Claim-Link Generator
Let someone claim, edit, or take over their page with a magic link: no account, no password, HMAC-signed.
- What
- Let someone claim, edit, or take over their page with a magic link: no account, no password, HMAC-signed.
- Cost
- Free
- Needs
- Add magic claim links to your directory in four steps. You need: a server/edge runtime with HMAC-SHA256 (WebCrypto or Python hashlib) and a secret vault.
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
The Claim-Link Generator lets someone claim, edit, or take over their page with a magic link: no account, no password. One signed URL per recipient lets them take over their listing, edit the description, add links, and manage it themselves, with zero signup friction. It was proven across 255 creators with free, frictionless, expiry-bounded links. The mechanism is simple and robust. The token is HMAC-SHA256 over a domain-separated payload: the literal prefix "claim." plus the lowercased email, a pipe, and a unix expiry timestamp, hex-encoded. The token carries email, expiry, and signature, so verification needs no database lookup for the signature check itself: the server recomputes the HMAC, compares in constant time, and rejects expired tokens. Thirty days of TTL is plenty; shorter for sensitive actions. One token claims everything tied to that email (all their listings), not one token per item, which means fewer emails and fewer lost links. The claim page works with zero JavaScript because email recipients open links everywhere, and expired or tampered tokens show a plain "link expired" page with a resend option, never a stack trace. The trust contract matters as much as the crypto: every claim email also offers the inverse ("rather not be listed? reply and I'll remove it"), because claim links build trust only when removal is one reply away. Tokens are bearer credentials, so they never go into logs, analytics URLs, or forwards, and the signing secret lives in a vault, never in the repo or the client bundle. Rotating the secret invalidates outstanding links, which is acceptable since links are reissued on demand.
Version:
Install
Copy the install package below, then paste it into MuseCommunity-built. Skill Harbor doesn't audit code — review the source before installing.
Add magic claim links to your directory in four steps. You need: a server/edge runtime with HMAC-SHA256 (WebCrypto or Python hashlib) and a secret vault. 1. Sign: token = HMAC-SHA256(secret, "claim." + email.lower() + "|" + expiry_unix). Hex-encode it. The "claim." prefix is domain separation so the same secret can sign other token types safely. Build the URL: https://your-site.com/claim?token={token}. Embed a 30-day expiry in the signed payload. 2. Send: include the link in your outreach email, personalized: "Here is your personal link to claim the listing. You can edit the description, add links, and manage the page yourself. It is free. If you would rather not be listed, just reply and I will remove it." 3. Verify: on GET /claim?token=..., split into email, expiry, signature. Reject if expired. Recompute the HMAC and compare in constant time (compare every byte, no early exit). On success, bind the session to that email: set a cookie or mark their listings claimed. One token claims everything tied to that email. 4. Handle expiry gracefully: expired or tampered tokens show a plain "link expired" page with a one-click "resend my link" button that re-sends to the same address. Rules: the secret lives in a vault, never in the repo. Tokens never go into logs or analytics. The claim page works with zero JavaScript.
Saved to your recent installs. Find it anytime on /connect.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.