URL-first, no-account, real-time collaborative pads. A modern Dontpad successor.
Live at padline.page — open any URL and start typing.
Open a URL → it's a pad. Share the link → you're collaborating. A pad is a lightweight Notion-style page with live cursors, presence, offline resilience, and snapshot history. No accounts, no onboarding, no friction.
- ✏️ Rich collaborative editing — Notion-style blocks (BlockNote) over Yjs CRDTs; simultaneous edits merge conflict-free
- 👥 Presence — live cursors, selections, and auto-generated identities ("Mellow Otter") you can rename
- 🔗 URL-first —
padline.page/anything-you-likeis the pad; empty pads cost nothing until the first keystroke - 🔒 PIN protection — optional per-pad PIN gates both viewing and editing, enforced server-side with brute-force backoff
- 👁️ Read-only links — share a view-only capability URL; rotate it anytime to revoke old copies
- 🕘 Snapshot history — automatic snapshots; restoring is itself an undoable edit, never a rollback
- 📴 Offline resilience — every visited pad is cached in IndexedDB; brief disconnections lose nothing
- 📊 Status line — live word, character, block, and reading-time counts beside a labelled sync indicator
- 📤 Markdown export — copy or download; your content is never trapped
- 🚩 Reporting & moderation — a Turnstile-gated report form, cases, evidence with retention, freeze/block/remove, totals and exports, all in a tamper-evident log (ADR-0018)
- 🛡️ Abuse invariants — document size caps, connection caps, message limits, per-IP caps (ADR-0008, ADR-0009)
| User guide | Using pads: sharing, PINs, read-only links, history, export, limits, reporting |
| Self-hosting | Local dev, deploying, secrets, edge rules, upgrades, troubleshooting |
| Operating a public instance | Your legal responsibility, and what's specific to Brazil |
| Moderation guide | Handling reports end to end, evidence, totals, exports |
| Reference | CLI · HTTP & WebSocket API · Configuration & limits |
| Architecture | Modules, flows, storage, security boundaries, tests |
| ADRs · CONTEXT.md | Why each decision was made · the domain vocabulary |
All of it is indexed in docs/.
The whole app is one Cloudflare Worker: static assets, an HTTP API, one Durable Object room per pad, and one moderation ledger.
flowchart LR
B[Browser<br/>React + BlockNote + Yjs] -->|"WebSocket (Yjs sync + awareness)"| W[Cloudflare Worker]
B -->|"HTTP ops and reports"| W
W --> DO["Durable Object per pad<br/>(y-partyserver room)"]
W --> L["Moderation ledger<br/>(one Durable Object)"]
L -->|takedowns| DO
B <-->|offline cache| IDB[(IndexedDB)]
Authorization happens before any document bytes are sent, every takedown goes through the ledger and is recorded, and there is no list of pads by design. The architecture page walks through each flow.
Stack: React 19 · Vite · Tailwind v4 · shadcn/ui · BlockNote · Yjs · y-indexeddb · Hono · Cloudflare Workers · Durable Objects (SQLite) · y-partyserver · Turnstile
git clone https://github.com/idcesares/padline.git
cd padline
npm install
npm run dev # http://127.0.0.1:8788Open http://127.0.0.1:8788/my-first-pad in two tabs and type in one. For local secrets, tests, and the Windows notes, see Self-hosting.
npx wrangler login
npm run deployPadline runs on the Cloudflare free tier. Before opening an instance to the public, point wrangler.jsonc at your own domain, set the moderation secrets, and read Operating a public instance — the legal responsibility is yours, and this repository's policies were written for padline.page's operator under Brazilian law. The full checklist is in Self-hosting.
Contributions are welcome — see CONTRIBUTING.md for setup, verification, and the PR flow. Security issues: see SECURITY.md. A report about a pad's content is a moderation matter, not a vulnerability — use the report form.
The deployed service publishes its Terms of Use, Privacy Policy, and Content Policy, served by the app itself (src/routes/legal.tsx). If you self-host, rewrite them for your own deployment and jurisdiction.
public/robots.txt, public/sitemap.xml, and public/llms.txt document the crawling and AI-assistant-citation policy — see ADR-0012.
Padline is written by AI coding agents under human product direction. Product decisions, architecture, and trade-offs are human-owned and human-reviewed; the agents do implementation, refactoring, and test coverage against specs written for them.
That split is auditable rather than asserted. docs/adr/ carries a
numbered ADR for every non-obvious decision — what was chosen, what was
rejected, and why — and AGENTS.md is the working contract the
agents follow.
This describes how the software is written, not how it runs. Padline ships
no AI features and makes no model calls. Pad content stays between your browser
and its Room and is never sent to a model — AI features are explicitly deferred
(see CONTEXT.md).
MIT © Isaac D'Césares — created and directed by a human, implemented with AI assistance.