Sharpbin is a pastebin-style website built with ASP.NET Core and SvelteKit.
A live instance is available at sharpbin.cc.
- User authentication and account management.
- Syntax highlighting for various programming languages.
- Private pastes with client-side encryption.
- Raw text serving for easy sharing and scripting.
- Paste editing including content, syntax, title, and expiration.
- Configurable paste expiration.
- Server-side paste compression to save storage.
- Captcha support via Cloudflare Turnstile.
The easiest way to run SharpbinV3 is using Docker Compose.
- Ensure Docker and Docker Compose are installed.
- Clone the repository.
git clone https://github.com/whoswhip/Sharpbin.git- In the repository root, copy
.env.exampleto.env. - Replace the secret placeholders and configure your domain and Turnstile keys. Set
ORIGINto the public frontend URL, including the scheme. For local Docker testing, useORIGIN=http://localhost:5173,Domain=localhost:5173,Https=false, andAllowedCorsOrigins__0=http://localhost:5173. - Run the following command in the root directory:
docker compose up -d --buildConfigure Sharpbin in the root .env file when using Docker Compose. The backend loads this file as environment variables. Compose passes only the backend URL, public origin, and shared view-recording key to the frontend.
The backend image includes appsettings.json with application defaults. Environment variables have priority, so you do not need to edit or mount that file for normal setup. Additional backend settings, including EmailSettings__Host and other SMTP settings, can be added to .env using their existing names.
Compose defaults the database to /app/data/sharpbin.db, Data Protection keys to /app/data/keys, and VITE_API_URL to http://backend:8080. To override them, add ConnectionStrings__DefaultConnection, DATA_PROTECTION_KEY_PATH, or VITE_API_URL to .env. Keep database and key paths under /app/data to use the existing persistent volume.
The example secrets are placeholders, not secure defaults. Generate a separate secret for JWT signing, API-key hashing, and view hashing, plus one shared internal API key. This command generates a 64-character random hex value; run it once for each secret:
docker run --rm node:24-alpine node -e "console.log(require('node:crypto').randomBytes(32).toString('hex'))"or use openSSL:
openssl rand -hex 32Set the shared key once as PasteSettings__View_Internal_API_Key. Compose supplies it to the frontend as VIEW_INTERNAL_API_KEY. Keep generated secrets across restarts and updates. Changing the API-key HMAC secret invalidates existing API keys.
- Copy the values from
backend.envinto the root.envfile. If.envalready exists, merge the settings without replacing existing values blindly. - Copy
ORIGINfromfrontend.env. If it was unset, use your public frontend URL, including the scheme. - Keep
PasteSettings__View_Internal_API_Keyset to the existing shared key. The separateVIEW_INTERNAL_API_KEYentry is no longer needed for Compose. - Move any custom
appsettings.jsonvalues into.envusing__for nested settings. For array settings, use numbered entries such asAllowedCorsOrigins__0. If you need to retain a custom JSON file, add a read-only mount for it incompose.override.yaml. - Run
docker compose up -d --build. The oldbackend.envandfrontend.envfiles are no longer read by Compose.
Keep the existing database volume, Data Protection keys, and secret values. Do not regenerate secrets during this migration.
When configuring via
appsettings.jsoninstead of for exampleConnectionStrings__DefaultConnectionit would be:
"ConnectionStrings": {
"DefaultConnection": "Data Source=sharpbin.db"
},Domain: The domain your instance of Sharpbin will be hosted at (e.g., example.com)Https: Whether the public instance uses HTTPS. Used when generating email links; this does not enable TLS on the server.AllowedCorsOrigins__0: An allowed browser origin for the backend API (e.g.,https://example.com). Use numbered entries for additional origins.ConnectionStrings__DefaultConnection: SQLite connection string (e.g.,Data Source=/app/data/sharpbin.db).JwtSettings__Secret: A random secret of 32-128 characters used for signing JWT tokens.AuthSettings__CF_Turnstile_SecretKey: Your Cloudflare Turnstile secret key.AuthSettings__CF_Turnstile_SiteKey: Your Cloudflare Turnstile site key.AuthSettings__Registration_Enabled:true: Enables/disables registration.AuthSettings__First_User_Admin: Gives the first user the admin role, it is recommended to disable this after use.AuthSettings__Admins_Require_2FA: Enforces Admins to have 2FA when trying to do certain actions.AuthSettings__API_Key_HMAC_Secret: Recommended to securely hash API keys, but is not required.PasteSettings__MaxTitleLength: Max title length in characters.PasteSettings__MaxPasteSizeInBytes:1_048_576 (1MB): Max Paste Size set in bytes.PasteSettings__EnablePasteCompression:true: Enables/Disables server-side paste compression.PasteSettings__RequiresVerification:true: Enables/Disables CAPTCHA verification when creating pastes.PasteSettings__View_HMAC_Secret: A required random secret of 32–128 characters used to hash viewer identifiers.PasteSettings__View_Internal_API_Key: A shared key of 32–128 characters used to authorize view recording. Compose passes it to both services.
VITE_API_URL: The backend URL reachable from the frontend server. Defaults tohttp://localhost:5050when running directly andhttp://backend:8080in Compose. Browser requests use the frontend's/apiproxy.ORIGIN: The public frontend URL, including its scheme (e.g.,https://example.com). Used by the production Node server; see SvelteKit's Node adapter documentation.VITE_ALLOWED_HOSTS: A comma-separated list used only by Vite dev/preview (e.g.,localhost,sharpbin.cc). Export it in the shell before starting Vite; the config readsprocess.envdirectly. It does not configure production host restrictions.VIEW_INTERNAL_API_KEY: The production frontend's shared view-recording key. Compose sets it fromPasteSettings__View_Internal_API_Key; do not duplicate it in the root.env. When running the frontend directly, set it yourself or use the existingView_HMAC_Internal_API_Keyfallback.
When NODE_ENV=development, the frontend uses a fixed development-only internal key matching the backend's checked-in development configuration and ignores both environment key names. See the client README for development and standalone production setup.
The frontend will be accessible at http://localhost:5173.
- SharpbinV3.Server: Backend API built with C# and ASP.NET Core. Refer to its README for server-side development and configuration.
- SharpbinV3.Client: Frontend application built with SvelteKit and TypeScript. Refer to its README for client-side development and setup.