A minimal file upload/pastebin service.
Go to file
dependabot[bot] 9ceb0d4c21
chore(deps): bump docker/setup-qemu-action from 2 to 3 (#283)
Bumps [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) from 2 to 3.
- [Release notes](https://github.com/docker/setup-qemu-action/releases)
- [Commits](https://github.com/docker/setup-qemu-action/compare/v2...v3)

- dependency-name: docker/setup-qemu-action
  dependency-type: direct:production
  update-type: version-update:semver-major

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-13 19:27:39 +03:00
.github chore(deps): bump docker/setup-qemu-action from 2 to 3 (#283) 2024-05-13 19:27:39 +03:00
examples chore(example): add auth token handling to HTML form example (#183) 2023-12-03 21:37:00 +03:00
extra/systemd chore(systemd): add systemd service files (#22) 2022-03-25 23:51:20 +03:00
fixtures refactor(server): use more specific HTTP status codes (#262) 2024-03-11 14:00:45 +01:00
img docs(readme): add README.md 2021-07-26 21:29:46 +03:00
shuttle feat(server): improve random_url config handling (#122) 2023-08-20 20:32:41 +02:00
src refactor(server): use more specific HTTP status codes (#262) 2024-03-11 14:00:45 +01:00
.dockerignore docs(example): add information about using HTML form (#51) 2023-05-31 00:21:15 +02:00
.editorconfig chore(style): add editorconfig 2023-07-01 01:21:02 +03:00
.env refactor(server): use .env for auth token 2021-07-24 14:10:30 +03:00
.gitignore test(fixtures): add a test framework along with test fixtures 2022-05-21 15:27:38 +03:00
CHANGELOG.md chore(release): prepare for v0.15.0 2024-03-27 23:03:10 +03:00
Cargo.lock chore(deps): bump tokio from 1.36.0 to 1.37.0 (#268) 2024-04-04 00:09:29 +03:00
Cargo.toml chore(deps): bump tokio from 1.36.0 to 1.37.0 (#268) 2024-04-04 00:09:29 +03:00
Dockerfile chore(project): update crates and rustls deps (#135) 2023-08-30 12:04:52 +02:00
LICENSE chore(license): update the copyright years 2024-03-24 23:45:04 +03:00
README.md docs(readme): remove blog post link 2024-05-05 14:01:07 +03:00
RELEASE.md docs(release): add release instructions 2023-12-05 15:17:55 +03:00
codecov.yml chore(codecov): add codecov config (#21) 2022-03-17 00:29:26 +03:00
config.toml feat(server): add delete endpoint (#136) 2023-09-03 17:47:52 +02:00
docker-compose.yml chore(docker): share the config file between host and container 2021-08-09 23:27:35 +03:00


GitHub Release Crate Release Coverage Continuous Integration Continuous Deployment Docker Builds Documentation

Rustypaste is a minimal file upload/pastebin service.

$ echo "some text" > awesome.txt

$ curl -F "file=@awesome.txt" https://paste.site.com

$ curl https://paste.site.com/safe-toad.txt
some text
Table of Contents


  • File upload & URL shortening & upload from URL
    • supports basic HTTP authentication
    • random file names (optional)
      • pet name (e.g. capital-mosquito.txt)
      • alphanumeric string (e.g. yB84D2Dv.txt)
      • random suffix (e.g. file.MRV5as.tar.gz)
    • supports expiring links
      • auto-expiration of files (optional)
      • auto-deletion of expired files (optional)
    • supports one shot links/URLs (can only be viewed once)
    • guesses MIME types
      • supports overriding and blacklisting
      • supports forcing to download via ?download=true
    • no duplicate uploads (optional)
    • listing/deleting files
    • custom landing page
  • Single binary
  • Simple configuration
    • supports hot reloading
  • Easy to deploy
  • No database
    • filesystem is used
  • Self-hosted
    • centralization is bad!
  • Written in Rust
    • blazingly fast!


Packaging status

Packaging status

From crates.io

cargo install rustypaste

Arch Linux

pacman -S rustypaste

Alpine Linux

rustypaste is available for Alpine Edge. It can be installed via apk after enabling the community repository.

apk add rustypaste


pkg install rustypaste

Binary releases

See the available binaries on the releases page.

Build from source

git clone https://github.com/orhun/rustypaste.git
cd rustypaste/
cargo build --release

Feature flags

  • shuttle: enable an entry point for deploying on Shuttle
  • openssl: use distro OpenSSL (binary size is reduced ~20% in release mode)
  • rustls: use rustls (enabled as default)

To enable a feature for build, pass --features flag to cargo build command.

