Creator workflow
Step 1
Content creation
The creator makes the work with the tools they already use, whether that means images, video, HTML, PDFs, or another format they want to share more intentionally.
How it works
Supported image Capsule flow
Share Capsules lifecycle steps
Share Capsules separates the act of publishing from the decision to unlock. Creators keep their work portable, while Viewers open it through trusted services that check access before anything protected is shown.
Creator workflow
Step 1
The creator makes the work with the tools they already use, whether that means images, video, HTML, PDFs, or another format they want to share more intentionally.
Creator workflow
Step 2
The creator tool wraps the work in an encrypted Capsule and signs the trust policy, so the package carries clear instructions about how it may be opened.
Creator workflow
Step 3
The encrypted Capsule can be placed on an ordinary website. The Host can share the file, but it cannot read the protected content inside it.
When someone visits the hosted page
Viewer workflow
Step 4
A Viewer connects through the official tool, reviews the access requirements, and chooses whether to opt in to this Capsule’s trust policy.
Viewer workflow
Step 5
A trusted provider checks only what this Capsule requires, such as account status, consent, limits, or creator-selected conditions.
Viewer workflow
Step 6
If access is approved, the broker releases a one-time opening key to that connected Viewer. The Host never receives it.
Viewer workflow
Step 7
The Viewer opens the Capsule locally and shows the protected work inside its own trusted viewing surface.
Capsule access rules
Capsules can be configured with time, limit, and trust policies. These policies can be used alone or combined to define the access rules for decryption. The Viewer opens the encrypted content only when every required policy is satisfied.
A Time Capsule, Limit Capsule, Trust Capsule, or Combined Capsule allows creators to configure how they want their protected content shared.
Allows creators to set opening and closing dates. The Capsule opens only during that configured access window.
Allows creators to limit how many times protected content can be viewed, either across all viewers or per viewer account.
Allows creators to require a viewer trust check before content opens. The trust score considers recent usage patterns and quick human challenges that help distinguish people from bots.
Combines selected rules so time, limit, and trust requirements must all pass before the key is released.
At viewing time
The current time, counters, account, device, and trust checks satisfy the signed policy.
A time window has not started, has ended, or an opening limit has already been reached.
The viewer is otherwise eligible, but current confidence is too low to release the key yet.
Recent high automation-risk behavior can keep access blocked even if a challenge is attempted.
Trust checks help reduce automated access, but they are not a perfect guarantee. They do not prove that a viewer is a unique person, generally trustworthy, or guaranteed to use the content well.
The participants
The journey works because each participant has a narrow job.
Share Capsules operates the first reference services, but Capsule and CTX are designed as an open protocol. Official tools can choose recognized providers and brokers without forcing every implementation into one closed ecosystem.
Original work using the tools they already know, such as image, video, HTML, PDF, or other supported formats.
Chooses what they want to share more intentionally.
The original work, creator signing key, trust policy, and freshly generated content key.
Produces the encrypted, policy-bearing Capsule locally.
Public fallback content and the encrypted Capsule file.
Can distribute the Capsule without needing Viewer identity, the key, or plaintext.
A person visits the hosted page and asks to open the Capsule through a compatible Viewer.
Starts as an ordinary visitor until the policy and key path complete.
The providers and brokers that official tools are willing to use by default.
Lets official Viewers refuse unknown, suspended, or revoked services before private information is shared.
The policy check and key-release conversation between the Viewer, provider, and broker.
Keeps the Host out of the trust and key path.
The trust policy and only the consented evidence needed for that request.
Returns a limited policy result instead of raw account history.
Protected content-key material, release state, and exact short-lived authorization.
Wraps the content key to the authorized Viewer device; it does not render the work.
The account connection, consented evidence, device keys, released content key, and rendered plaintext.
Coordinates access and decrypts locally, outside the Host page.
At viewing time
Downloading an encrypted Capsule is not itself a protected view. The content becomes readable only after authorization and device-bound key release.
Step 1
The Viewer fetches the Capsule, validates its signature and declared trust policy, and checks that the required services are recognized before sharing account evidence.
Step 2
The Viewer explains which policy conditions will be checked and asks whether the visitor wants to opt in for this opening.
Step 3
The Trust Provider evaluates the creator’s policy for this Capsule, revision, action, account, and registered device. Approval is short-lived and cannot authorize unrelated content.
Step 4
The Key Broker validates the authorization and wraps the content key to the Viewer device. The Viewer decrypts in its isolated surface; the Host does not receive the key or plaintext.
Available now
Create an account, protect an image, publish the protected Capsule on your site, and let eligible viewers open it with the Share Capsules Viewer. The hosted Share Capsules services handle the account, access, and key-release steps for the supported V1 flow.
An authorized person can still photograph, record, reproduce, or misuse rendered content. Share Capsules aims to make anonymous bulk access harder and releases more accountable; it does not make visible work impossible to copy or prove future human intent.