Documentation
Three endpoints. No authentication for public objects.
Fetch an object
GET /o/<sha256>/<filename> → 200 with Cache-Control: public, max-age=31536000, immutable → 404 if the digest is unknown
Check a digest without downloading
HEAD /o/<sha256>/<filename>
The response carries ETag equal to the digest, so a conditional request never transfers the body twice.
Health
GET /healthz → 200 ok
Limits
| Item | Value |
|---|---|
| Maximum object size | 256 MB |
| Requests per minute per IP | 600 |
| Retention for unreferenced objects | 90 days |
Caching notes
Because paths are content-addressed, intermediate caches may hold objects indefinitely. If you need a different byte sequence, you need a different digest — there is no purge API and no cache invalidation to reason about.