Begin with what is not protected.
Email syntax is validated, but ownership is not verified. A valid-looking address can belong to someone else or be undeliverable. The signup service uses basic abuse controls and does not include Turnstile or another challenge provider.
New and duplicate JSON replies differ, so the endpoint does not conceal whether an email is registered. No financial authentication, payment processing, custody or asset transfer is implemented. These docs claim no independent security audit or certification.
A narrow door for each request.
- Method & body
- Both endpoints require POST, an accepted content type and a bounded body read.
- Browser origin
- A mismatched Origin or cross-site Sec-Fetch-Site is rejected. These checks protect browser flows; they do not authenticate non-browser clients.
- Signup input
- Email and consent checks, a honeypot, and an atomic hourly counter apply before a registration is inserted.
- SQL values
- Prepared statements bind inputs as parameters. Visitor strings are not concatenated into SQL.
Application errors log event names without request bodies, emails or raw removal tokens. Cloudflare’s hosting and network logs are a separate system.
A private link is a permission.
The removal token is made from 32 cryptographically random bytes using Web Crypto. Only its SHA-256 hash is stored. Anyone possessing the raw token can remove that signup, so keep it out of analytics, logs, screenshots, query strings and shared messages.
A duplicate registration does not replace or reveal the original credential. The management page sends no referrer and asks not to be indexed. The removal endpoint does not use the signup rate limiter; the private credential authorizes deletion.
A lost credential cannot be
recovered from its hash.
No account-based or email-based token-recovery flow exists.
Care in the browser, too.
The frontend inserts server messages as text. Native HTML confirmations use internally controlled copy and a generated hexadecimal token, without reflecting the visitor’s email into markup.
Static pages set Content Security Policy, nosniff, DENY framing, a referrer policy and a permissions policy that disables camera, microphone and geolocation.
The CSP permits same-site resources and data images, with inline scripts and styles allowed for theme initialization and generated styles. It is not a nonce-only or hash-only policy.
API responses use no-store and no-referrer. Successful native HTML responses also set a restrictive CSP. Static header rules and API response headers are maintained separately.