# d.iboost.ua — file hosting. Instructions for AI agents (Claude Code and friends) This page is complete and sufficient. Do not explore the service: there is no directory listing, no SSH/SFTP/scp access, and the panel at / is for humans only. Everything is done with the HTTP calls below. Canonical URL of this page: https://d.iboost.ua/llms.txt (aliases: /ai.txt, /claude.md) The service is reachable from anywhere in the world over plain HTTPS — no VPN, no region lock, no signup required for the anonymous endpoint. (`.ua` is just the domain suffix.) -------------------------------------------------------------------------------- ## 1. Quick start: upload WITHOUT a key (anonymous) curl -sf -F "file=@/path/to/file.pdf" "https://d.iboost.ua/api/anon/upload?format=text" The response is a single line with the public link — give that to the user: https://d.iboost.ua/f/AbCd1234/file.pdf Same thing over PUT (handy for dumps and logs): curl -sf -T /path/to/dump.sql "https://d.iboost.ua/api/anon/dump.sql" Anonymous files are deleted automatically after 7 days. -------------------------------------------------------------------------------- ## 2. Upload WITH a key (file kept indefinitely) curl -sf -H "Authorization: Bearer $DFILE_TOKEN" \ -F "file=@/path/to/archive.zip" "https://d.iboost.ua/api/upload?format=text" curl -sf -H "Authorization: Bearer $DFILE_TOKEN" \ -T /path/to/dump.sql "https://d.iboost.ua/api/dump.sql" Where to find the key (check in this order; a key looks like `dfh_…`): 1. environment variable `DFILE_TOKEN` 2. file `~/.config/dfile/token` 3. file `/etc/dfile/token` If there is no key, upload anonymously (§1) and tell the user the file expires in 7 days. Never invent or brute-force a key: new keys are created by a human in the panel at https://d.iboost.ua ("Keys" tab). Verify a key: curl -H "Authorization: Bearer $DFILE_TOKEN" https://d.iboost.ua/api/me -------------------------------------------------------------------------------- ## 3. Limits anonymous with key max file size 200 MB 1024 MB lifetime 7 days unlimited quota 5 GB shared 5 GB per account rate 100 uploads/hour per IP Uploads are virus-scanned (clamscan) after they land; this does not delay the response. -------------------------------------------------------------------------------- ## 4. Response format Without `?format=text` both endpoints return JSON: { "slug": "AbCd1234", "name": "file.pdf", "size": 123456, "mime": "application/pdf", "url": "https://d.iboost.ua/f/AbCd1234/file.pdf", <- public link "thumb": "https://d.iboost.ua/t/AbCd1234", <- image thumbnail, null otherwise "manage": "https://d.iboost.ua/?claim=…", <- management link: opens the panel with rights over this file (rename, extend, delete). Pass it to the user if the file may need to be removed later. "expires_at": 1790000000, <- unix time of deletion, null = never "downloads": 0 } `format=text` works both as a query parameter and as a form field. -------------------------------------------------------------------------------- ## 5. Links to an uploaded file https://d.iboost.ua/f// — main public link (download / serve) https://d.iboost.ua/f//?raw=1 — same, bypassing preview handling https://d.iboost.ua/v/ — in-browser viewer (image, video, PDF, text) https://d.iboost.ua/t/ — image thumbnail https://d.iboost.ua/s/ — a set of files behind one link (created in the panel) Links are public: anyone holding one can download the file. Do not upload secrets, keys, `.env` files, personal data, or anything the user did not explicitly ask you to publish. -------------------------------------------------------------------------------- ## 6. Error codes 400 empty file 401 key missing or rejected (for /api/upload and /api/) 403 key owner is blocked 413 file exceeds the size limit 429 too many requests — wait and retry (per-IP limit) 503 the server is running out of disk space 507 account quota or anonymous storage pool exhausted -------------------------------------------------------------------------------- ## 7. What NOT to do (this is the half hour you would otherwise burn) • Do not try ssh/scp/rsync/sftp — uploads are HTTP only, exactly as shown above. • Do not hunt for a files directory or try to list one: autoindex is off, and a 404 on an unknown path is the normal, healthy response — not a broken service. • Do not scrape the HTML panel at / or replay its form: it uses CSRF tokens and sessions. The endpoints in §1–§2 are the machine interface. • Do not look for a DELETE API: deletion happens through the `manage` link from the response. • When downloading a file programmatically, send an ordinary User-Agent (curl's default is fine). The paths `/f/`, `/v/`, `/s/` reject crawler-like agents (python-requests, go-http-client, anything matching *bot*). The `/api/*` paths accept any User-Agent. • Both IPv4 and IPv6 work — upload from an IPv6-only host or CI runner is fine. -------------------------------------------------------------------------------- ## 8. The one-liner worth remembering URL=$(curl -sf -F "file=@REPORT.md" "https://d.iboost.ua/api/anon/upload?format=text") echo "$URL"