Repository navigation
v0.3.14 — opt-in link previews for private sites and shares
✨ New
Paste a Cloudglue link into Slack, iMessage, Notion, or Discord and it can now unfurl as a real card — title, description, thumbnail — instead of a bare URL or a generic "Sign in" box.
Public sites and shares already previewed. For a public site, the card comes from the Open Graph tags in the HTML you generate, so this release teaches every authoring surface to emit them on each publish: og:title, og:description, og:image (an absolute URL — a share's preview_url works), og:url, twitter:card. Regenerating a page without them silently reverts the card to a bare link, which is the failure this guidance exists to prevent. Unfurl bots don't run JavaScript, so the tags must be in the static HTML.
Private sites and shares never reached the bot at all — the edge gate redirects it to sign-in before any HTML is served. They now opt in explicitly:
# Private site: card = --preview-title + the site description + --preview-image
tinycloud publish ./site --visibility private --link-preview full \
--preview-title "Q3 launch clips" \
--preview-image "https://…/preview.png" --json
# Private share: card = the share's own title, description, and thumbnail
tinycloud publish video ./launch.mp4 --visibility private \
--name "Q3 launch review" --link-preview full --json--link-preview noneis the default and stays today's behavior.- Flipping the setting on an existing site is a settings PATCH — no re-upload, no new version — reported as the new
settings-onlyaction. On an existing share it reuses the share. --preview-imagemust be publicly fetchable: site assets sit behind the same gate the bot can't pass. It's validated as an absolutehttp(s)URL before anything uploads.--preview-title/--preview-imageare site-only and require--link-preview full; both rules are enforced rather than silently ignored.
⚠️ Before you turn it on
--link-preview full makes the card title, description, and image readable by anyone who fetches the link — the user-agent check only routes requests; the setting is the security boundary. Nothing else is exposed: no site content, no video, no tokens or cookies, and playback stays sign-in gated in every mode. Platforms cache the unfurl per exact URL and rehost the image, so switching back to none stops future previews but does not retract cards already posted.
Because of that, the skill and system prompt both tell the agent to ask you first before opting a private artifact in.
Notes
Still 16 verbs; features 33 → 34 with the new publish.link.preview.v1 id. The bundled Cloudglue SDK moves to 0.7.20 for the share link_preview parameter. The skill floor rises to 0.3.14, since the skill now teaches the new flags.
Install
curl -fsSL https://app.cloudglue.dev/tinycloud.sh | bash
# or
npx @cloudglue/tinycloud@latest