Docs
Shorten from anywhere
One REST API under /api/v1, and four ways to call it: curl, the CLI, the MCP server and the desktop app. Machine-readable summary at /llms.txt.
REST API
Authenticate with Authorization: Bearer <key>. Keys (wx93_live_…) are God Mode: one key can do anything its account can. Make one on your account page (Pro and up). OAuth access tokens from wx93 login (wx93_at_…) work the same way. With no key you can still create free links.
curl -s https://wx93.me/api/v1/links \
-H 'authorization: Bearer wx93_live_…' -H 'content-type: application/json' \
-d '{"url":"https://example.com/long","alias":"launch","expires_in":"30d"}'
POST /api/v1/links | {url, alias?, title?, expires_at? | expires_in? ("7d", "12h"), redirect_type? (301|302|307|308), domain? ("wx93.me" default, "9xq.me", or your verified domain)} → 201 link |
POST /api/v1/links/bulk | {links: [{url, alias?, …}]}, up to 1,000 (Automation) → per-item results |
GET /api/v1/links | your links, newest first; ?limit=&before=&q= |
GET /api/v1/links/{id|code} | one link |
PATCH /api/v1/links/{id|code} | {url?, title?, expires_at?, redirect_type?} |
DELETE /api/v1/links/{id|code} | delete it; the code stops resolving at once |
GET /api/v1/links/{id|code}/stats | ?days=30: totals, daily, referrers, countries, devices, browsers, os (Pro and up; Free gets totals) |
GET /qr/{code}.svg | QR code, SVG |
GET /api/v1/expand?url= | where a wx93 link goes, without visiting it |
GET /api/v1/me | account, plan, usage and limits |
GET|POST|DELETE /api/v1/keys | API keys |
GET|POST|DELETE /api/v1/webhooks | Automation: {url, events?}; POST /api/v1/webhooks/{id}/test |
GET|POST|DELETE /api/v1/domains | Automation: {hostname}, then TXT _wx93.<hostname> and POST /api/v1/domains/{id}/verify |
POST /api/v1/billing/checkout | {plan: "pro"|"automation", term: "month"|"year", chain?} → {checkout_url} |
POST /api/v1/reports | {url, reason: phishing|malware|spam|illegal|other, details?} |
GET /api/v1/health | liveness, with a database round trip |
How a short link answers
- Pro and Automation links: the HTTP redirect you chose (302 by default). 301 and 308 are cacheable for an hour, so repeat visits from one browser may not be counted.
- Free links, opened by a person in a browser: a page with an ad and a 5 second
<meta http-equiv="refresh">, plus a Continue link. No JavaScript involved. - Free links, fetched by a crawler, a link unfurler, curl or any script: the plain 302, so previews and tools keep working.
- Every code works on both of our short domains:
wx93.me/abc123and9xq.me/abc123are the same link, with the same stats. Pick which one a link is shown with bydomain. - Add
+to any link (wx93.me/abc123+) to see where it goes without going there.
CLI and TUI
curl -fsSL https://wx93.me/install | sh
Installs wx93 under ~/.local without sudo; adds the desktop app when there is a desktop session (--desktop / --cli-only to choose). Or npm i -g @profullstack/wx93.
wx93 https://example.com/long --alias launch --expires 30d wx93 login # OAuth 2.1 in your browser (--manual over SSH) wx93 ls # your links wx93 stats launch # referrers, countries, devices wx93 qr launch # a QR code in the terminal wx93 bulk urls.txt # one URL per line (Automation) wx93 tui # all of it, as a screen wx93 mcp # stdio MCP server wx93 upgrade | uninstall
MCP server
Stdio: npx -y @profullstack/wx93-mcp (or wx93 mcp). It uses your wx93 login sign-in or WX93_API_KEY. Hosted: POST https://wx93.me/mcp (JSON-RPC 2.0, streamable HTTP, Bearer key optional). Tools: shorten_url, bulk_shorten, list_links, get_link, link_stats, update_link, delete_link, expand_link, whoami.
OAuth 2.1
Authorization code with PKCE (S256), loopback redirects, rotating refresh tokens. Metadata at /.well-known/oauth-authorization-server. Public client id wx93-cli.
x402: pay per call
No account, no key. Past the free allowance (20 links an hour per address) POST /api/v1/links answers 402 with an x402 offer. Pay it (USDC on Base, Polygon or Ethereum) and send the pass back as x-crawl-pass. A pass costs $0.25, lasts 60 minutes, covers 100 links, and every link made with it skips the ad page for a year.
npm i -g @profullstack/coinpay
coinpay x402 pay https://wx93.me/x402 --output pass.json
curl -s https://wx93.me/api/v1/links -H "x-crawl-pass: $(node -p "require('./pass.json').pass")" \
-H 'content-type: application/json' -d '{"url":"https://example.com"}'
Abuse policy
Every destination is checked when it is shortened: http and https only, no credentials in the URL, no private addresses, no other shorteners, our blocklist, the URLhaus and OpenPhish feeds (refreshed every few hours and swept over existing links), and Google Safe Browsing where configured. Anonymous links that look like credential phishing need an account. Anyone can report a link; after 3 independent reports it is pulled pending review.
Privacy
A click records the time, the referring site's hostname, a country code, and the device, browser and OS family. The visitor's IP address is used once to look up the country and is never stored.