Secret Server + DarkStorage
Keep your IP, secret.
Protected documents combine Secret Server access control with encrypted storage in DarkStorage. Share watermarked page previews with people in your account, set an expiry, and decide separately who may download the original or print pages. Your operator must enable the integration before use.
Manage and share
- Open Documents in the management console. Managers can upload a PDF of up to 8 MiB and 50 pages.
- Select a document and enter the email of an existing member of your account. Choose an expiry within the next 30 days.
- Download and print are off by default. Enable each one separately when needed. No invitation email is sent; tell the recipient to sign in and open Documents.
- Review grants and revoke access when needed. Multiple active grants combine their permissions; revoke every grant to remove all access.
Recipients see watermarked page previews. The watermark carries the viewer's identity and the time, burned into the image pixels. Original download requires download permission. Administrators with documents:manage or admin:* have full document access.
Protection and limits
Each PDF gets its own randomly generated AES-256-GCM key. Per-document keys are held in Secret Server's key store, separate from the ciphertext and from document metadata. DarkStorage stores only ciphertext. Every preview, print and download request is checked against current grants and audited by Secret Server before content is released.
This is server-managed encryption, not end-to-end or zero-knowledge encryption. Secret Server decrypts a document on the server to render pages for an authorized request, and its operators remain trusted.
Print permission is a viewer setting, not a security control. It decides whether the Documents viewer offers Print this page, which prints a rendered, watermarked page. Anyone who can view a page can still print or save what is on their screen.
This release supports PDFs and existing members of the same account. It does not offer anonymous links, Office documents, document deletion, version history, or offline viewing. The device agent does not cache protected documents.
API and SDKs
Use the Secret Server API origin with normal bearer authentication. Management API keys need documents:manage. User grants require the recipient's interactive session; an API key does not inherit its creator's document grants.
GET /api/v1/documents
POST /api/v1/documents?name=design.pdf (raw application/pdf body)
GET /api/v1/documents/{id}
GET /api/v1/documents/{id}/pages/1 (PNG)
GET /api/v1/documents/{id}/pages/1?purpose=print (PNG)
GET /api/v1/documents/{id}/download (original PDF)
GET /api/v1/documents/{id}/grants
POST /api/v1/documents/{id}/grants
DELETE /api/v1/documents/{id}/grants/{grantId}Grant request body
{"recipient_email":"colleague@example.com","expires_at":"<future RFC3339 time>",
"allow_download":false,"allow_print":false}| Status | Meaning |
|---|---|
| 404 | The document does not exist or is not accessible to the caller |
| 403 | A download, print or management action the caller is not permitted |
| 413 | The PDF is larger than 8 MiB |
| 422 | The file is not a readable PDF or exceeds the page limit |
| 503 | The integration is disabled or a storage, key, audit or renderer service is unavailable |
Listing returns the newest 100 accessible documents. Responses include the effective can_manage, can_download and can_print permissions.
The Go, Python, Node and PHP SDKs include document helpers. Configure an 80 second request timeout for document work. Binary helpers return bytes in memory and do not save files automatically. The DarkStorage CLI also supports darkstorage protected commands using a separate Secret Server API key.