Docs

Share one live team view without a seat

A Share link gives anyone holding its URL one live, read-only team view without an account. An owner or admin chooses Team activity or AI share of merged work, may narrow it to one repository, may set an expiry, and can revoke it. The token in the URL is the credential.

For: the owner or admin who needs to show a bounded team result to someone outside the dashboard

What it does, and why it helps

The create form writes one row with a 24-byte random URL-safe token, an optional label, one view, a stored window key, an optional repository key and an optional expiry. Team activity is the default. It shows developer names, Sessions, Active hours, Tokens and Spend for the chosen window. AI share of merged work shows Merged units, AI share and the evidence tiers Attested, Co-authored, Classified, Human and Unattributed. It reads each repository's freshest published snapshot, so the link's Window does not apply to that view.

The public page has no sign-in gate. It resolves the team from the token row, checks revocation and expiry on every uncached open, rejects an unknown view, and resolves the personal-repository deny-list before either data read. An unscoped AI-share link reports a repository count but withholds repository names and developer identities. A repository-scoped AI-share link names that one repository. Team activity names only developers whose narrowed row still has activity.

The pain. A screenshot freezes too early, while a dashboard login grants an ongoing seat and more views than the recipient needs. A broad export can carry fields that were never part of the question.

The point of view. Treat a share URL as a credential, not as a picture. Give it one view, the smallest repository scope and a useful lifetime, then revoke it when the question ends.

What gets easier. Showing a contractor review, a spend window or an aggregate AI-share figure without creating an account. The manager page keeps the URL, label, view, window, status and revoke action together.

When it helps. When a finance partner, customer, contractor or executive needs a live read-only answer but should not enter the hosted dashboard. Use a scoped link when a repository name or one repository's activity is part of the answer.

Its limits. The link is bearer access: forwarding the URL forwards the view. It is live, not a frozen snapshot. It has no recipient identity, password, access log, download control or view-count limit. Revoke and expiry stop later opens but do not retract data someone already read or copied.

Understand it in 30 seconds

30.1 s, captions on. Narration: Microsoft Zira Desktop (provisional voice; an approved narration source is pending).Transcript
Read the narration
  1. 0:00 A dashboard screenshot goes stale quickly. A broad login grants too much.
  2. 0:06 A share link is a credential, not a screenshot or a seat.
  3. 0:13 It binds one live view, an optional repository and an expiry.
  4. 0:17 Every open checks the personal-repository deny-list first.
  5. 0:23 Share the narrowest link, then revoke it promptly when the question ends.

Synthetic example. Read the guide

Where to find it

  • Hosted: repoops.ai/team/share, from Team & settings in the sidebar, then Share links under Account and access.
  • Desktop: hosted only.

When to use it

Share one contractor's repository window

Situation. A customer should see work and spend for one repository over the last 30 days, without seeing another client's repository or receiving a dashboard seat.

What you do. Enter a neutral Label, choose Team activity, keep Window at 30 days, choose the repository, set Expires to 7 days, and press Create link. Copy the generated URL.

What you see. The public chip reads Read-only shared view, Team activity, 30 days and the repository key. The cards show Developers, Sessions, Active hours, Tokens and Spend. The table includes only developers with nonzero narrowed activity.

What it establishes. The recipient gets the selected live rollup without an account. The status row stays active until the exact expiry instant or a manager presses Revoke.

Share an aggregate AI contribution figure

Situation. An executive needs the team's current AI share by evidence tier, but repository names and developer identities are outside the request.

What you do. Choose AI share of merged work, leave Repo at All, choose an expiry, and create the link. The Window choice is stored but does not narrow this view.

What you see. The public view shows Merged units, AI share, Repos and the five evidence-tier rows. Its copy says the freshest snapshot per repository is used. The page does not print the stored window or any repository name.

What it establishes. The recipient sees the aggregate and the evidence mix. A zero total reads n/a, not 0 percent, because the ratio is not assessable from an empty denominator.

Pull back an exposed URL

Situation. A share URL reached the wrong channel or the review has ended before its expiry.

What you do. Find the active row on Share links and press Revoke.

What you see. The row changes to revoked and loses the Revoke button. The next open of the public URL says This share link has been revoked. The viewer is force-dynamic, so it rechecks the row instead of serving cached HTML.

What it establishes. Later requests receive no team view. The row and its raw token remain in the database, and the audit log records share_link.revoke.