For example, to reuse the OpenSSL present on a distro already:

cargo build --release --no-default-features --features openssl


Unit tests
cargo test -- --test-threads 1
Test Fixtures


The standalone command line tool (rpaste) is available here.


function rpaste() {
  curl -F "file=@$1" -H "Authorization: <auth_token>" "<server_address>"

* consider reading authorization headers from a file. (e.g. -H @rpaste_auth)

# upload a file
$ rpaste x.txt

# paste from stdin
$ rpaste -


$ curl -F "file=@x.txt" -H "expire:10min" "<server_address>"

supported units:

  • nsec, ns
  • usec, us
  • msec, ms
  • seconds, second, sec, s
  • minutes, minute, min, m
  • hours, hour, hr, h
  • days, day, d
  • weeks, week, w
  • months, month, M
  • years, year, y

One shot files

$ curl -F "oneshot=@x.txt" "<server_address>"

One shot URLs

$ curl -F "oneshot_url=https://example.com" "<server_address>"

URL shortening

$ curl -F "url=https://example.com/some/long/url" "<server_address>"

Paste file from remote URL

$ curl -F "remote=https://example.com/file.png" "<server_address>"

Cleaning up expired files

Configure [paste].delete_expired_files to set an interval for deleting the expired files automatically.

On the other hand, following script can be used as cron for cleaning up the expired files manually:

#!/bin/env sh
now=$(date +%s)
find upload/ -maxdepth 2 -type f -iname "*.[0-9]*" |
while read -r filename; do
	[ "$(( ${filename##*.} / 1000 - "${now}" ))" -lt 0 ] && rm -v "${filename}"

Delete file from server

Set delete_tokens array in config.toml to activate the DELETE endpoint and secure it with one (or more) auth token(s).

$ curl -H "Authorization: <auth_token>" -X DELETE "<server_address>/file.txt"

The DELETE endpoint will not be exposed and will return 404 error if delete_tokens are not set.

Override the filename when using random_url

The generation of a random filename can be overridden by sending a header called filename:

curl -F "file=@x.txt" -H "filename: <file_name>" "<server_address>"


To start the server:

$ rustypaste

If the configuration file is not found in the current directory, specify it via CONFIG environment variable:

$ CONFIG="$HOME/.rustypaste.toml" rustypaste

To enable basic HTTP auth, set the AUTH_TOKEN environment variable (via .env):

$ echo "AUTH_TOKEN=$(openssl rand -base64 16)" > .env
$ rustypaste

You can also set multiple auth tokens via the array field [server].auth_tokens in your config.toml.

If neither AUTH_TOKEN nor [server].auth_tokens are set, the server will not require any authentication.

Exception is the DELETE endpoint, which requires at least one token to be set. See deleting files from server for more information.

See config.toml for configuration options.

List endpoint

Set expose_list to true in config.toml to be able to retrieve a JSON formatted list of files in your uploads directory. This will not include oneshot files, oneshot URLs, or URLs.

$ curl "http://<server_address>/list"


This route will require an AUTH_TOKEN if one is set.


It is possible to use an HTML form for uploading files. To do so, you need to update two fields in your config.toml:

  • Set the [landing_page].content_type to text/html; charset=utf-8.
  • Update the [landing_page].text field with your HTML form or point [landing_page].file to your html file.

For an example, see examples/html_form.toml


Following command can be used to run a container which is built from the Dockerfile in this repository:

$ docker run --rm -d \
  -v "$(pwd)/upload/":/app/upload \
  -v "$(pwd)/config.toml":/app/config.toml \
  --env-file "$(pwd)/.env" \
  -e "RUST_LOG=debug" \
  -p 8000:8000 \
  --name rustypaste \
  • uploaded files go into ./upload (on the host machine)
  • set the AUTH_TOKEN via -e or --env-file to enable auth

You can build this image using docker build -t rustypaste . command.

If you want to run the image using docker compose, simply run docker-compose up -d. (see docker-compose.yml)


Example server configuration with reverse proxy:

server {
    listen 80;
    location / {
        proxy_pass                         http://localhost:8000/;
        proxy_set_header Host              $host;
        proxy_set_header X-Forwarded-For   $remote_addr;
        proxy_set_header X-Forwarded-Proto $scheme;
        add_header X-XSS-Protection        "1; mode=block";
        add_header X-Frame-Options         "sameorigin";
        add_header X-Content-Type-Options  "nosniff";

If you get a 413 Request Entity Too Large error during upload, set the max body size in nginx.conf:

http {
    # ...
    client_max_body_size 100M;


Pull requests are welcome!

Consider submitting your ideas via issues first and check out the existing issues.


All code is licensed under The MIT License.