Docs

Shorten from anywhere

One REST API under /api/v1, and four ways to call it: curl, the CLI, the MCP server and the desktop app. Machine-readable summary at /llms.txt.

REST API

Authenticate with Authorization: Bearer <key>. Keys (wx93_live_…) are God Mode: one key can do anything its account can. Make one on your account page (Pro and up). OAuth access tokens from wx93 login (wx93_at_…) work the same way. With no key you can still create free links.

curl -s https://wx93.me/api/v1/links \
  -H 'authorization: Bearer wx93_live_…' -H 'content-type: application/json' \
  -d '{"url":"https://example.com/long","alias":"launch","expires_in":"30d"}'
POST /api/v1/links{url, alias?, title?, expires_at? | expires_in? ("7d", "12h"), redirect_type? (301|302|307|308), domain? ("wx93.me" default, "9xq.me", or your verified domain)} → 201 link
POST /api/v1/links/bulk{links: [{url, alias?, …}]}, up to 1,000 (Automation) → per-item results
GET /api/v1/linksyour links, newest first; ?limit=&before=&q=
GET /api/v1/links/{id|code}one link
PATCH /api/v1/links/{id|code}{url?, title?, expires_at?, redirect_type?}
DELETE /api/v1/links/{id|code}delete it; the code stops resolving at once
GET /api/v1/links/{id|code}/stats?days=30: totals, daily, referrers, countries, devices, browsers, os (Pro and up; Free gets totals)
GET /qr/{code}.svgQR code, SVG
GET /api/v1/expand?url=where a wx93 link goes, without visiting it
GET /api/v1/meaccount, plan, usage and limits
GET|POST|DELETE /api/v1/keysAPI keys
GET|POST|DELETE /api/v1/webhooksAutomation: {url, events?}; POST /api/v1/webhooks/{id}/test
GET|POST|DELETE /api/v1/domainsAutomation: {hostname}, then TXT _wx93.<hostname> and POST /api/v1/domains/{id}/verify
POST /api/v1/billing/checkout{plan: "pro"|"automation", term: "month"|"year", chain?} → {checkout_url}
POST /api/v1/reports{url, reason: phishing|malware|spam|illegal|other, details?}
GET /api/v1/healthliveness, with a database round trip

How a short link answers

CLI and TUI

curl -fsSL https://wx93.me/install | sh

Installs wx93 under ~/.local without sudo; adds the desktop app when there is a desktop session (--desktop / --cli-only to choose). Or npm i -g @profullstack/wx93.

wx93 https://example.com/long --alias launch --expires 30d
wx93 login              # OAuth 2.1 in your browser (--manual over SSH)
wx93 ls                 # your links
wx93 stats launch       # referrers, countries, devices
wx93 qr launch          # a QR code in the terminal
wx93 bulk urls.txt      # one URL per line (Automation)
wx93 tui                # all of it, as a screen
wx93 mcp                # stdio MCP server
wx93 upgrade | uninstall

MCP server

Stdio: npx -y @profullstack/wx93-mcp (or wx93 mcp). It uses your wx93 login sign-in or WX93_API_KEY. Hosted: POST https://wx93.me/mcp (JSON-RPC 2.0, streamable HTTP, Bearer key optional). Tools: shorten_url, bulk_shorten, list_links, get_link, link_stats, update_link, delete_link, expand_link, whoami.

OAuth 2.1

Authorization code with PKCE (S256), loopback redirects, rotating refresh tokens. Metadata at /.well-known/oauth-authorization-server. Public client id wx93-cli.

x402: pay per call

No account, no key. Past the free allowance (20 links an hour per address) POST /api/v1/links answers 402 with an x402 offer. Pay it (USDC on Base, Polygon or Ethereum) and send the pass back as x-crawl-pass. A pass costs $0.25, lasts 60 minutes, covers 100 links, and every link made with it skips the ad page for a year.

npm i -g @profullstack/coinpay
coinpay x402 pay https://wx93.me/x402 --output pass.json
curl -s https://wx93.me/api/v1/links -H "x-crawl-pass: $(node -p "require('./pass.json').pass")" \
  -H 'content-type: application/json' -d '{"url":"https://example.com"}'

Abuse policy

Every destination is checked when it is shortened: http and https only, no credentials in the URL, no private addresses, no other shorteners, our blocklist, the URLhaus and OpenPhish feeds (refreshed every few hours and swept over existing links), and Google Safe Browsing where configured. Anonymous links that look like credential phishing need an account. Anyone can report a link; after 3 independent reports it is pulled pending review.

Privacy

A click records the time, the referring site's hostname, a country code, and the device, browser and OS family. The visitor's IP address is used once to look up the country and is never stored.