Skip to content
  1. 1Generate a key
  2. 2Deploy to Cloudflare
  3. 3Create your account

Your encryption key

Paste it into the APP_ENCRYPTION_KEY field of the deploy form, and keep a copy: your first visit to CogSend asks for it again.

APP_ENCRYPTION_KEY

Made in this browser, sent nowhere

Generating…

Prefer a terminal? openssl rand -hex 32 makes the same kind of key.

Only you have seen this key

See the code that made it
// 32 random bytes from your browser's own cryptographic
// generator, written as 64 hex characters: the kind of key
// `openssl rand -hex 32` prints.
export function generateKey(): string {
	const bytes = crypto.getRandomValues(new Uint8Array(32));
	return Array.from(bytes, (b) =>
		b.toString(16).padStart(2, '0')
	).join('');
}

That is all of it. The rest of the page only shows, copies and downloads the result: read its source.

Save it, then deploy

Why this key matters
  • Your first visit to the new instance asks for it, to prove the instance is yours before it creates your account.
  • It encrypts the account tokens CogSend stores. Replacing it means reconnecting every account.
  • Treat it like a password: anyone holding it and your database can read those tokens.