Before you start

Supported versions
RepoOps hosted v0.3.1, the release this guide was read against. The desktop app has no row for it; links are managed on repoops.ai.
Where it runs
Management runs at repoops.ai/team/share, Share links under Team & settings, and is hosted only. Public reads run at /share/<token> without an account and carry robots noindex. There is no public/share-links.html desktop tab.
Permissions
A signed-in owner or admin may create, list, copy and revoke links. The server actions repeat the membership and manager check. Anyone with a valid active token may open its public view. The public page takes the team id only from the stored link row, never from the request.
Connections
Team activity needs telemetry already streamed to the hosted team. AI share needs a published team AI-share snapshot. Repository choices combine both sources and omit repositories currently marked personal.
Plan
The manager page inherits the hosted dashboard's active-subscription and paid-seat gate. It has no separate Team-tier check in its page or write actions, despite the pricing catalog assigning Read-only share links to Team. The public viewer does not recheck subscription state after a link exists.

Configure it

  1. Decide what the recipient needs to answer.

    Choose Team activity for developer names, sessions, active time, tokens and spend over a window. Choose AI share of merged work for aggregate evidence tiers from the freshest snapshot per repository.

  2. Narrow before minting the credential.

    Choose one repository when the question allows it. The option list is the union of telemetry and AI-share repositories, minus personal repositories. All is wider and, for AI share, deliberately hides repository names.

  3. Choose a lifetime and a safe label.

    Expires offers Never, 7 days, 30 days or 90 days. The optional label becomes the public page heading, so do not put a secret in it.

  4. Open the URL before sending it.

    Check the public chip, cards and table without relying on the manager form. For AI share, confirm that the Window is absent because it did not run. For a scoped link, confirm only the intended repository is named.

  5. Revoke when the review ends.

    Revoke sets revokedAt and the next open shows a neutral unavailable notice. The row stays in the manager list as evidence rather than being deleted.

SettingWhereA sensible choiceWhy it matters
LabelCreate link formA short purpose such as Q1 contractor review, with no private detailThe server truncates it to 200 characters and the public page uses it as the heading. Blank falls back to the view name.
ViewCreate link formTeam activity for a windowed developer rollup, or AI share of merged work for an aggregate evidence viewOne token carries one view. Unknown stored views fail closed instead of falling back to another view.
WindowCreate link form7 days, 30 days (the default), 90 days, 1 year or All timeIt narrows Team activity by server received time. The AI-share row later reads n/a because this setting does not filter snapshots.
RepoCreate link form, when a shareable repository existsOne repository for the narrowest link, or All only when the aggregate is the taskA scoped activity link filters the rollup. A scoped AI-share link may name that repository; an All link withholds all repository names.
ExpiresCreate link form7 days for a short review; Never only for an intentional standing linkChoices are Never, 7 days, 30 days and 90 days. Expiry at or before the current instant is invalid.
Create linkCreate link formPress once after checking view, repo and expiryIt writes the token row and share_link.create audit event. The URL is bearer access and has no second confirmation.
Copy linkLink columnCopy only the intended active rowThe full URL contains the raw credential. The list also keeps expired and revoked rows, so check Status before sending.
RevokeActive link rowUse as soon as a review ends or a URL is misplacedRevocation is team-scoped and idempotent. It takes effect on the next uncached open and writes share_link.revoke.
ⓘ
To stop or undo
Press Revoke on each active row you need to stop. Waiting for expiry also stops a link, but Never has no clock. There is no bulk revoke, token rotation or edit action. To change view, repository, window, label or expiry, create a replacement link and revoke the old one.

What you should see

An active Team activity link

Configuration. View Team activity, Window 30 days, one repository, Expires 7 days.

Expect. The public heading uses the label or Team activity. Five cards show Developers, Sessions, Active hours, Tokens and Spend, followed by one per-developer row for narrowed nonzero activity.

Verify. The chip names Team activity, 30 days and the repository. Compare the totals with the hosted Activity view on the same window and repository, while remembering the public view also excludes personal repositories.

An unscoped AI-share link

Configuration. View AI share of merged work, Repo All, with at least one published snapshot.

Expect. Merged units, AI share and Repos summarize the freshest snapshot per repository. The evidence table shows Attested, Co-authored, Classified, Human and Unattributed. No repository or developer name appears.

Verify. The page says the link's window does not apply. The evidence shares are recomputed from summed counts, and an empty denominator renders n/a.

A link that can no longer be served

Configuration. Revoked, expired, unknown view, newly personal repository, or a deny-list read that fails.

Expect. Shared view unavailable appears with a neutral reason and no rollup. A missing token does not reveal whether a team exists.

Verify. Reopen the URL after the state change. The manager row distinguishes revoked from expired; an unknown view or scope-read failure is visible only as unavailable on the public page.

