
Questions
- Is my code uploaded when I share a Rush?
- No. The source is carried in the URL fragment, which browsers never include in an HTTP request. There is no server-side copy of a Rush.
- Can I delete a Rush link after sending it?
- No, and the page says so rather than implying otherwise: there is no server file to delete. Treat a sent link as sent.
- What is the difference between private and password mode?
- A private Rush is encrypted with a random key carried in the same link, so the exact URL is the secret. A password Rush derives the key from a password you send separately.
- How much code fits in a link?
- Up to 64 KB of source. Past that, download the file and share it another way.