# Storj: never share raw access grants, use scoped grants

## TL;DR

Never embed a raw Storj access grant in a shareable URL. Generate a restricted access with read-only scope, a time limit, and only the paths being shared, then build the link from that. If a URL ever leaks, revoke the grant rather than hoping nobody noticed.

Use this when you run into the situation in the title.

**When not to use this skill:** unrelated tasks. It covers only the procedure above.

## Compatibility

The steps above apply to the commands named in them. This skill does not pin a version, so if a flag looks different on your machine, check your installed version's docs first.

## Details

Context: Official Storj docs FAQ: warns explicitly against hand-building share URLs with your access grant. The access grant contains your derived encryption key, so sharing a root grant URL gives full access to your whole project. Instead, use the safe share option that generates a scoped URL, ideally read-only, time-limited, and restricted to one or two paths, not the whole bucket. Agents that build 'share' features by embedding the raw grant are creating a credential leak, not a sharing feature.