Data and cost

What is captured
One share_links row per URL: team id, creator id, raw token, view scope, window key, optional repository key, optional label, created time, optional expiry and optional revoked time. Team activity reads live telemetry rows. AI share reads the freshest stored snapshot per repository and folds counts at request time.
Who can see it
Anyone holding the URL can read its live view without an account. Team activity exposes developer display names or user ids plus sessions, active hours, tokens and spend. AI share exposes aggregate merged units and evidence tiers; it omits developer identities and, unless scoped to one repository, repository names. Personal repositories are excluded before either view reads data.
How long it is kept
A link with Never remains valid until revoked or its team is deleted. Expiry and revoke do not delete the row or raw token. Not provided: no cleanup schedule, retention setting or hard-delete action exists for share_links. The underlying telemetry and AI-share snapshot stores have their own lifecycles, so the live result may change while the URL remains valid.
What leaves the machine
RepoOps sends nothing when a link is created or copied. The manager distributes the URL through a channel of their choice. Each recipient request sends the token in the path to RepoOps and receives the selected hosted data. No model is called.
What it costs
No model cost. Creating, opening and revoking a link use hosted database reads and writes. The displayed Spend is captured team activity, not the cost of serving the link.

When the result differs

SymptomLikely causeNext action
No Repo control appears.Neither telemetry nor AI-share snapshots expose a shareable repository after personal repositories are removed.Stream Team activity or publish an AI-share snapshot for a non-personal repository, then return to the form.
An AI-share link ignores the selected Window.That view is not windowed. It reads the freshest published snapshot per repository, whose payload carries its own period.Read the period on the source snapshot. Use Team activity when the public question requires one of the Window presets.
The public page says no repo has published a snapshot.No AI-share snapshot exists after the optional repository and personal deny-list filters.Confirm AI-share publishing for that repository and that the repository is not marked personal.
The public page says the repository is no longer shared.The link targets a repository that was marked personal after creation.Keep it personal. Create a new link for a different shareable repository if the recipient still needs a view.
The public page is temporarily unavailable.The strict personal-repository scope read failed, so the anonymous viewer refused to assume that every repository was shareable.Retry after the database or migration issue is fixed. Do not bypass the strict guard.
The row is active but the recipient sees an expired notice.The request crossed the expiry instant after the manager page rendered, or the manager list is stale.Reload the manager page. Create a replacement with the intended expiry if access should continue.
Disable
Press Revoke. The public route is force-dynamic and runs the validity check on the next open. A plan downgrade does not disable an existing link because the public viewer has no subscription check.
Roll back
Not provided. A link row cannot be edited or restored after revoke. Create a new URL with the former settings and distribute it, then leave the old row revoked.
Revoke access
Press Revoke on one active row. Not provided for bulk revoke or token rotation. Revocation marks the row rather than deleting it, and the raw URL token remains stored with that row.
Delete
Not provided. There is no hard-delete action for an individual link. The share_links row belongs to the team and cascades only when the team row is deleted. Revoked and expired rows remain listed for status and audit context.

Maintenance evidence

Feature id
share-links (spine leaf share-links)
Owner
Phase 6 read-only share links, with A0828 view and personal-repository hardening and LDG-0490 repository-option repair. Guide: LDG-0717.
Supported product version
RepoOps v0.3.1
Last verified
2026-09-15, read against origin/main at 52366bb6d; labels read from the served tab source in website/app/team/(home)/share/page.tsx and website/app/(marketing)/share/[token]/page.tsx, with the desktop pointer in lib/canonical-tabs.mjs.
Example fixtures
No fixture file. website/lib/share-links.test.ts covers revoke and expiry validity plus unknown-scope refusal; share-scopes.test.ts covers the view vocabulary and window rule; share-repo-options.test.ts covers the source union, personal exclusion and empty-key encoding; share-repo-guard.test.ts covers fail-closed scope reads; website/app/(marketing)/share/[token]/share-viewer.test.ts pins cache, view, team, deny-list and noindex behavior; ai-share-snapshot-read.integration.test.ts covers freshest-per-repo reads and team scope.
Source references
lib/canonical-spine.json, lib/canonical-tabs.mjs, website/app/team/(home)/share/page.tsx, website/app/team/(home)/layout.tsx, website/lib/share-links.ts, website/lib/share-scopes.ts, website/lib/share-repo-options.ts, website/lib/share-repo-guard.ts, website/app/(marketing)/share/[token]/page.tsx, website/lib/team-activity.ts, website/lib/activity-format.ts, website/lib/ai-share-snapshot-read.ts
Documentation review
Independent review requested on the slice pull request; not yet recorded.
Video review
Narrated story rendered and published 2026-09-26 (render b278dd87bcb2, LDG-1012) with the breadcrumb Team & settings, checked against main at b0bb02812. Six frames, the captions and the transcript were reviewed by the authoring agent, not an independent reviewer; the audio was not listened to by a person. Narration is the provisional Windows voice until LDG-0721.

Last updated