# A confidential delivery

> A password the client types once, a short lifetime, and a code that is gone at the first download. How to do it with colis, what to watch, and where it is written down.

Canonical: https://colis-site.vercel.app/en/use-cases/livraison-confidentielle · Markdown: https://colis-site.vercel.app/en/use-cases/livraison-confidentielle.md · Français: https://colis-site.vercel.app/use-cases/livraison-confidentielle

A password the client types once, a short lifetime, and a code that is gone at the first download.

```sh
curl -X POST https://drop.example.com/api/transfers \
  -H 'content-type: application/pdf' \
  -H "x-colis-filename: $(printf %s contrat.pdf | jq -sRr @uri)" \
  -H 'x-drop-expires-in: 3600' -H 'x-drop-once: 1' \
  -H 'x-drop-passphrase: open%20sesame' \
  --data-binary @contrat.pdf
```

## What is actually going on.
### The problem
A contract, credentials, an exported customer list: the link must not sit in an inbox for months, nor work for anyone else.

### What colis does about it
On the sending page, pick the lifetime (from ten minutes to your deployment’s maximum), a password for this parcel, and burn after the first download. The password is hashed with scrypt, never stored in clear, never recoverable. The preview stays free; the download spends the code, and two downloads started at once do not both get it.

## The things that are easy to get wrong.
- **Two channels** — Send the code one way and the password another. The code alone is then worth nothing.
- **Attempts are limited** — Ten wrong passwords from one client, or fifty on one code, lock it for fifteen minutes. The counters live in each instance’s memory, so on a serverless host they slow guessing down rather than stop it.
- **A lost password is lost** — Nobody can read it back or reset it, not even you. The parcel is then only a file that expires.

Packages: colis-drop. [The delivery page, in full](https://github.com/mamadouwhile/colis/blob/main/templates/drop/README.md)
