Sturm
File hosting. Upload through the API, download through a direct link.
Lifetime plan — $10 USD per account
One payment, no subscription, no tiers. Every account includes encrypted storage, direct UUID download links, and the full file API below.
Accepted payment methods
Pay the $10 USD fee with either currency:
Key rotation policy
Each account may rotate its Access + Secret pair up to 3 times using its Revocation Key. Rotation preserves existing file links.
- Rotations 1–3: succeed and return a fresh Access + Secret pair.
- 4th rotation request: refused with a final warning. Keys stay unchanged, but one more rotation request deletes the account.
- 5th rotation request: the account, its keys, and its files are permanently deleted.
Keep your Revocation Key safe. If the keys are compromised, rotate before the limit — a deleted account cannot be recovered.
How your files are encrypted
Every file is encrypted with AES-256-GCM before it touches storage. Each file gets its own random 256-bit data key and 96-bit IV, and the 128-bit authentication tag rejects any tampered ciphertext on download — corrupted bytes fail closed instead of serving garbage.
- File contents: AES-256-GCM with a per-file random key and IV.
- Data keys: wrapped with a separate 256-bit master key using AES-256-GCM with additional authenticated data bound to the file.
- API requests: signed with HMAC-SHA256. Your Secret Key never travels in a request body — only the signature does.
- Stored secrets and integrity digests: SHA-256 hashes and AES-256-GCM sealed envelopes. Passwords are hashed, never stored.
No filenames, MIME types, or custom metadata are stored alongside the ciphertext. Storage only ever holds encrypted bytes.
Why use Sturm
- Encryption first: storage holds ciphertext only, and downloads are integrity-checked before a single byte is served.
- Direct links: anyone with the link downloads the file itself. There is no login wall and no preview page.
- One payment: $10 USD lifetime. No subscription to cancel, no usage meter running against your uploads.
- Honest limits: 3 key rotations per account, enforced in the open and documented above.
How it works
Your account is created with credentials. Use your Access Key and Secret Key to sign uploads and manage your files.
Anyone with the UUID link can download the file without signing in. The URL serves the file itself:
https://sturmv1.lol/f/xxxxxxxx-xxxx-4xxx-yxxx-xxxxxxxxxxxxUpload
Uploads are plain HTTPS requests. The file bytes are the body, and HMAC-SHA256 headers prove the request came from you. Your Secret Key stays on your computer.
curl -X POST https://sturmv1.lol/api/v1/files \
--data-binary @./file.txt \
-H "Content-Type: application/octet-stream" \
-H "X-Access-Key: <access-key>" \
-H "X-Timestamp: <unix-seconds>" \
-H "X-Nonce: <random-nonce>" \
-H "X-Content-SHA256: <body-sha256>" \
-H "Authorization: Sturm-HMAC-SHA256 <hex-signature>" \
-H "X-File-Name: file.txt" \
-H "X-File-Mime: text/plain" \
-H "X-File-Size: 1234" \
-H "Idempotency-Key: <unique-key>"A successful upload returns your file, including its public url. See the full header format and the other endpoints in the documentation.
Credentials
- Access Key: identifies your credentials.
- Secret Key: signs upload and management requests.
- Revocation Key: replaces the Access + Secret pair if compromised.
Keep all three keys.
Storage and limits
Files are encrypted in storage. Names, types, and management information are stored in the database.
Check the current API capabilities before uploading.