Proving you control a host unlocks the dashboard about your own project — free, private, and conditional on nothing. It is also how you replace a token you have lost: the same first three steps, because control of the domain is the only credential this system has. Step four says where your files are, and a project that has already been fetched does not repeat it.
Proving control means publishing something you were just given, not pointing at something already published. Anyone can read a public file, so a file alone would let any passer-by claim any host that followed the instructions.
There is no password, no email and no session. We store only the hash of your token, so we cannot show it to you again and we cannot recover it for you. That is deliberate — an account we could recover is an account somebody could talk us into recovering for them.
Put exactly this text at:
Contents:
Not a secret — it has to be readable by anyone, which is what makes it proof of control. Leave it published: it is also how we re-confirm later that you still control the host.
And keep this. It is shown once and never published.
A public file shows that somebody controls this host. It cannot show that the somebody is you — anyone can read it, and on a forge anyone can read the repository it lives in. This second half is what makes the claim yours: it is the value the published one is a hash of, we never publish it, and step three will not finish without it. Nothing else on this page is secret.
Your token. This is shown once.
Storing it here is a convenience, not a backup. Clearing your browser data clears it, and forgetting it is not the same as revoking it.
The three steps above prove you control the host. They do not say where your
.podshl/ is, and until you do, nothing is fetched — a token on its
own is an account with no project attached to it.
Leave it as the bare host if .podshl/ is at the top.
On shared hosting — a forge's pages, one project among several — give the path,
and nothing outside it is ever fetched.
Run these same three steps again. The new token works immediately and every token issued for this domain before it stops working. Anyone who can publish the challenge file already controls the domain, which is the only thing this system was ever checking.
Revoke it from your dashboard. That stops every token for the domain — including the one you are holding — and then you re-prove. It revokes all of them because they are indistinguishable to you: you saw each one exactly once, so "revoke the one that leaked" is not an instruction anybody could follow.
Withdraw from your dashboard. The mirror stops, the attestation is withdrawn,
and your anchor goes back to unknown — where every project starts,
and which says nothing about anybody. Nothing in your repository is touched, and
you can come back whenever you like.