What a share link is
A share link lets anyone watch one specific replay in the in-browser viewer without signing in. The link points at replaycore.com/watch/ followed by an unguessable token; the token is the only credential, so whoever holds the link can watch that replay and nothing else.
Share links are ideal for posting evidence into a staff Discord channel, sending a highlight to a player, or sharing a match publicly.
Creating a link
Open the replay in your dashboard and choose Share. The full link is shown exactly once at creation, because only a hash of the token is stored server-side; copy it before closing the dialog. A replay can have one active link at a time, and creating a new link automatically revokes the previous one.
Revoking and disabling
Links do not expire on their own, but they are revocable at any time from the same dialog. Revocation takes effect immediately: the token stops resolving on the very next request, because the page and the archive stream are both resolved server-side on every fetch.
You can also disable public sharing for your whole account from the sharing settings (owner or admin only). With sharing disabled, every existing link stops resolving and no new links can be created.
Safety properties
Tokens are cryptographically random and stored only as hashes, so a leaked database backup does not leak watchable links. A revoked link, a deleted replay, and a tenant with sharing disabled all fail in the same indistinguishable way, so tokens cannot be probed. The viewer page never receives a durable storage URL.