The payload lives server-side and the URL carries an opaque code drawn from an alphabet with no O/0, I/1/L or U. The same target reuses one code, so a reschedule link is identical in the confirmation and in every later reminder. The code doubles as a per-person handle for attribution.
Also called: that link looks broken · long ugly URL · shareable booking link
- 1A fingerprint of the target (host, type, card, reschedule target, email) keys the lookup so the same target never mints a second code.
- 2Losing a race on the unique fingerprint falls back to the winner's code.
- 3If the table cannot be written, it falls back to a legacy self-contained signed token — 'a long link beats no link in an email that needs one'.
- 4Legacy tokens still verify by signature and must: links already sitting in inboxes have to keep working. The two are told apart by shape.
- 5Opening a link stamps a best-effort last-used time that can never fail the lookup.
Migration 259 quotes “the link is just ridiculously long… it looks really bad.” It explains why that matters: '~200 characters with no spaces in it. In an email that is a wall of gibberish that wraps across four lines and reads as broken or unsafe.' The library adds the warning against tidying up: 'Do not delete the HMAC path.'
- Unshareable link length
- Reschedule links changing between sends
See it on your own jobs
Twenty minutes, your numbers, no slide deck. We’ll build one of your real buildings in front of you and send you the estimate link at the end — yours to keep either way.
or keep browsing features →