- 1Generate a key
- 2Deploy to Cloudflare
- 3Create your account
Your encryption key
Paste it into the APP_ENCRYPTION_KEY field of the deploy form, and keep a copy: your first visit to CogSend asks for it again.
APP_ENCRYPTION_KEY
Made in this browser, sent nowhere
Prefer a terminal? openssl rand -hex 32 makes the same kind of key.
Only you have seen this key
Made in your browser
By the cryptographic random generator built into every modern browser (Web Crypto).
Never sent or stored
This page has no analytics, and its security policy forbids it from connecting to any server. Nothing is saved: reload, and the key is gone.
Check it yourself
Turn off your Wi-Fi and press Generate another. A new key still appears.
See the code that made it
// 32 random bytes from your browser's own cryptographic
// generator, written as 64 hex characters: the kind of key
// `openssl rand -hex 32` prints.
export function generateKey(): string {
const bytes = crypto.getRandomValues(new Uint8Array(32));
return Array.from(bytes, (b) =>
b.toString(16).padStart(2, '0')
).join('');
}That is all of it. The rest of the page only shows, copies and downloads the result: read its source.
Save it, then deploy
- Put it in your password manager now. Nobody, us included, can recover it.
- Already have Cloudflare's deploy form open? Paste the key into its
APP_ENCRYPTION_KEYfield and carry on there. - Starting here? The button below opens it.
Why this key matters
- Your first visit to the new instance asks for it, to prove the instance is yours before it creates your account.
- It encrypts the account tokens CogSend stores. Replacing it means reconnecting every account.
- Treat it like a password: anyone holding it and your database can read those tokens.