v1.0Open source · MIT · Self-hosted

Share files with exactly the people you choose.

Gatekeep is open-source file sharing you run yourself. Every recipient gets their own password, links expire on your schedule, and every unlock attempt is on the record.

dl.example.com/admin
Gatekeep dashboard listing uploaded files, folders and their share links

Q3-board-report.pdf

4.2 MB · PDF

Unlocked
dl.example.com/aB3xY9
Expires
in 7 days
Downloads
2 of 5
Mmaya@acme.co own password
Built onNext.js 16SupabasePostgres RLSVercelDockerTypeScript

Features

Everything a private link should have.

Public links leak and shared drives want everyone to sign up. Gatekeep sits in between: you own the storage, and every person gets their own key.

A password for every recipient

Grant access by email or username — one at a time or a whole list in bulk — or create a public link that only needs a password.

  • Mmaya@acme.coExpires in 7 days
  • Jj.chen2 of 5 downloads
  • *Anyone with the linkPassword only

Links you can read aloud

Every file gets a six-character code on your own domain.

dl.example.com/

aB3xY9

56.8 billion possible codes

Expiry & download limits

Let access lapse after an hour, a week or a date you pick, and cap how many downloads a grant gets.

2 of 5 downloads

Expires in 6 days

Revoke in real time

Remove a grant and a recipient who has the file open is signed out on the spot.

j.chenAccess revoked

Their open session ends immediately

Preview without downloading

Images, video, audio, PDFs, code and Office documents open right in the browser.

.pdf.png.jpg.mp4.mp3.docx.xlsx.pptx.ts.json.md.csv

An audit log with reasons

Every unlock attempt — granted or denied — is recorded with its reason, IP and time. Analytics rank your most-opened files; download counts sit on each grant.

maya@acme.counlocked2m ago
203.0.113.7wrong_password9m ago
j.chenexpired1h ago
publicunlocked3h ago

Folders, bulk grants & email

Organise uploads into nested folders, grant a whole list at once, and optionally email people when they’re given access (via Resend).

Clients

└ Acme

└ Contracts

Access granted

“You can now open Q3-board-report.pdf”

How it works

From upload to unlocked in three steps.

Step 01

Upload straight to your bucket

Drag in files or whole folders. The browser uploads directly to your private Supabase Storage with presigned URLs, and each file gets its short link immediately.

Drop files or folders

Up to 100 MB each · straight to your bucket

  • contract-final.pdf1.8 MB

    dl.example.com/k9Tq2W

  • site-photos.zip86 MB
  • launch-video.mp442 MB
Step 02

Decide who gets in

Add recipients with their own password, set an expiry and a download cap, or create a password-only public link. Change or revoke any of it later.

dl.example.com/admin/access
Access manager listing recipients with their expiry and download limits
Step 03

Send the link. They unlock it.

Recipients open the short link, enter their password and preview or download — no account, no app. Their session lasts 24 hours and ends the moment you revoke it.

dl.example.com/aB3xY9
Share page asking the recipient for their email and password
dl.example.com/aB3xY9
Unlocked share page previewing the file in the browser

Security

Locked down by default.

No setting to forget. Every grant is re-checked on the server before a single byte leaves storage.

  • Row-level security on every table

    Postgres policies scope every row to its owner. The service-role key never reaches the browser.

  • Passwords are bcrypt-hashed

    Recipient passwords are never stored or returned in plain text — not even to you.

  • Hashed, httpOnly sessions

    Unlocking issues a random token, stored hashed and sent as an httpOnly, SameSite=Strict cookie.

  • Brute-force throttling

    20 failed attempts per IP and 100 per file every 15 minutes, counted in the database so the limit holds across serverless instances.

  • Short-lived signed URLs

    Files sit in a private bucket and only leave it through signed URLs issued after the grant is re-checked.

  • Strict headers

    Content-Security-Policy, HSTS, frame denial and a locked-down permissions policy on every response.

dl.example.com/admin
Analytics dashboard with views, downloads and the access log including denied attempts

Denied attempts are logged with their reason — wrong password, expired, limit reached.

Self-host

Your server. Your bucket. Your rules.

Bring a free Supabase project and run Gatekeep on Vercel or any machine with Docker. Setup takes about ten minutes.

Vercel

Recommended · one click

  1. 1Create a free Supabase project
  2. 2Apply the schema with npx supabase db push
  3. 3Click deploy and paste your keys
  4. 4Create your login with npm run create-admin

Docker

Any server · keep-alive sidecar included

$ git clone https://github.com/omsingh02/gatekeep
$ cd gatekeep && cp .env.example .env
$ docker compose up -d --build
✓ gatekeep is running on :3000

Health endpoint

/api/health for your uptime monitor.

Stays awake

A daily job keeps free Supabase projects from pausing.

MIT licensed

Use it, fork it, ship it — commercially too.

FAQ

Questions, answered.

Do recipients need an account?

No. You add a recipient by email or username and give them a password — or create a public, password-only link. They open the short link, enter it, and that’s it.

Where are my files stored?

In a private Storage bucket in your own Supabase project. Uploads go straight to the bucket with presigned URLs and downloads use short-lived signed URLs. One thing to know: Office documents (Word, Excel, PowerPoint) are previewed with Microsoft’s online viewer, which fetches the file through a signed link.

Can I take access away after sharing?

Yes. Revoke a grant and it stops working immediately — a named recipient who has the file open is signed out in real time. Grants can also expire on a date or after a number of downloads.

What does it cost to run?

Gatekeep is MIT-licensed and free, and it runs on Supabase’s and Vercel’s free tiers. A daily keep-alive job stops a free Supabase project from pausing. Check your Supabase plan’s storage and upload-size limits — Gatekeep accepts files up to 100 MB.

Can I use my own domain?

Yes. Set NEXT_PUBLIC_APP_URL to your domain and every share link is generated on it, e.g. files.yourcompany.com/aB3xY9.

How do I know it’s working?

Point any uptime monitor at /api/health — it returns 200 when the app can reach the database and 503 when it can’t. Every unlock attempt, granted or denied, is in the audit log with its reason.

Gatekeep

Own your file sharing.

Free, open source and yours to run. Deploy in minutes — or read the code first.