Shortline — Self-Hosted Link Shortener & Click Analytics

Preview and demo
Status: unchecked. Availability checks are not a security guarantee.
Description
Shortline is a complete, self-hosted URL shortener with privacy-friendly click analytics and a documented REST API. Own your short links and your data — no SaaS fees, no per-click pricing. Built with Node.js + Express + TypeScript + Prisma (SQLite) and a clean, responsive dashboard.
A real, installable application — not a starter: database, migrations, seed data, auth, roles, REST API with API keys, Docker and tests, all included.
Highlights
- Short links: custom or auto slug, destination, title, tags, active toggle, expiry and click cap.
- Redirect engine (301/302) with privacy-friendly click logging — visitor IPs are hashed, never stored raw.
- Analytics: clicks over time, top referrers, device/OS/browser breakdown; QR code per link.
- REST API with API keys, an OpenAPI 3 spec and an in-app explorer.
- Security: Helmet, CORS allowlist, rate limiting, Zod validation, bcrypt, hashed API secrets, http(s)-only destinations, ownership checks.
- Prisma + SQLite (swap to Postgres/MySQL), bundled migration + seed, Vitest tests, Docker + docker-compose.
Features
Requirements
- Node.js 20+ and npm
- No external database required (SQLite by default); Postgres/MySQL optional
- Reverse proxy (e.g. Nginx) with TLS recommended in production
Changelog
Frequently Asked Questions
Does it need a database server?
No. Shortline uses SQLite by default — a single file, zero configuration. You can switch to Postgres or MySQL by changing the provider in prisma/schema.prisma and the DATABASE_URL.
Is it a starter or a finished app?
A finished, installable application: dashboard, redirect engine, analytics, REST API, auth, roles, migrations and seed data are all included and working.
How is visitor privacy handled?
Visitor IP addresses are hashed with a per-install salt and never stored raw. There are no third-party trackers — analytics are computed from your own data.
Does it have an API?
Yes. A REST API secured by API keys, with an OpenAPI 3 spec at /api/openapi.json and an interactive explorer at /api/docs.
Can I run it with Docker?
Yes. A Dockerfile and docker-compose.yml are included; migrations run automatically on container start and the database lives in a named volume.
What do I get?
The full TypeScript source, Prisma schema/migration/seed, tests, Docker config and documentation. You can read, customise and extend everything.
Automated scan in progress
The automated security scan for version 1.0.0 has not completed. No scan result is shown for this version yet.
Technical requirements
- See the detailed requirements in the product description below.
What is included
- Self-hosted app package with full downloadable files
- Product listing and product page guidance
- Product files ready for self-hosting or integration
- 11 listed features
- Changelog included on the product page
Who is this product for
- Buyers who need a self-hosted app rather than a custom build from scratch
- Teams shopping within Node.js
- Use cases aligned with nodejs, express, typescript, url shortener
License and usage
- Regular license for one end product where end users are not charged for access to the item itself
- Extended license for one end product where end users can be charged
- Verify the exact usage rights on the selected license before deployment or client handoff
- Keep the purchase record and license certificate for future verification
Updates and support
- 6 months of seller support included
- Review the seller support scope before purchasing.
- Recent changes are visible in the product changelog
- Use the changelog to confirm ongoing maintenance before rollout
Technical details
- Current version
- 1.0.0
- Last updated
- Jul 11, 2026
- License options
- Regular, Extended
- Support period
- 6 months of seller support included
Marketplace review
Content review processNo completed marketplace review record is available for this product.
This is not a full penetration test or a guarantee that the product is vulnerability-free.
License comparison
A license is tied to one end product, not strictly to one domain. Development, staging, and the final production domain may belong to the same licensed deployment.
| Use | Regular License | Extended License |
|---|---|---|
| Source code modification | ||
| Own project use | ||
| One client project | ||
| One production deployment | ||
| Development and staging | ||
| Paid SaaS or paid user access | ||
| Multiple unrelated client projects | ||
| Redistribute source code | ||
| Resell source code |
License FAQ
Can I modify the source code?
Yes, under both licenses.
Can I use the script for a client?
Yes, for one client end product.
Can I install it on a staging domain?
Yes. Development and staging may belong to the licensed deployment.
Do I need another license for another client?
Yes, each unrelated client end product needs its own license.
Can I use it for a paid SaaS?
Yes, with an Extended License.
Can I resell the source code?
No. Standalone redistribution or resale is prohibited.
Is a license limited strictly to one domain?
No. It is tied to one end product, which may use development, staging, and production domains.
For one end product — free to end users
Item Details
- Last Update
- July 11, 2026
- Published
- June 28, 2026
- Version
- 1.0.0
- Category
- Node.js
- Sales
- 0
- Reviews
- No reviews
Buying guides
Share This Item
License Info
Regular License — Use in one end product which end users are not charged for.
Extended License — Use in one end product which end users can be charged for.
Verify a license key →