Never embed a raw Storj access grant in a shareable URL. Generate a restricted access with read-only scope, a time limit, and only the paths being shared, then build the link from that. If a URL ever leaks, revoke the grant rather than hoping nobody noticed.

Context: Official Storj docs FAQ: warns explicitly against hand-building share URLs with your access grant. The access grant contains your derived encryption key, so sharing a root grant URL gives full access to your whole project. Instead, use the safe share option that generates a scoped URL, ideally read-only, time-limited, and restricted to one or two paths, not the whole bucket. Agents that build 'share' features by embedding the raw grant are creating a credential leak, not a sharing feature.