Many one-time link systems work on the same basic principle: whoever holds the complete link can open the secret. That is also true for PCPX.one in standard mode. That is why TrustKey adds an additional cryptographic recipient approval.
What is PCPX TrustKey?
TrustKey is the optional recipient approval of pcpx.one. The key is split in two halves: one is in the link, the other stays in the sender's browser. Only a device the sender explicitly approves receives the second half. The link alone is then no longer enough to decrypt.
Why might a normal secret link not be enough?
With a normal one-time link, the complete key is inside the link. Whoever holds the link can open the secret, no matter how they got it. The link itself becomes a security factor. This applies to every service where the link alone is sufficient, including pcpx.one in standard mode.
Is PCPX.one insecure without TrustKey?
No, it is a different threat model. In standard mode everything is encrypted in the browser, the server only sees ciphertext, and the secret is deleted after retrieval. What standard mode does not cover: someone getting hold of the complete link. TrustKey exists for exactly that scenario.
When should I use TrustKey?
When the delivery channel is part of your threat model: the link travels through a channel you don't control, ends up in chat histories or backups, or it carries credentials that would be costly to lose. In short: whenever you say "even if someone gets the link, that should not be enough."
What happens if someone copies my TrustKey link?
They only hold half of the key material and cannot decrypt the content. They can request approval – you see the request with its fingerprint and deny it. Honest limit: whoever has the link can trigger the one-time retrieval and make the link unusable. They cannot read the content.
Is the TrustKey stored on the server?
Not in plaintext. The second key half stays in the sender's browser. Only on approval is it encrypted for the recipient device's public key and stored as a package that only this device can open. The recipient's private key never leaves their device.
Does the recipient need an account?
No. Neither sender nor recipient needs an account. The recipient's browser generates its own key pair automatically when requesting access.
Does TrustKey work with files?
Yes. TrustKey works with text, single files and multiple files up to 50 MB. An additional password is currently not combined with TrustKey mode – the approval replaces it.
Which cryptography does PCPX.one use?
Content is encrypted in the browser with AES-256-GCM; the key is derived via PBKDF2-SHA256 with 600,000 iterations. For TrustKey, the recipient device generates an ECDH key pair (P-256). The second key half is bound to exactly this message and exactly this device via ECDH, HKDF-SHA256 and AES-GCM-256.
Can I verify how it works myself?
Yes. Open a TrustKey link in a different browser: instead of the content, the approval request appears. In the network tab (F12) you can see that the part after the # is never sent. The crypto library including the TrustKey code is open source (MIT) on GitHub as @pcpx/sdk.