# MicroBin: a single-binary pastebin and URL shortener in Rust

> MicroBin is a self-hosted paste, file upload and link redirection service that ships as one Rust executable. It is small enough for a home server, but its defaults assume you will put authentication in front of it.

**szabodanika/microbin** — A secure, configurable file-sharing and URL shortening web app written in Rust.

- Repository: https://github.com/szabodanika/microbin
- Website: https://microbin.eu
- Stars: 4,573 · Forks: 321
- Language: Rust
- License: BSD-3-Clause
- Published: 2026-09-23 · Updated: 2026-09-23 · Language: en
- Canonical page: https://hysenlabs.com/projects/szabodanika-microbin

## What MicroBin is for, and who runs it

MicroBin calls itself a paste bin web application, but the README treats three things as the same object: pasted text, uploaded files, and URL redirections. All three are "uploads" with an identifier. The README lists the intended uses as sending long texts, sending large files, sharing secrets or sensitive documents, acting as a URL shortener, serving raw file content, moving files between a desktop and a console-only server, running a postbox where visitors can send you files but cannot see or remove what others sent, and taking quick notes.

That list points at one operator with a handful of users, not a public multi-tenant service. The features that make it pleasant for that operator are the small ones: identifiers are animal names drawn from a set of 64 rather than random numbers, uploads can be public or private, editable or not, and set to expire automatically or never. If you are the person who ends up pasting a config file into a chat window, MicroBin is aimed at you.

## How the Rust service is put together

Cargo.toml shows an Actix Web application (actix-web 4 with cookies, http2, brotli and gzip compression) rendering pages through Askama templates, with the templates directory at the repository root. Persistence is rusqlite with the bundled feature, so SQLite is compiled in rather than linked against a system library, and it is an optional dependency; the README also lists JSON database support, which is what the MICROBIN_JSON_DB setting switches. File uploads go through actix-multipart, filenames are passed through sanitize-filename, MIME types are guessed with mime_guess, and QR codes come from qrcode-generator.

The Dockerfile explains the deployment shape. A build stage on rust:1 produces the release binary; the runtime stage is gcr.io/distroless/cc-debian12, which has no shell and no package manager. Time zone data and CA certificates are copied across, the binary lands at /usr/bin/microbin, and the container runs as uid/gid 65532. The data directory /app/microbin_data is declared as a volume, and the container exposes port 8080. So the whole product is one process, one binary, one writable directory.

## Installing MicroBin with Docker Compose

The README offers a quick setup script, `bash <(curl -s https://microbin.eu/docker.sh)`, and a manual Cargo route. For a server you intend to keep, the compose.yaml in the repository is the more readable option, because every setting is an environment variable you can see and edit. The published image is danielszabo99/microbin:latest, and the host port is taken from MICROBIN_PORT while the container listens on 8080.

The compose file mounts a named volume at /app/microbin_data. Its comment explains why: Docker initialises a named volume from the image with the correct ownership (uid/gid 65532), so the nonroot user can write to it. If you prefer a bind mount, the same comment gives the replacement and the fix:

```bash
mkdir -p ./microbin-data && chown 65532:65532 ./microbin-data
```

Then swap the volume line for `- ./microbin-data:/app/microbin_data`. Skipping the chown is the most likely first failure, because the process runs as 65532 and will not be able to create its database or upload files in a directory owned by root.

## Installing from Cargo and running the binary

If you would rather not use Docker, the README gives a four-line Cargo install. It fetches the crate, downloads the sample .env file from the repository, sources it, and starts the server:

```bash
cargo install microbin
curl -L -O https://raw.githubusercontent.com/szabodanika/microbin/master/.env
source .env
microbin
```

Cargo.toml sets rust-version to 1.88.0, so an older toolchain will refuse to build. The .env file at the repository root is the template for the configuration; the compose.yaml forwards the same names as MICROBIN_* variables, including MICROBIN_BASIC_AUTH_USERNAME, MICROBIN_BASIC_AUTH_PASSWORD, MICROBIN_ADMIN_USERNAME, MICROBIN_ADMIN_PASSWORD, MICROBIN_EDITABLE, MICROBIN_PRIVATE, MICROBIN_PUBLIC_PATH, MICROBIN_SHORT_PATH, MICROBIN_READONLY, MICROBIN_UPLOADER_PASSWORD, MICROBIN_DATA_DIR, MICROBIN_JSON_DB, MICROBIN_GC_DAYS and MICROBIN_THREADS. The README does not document what each one does; microbin.eu/docs/intro is the place it points to for that. Treat the .env file as the source of truth and read it before you start the service, rather than starting with defaults and fixing them later.

## Encryption, raw serving and the limits that come with them

MicroBin advertises both server-side and client-side end-to-end encryption. Client-side encryption is the more interesting of the two, because it means the server stores ciphertext it cannot read. The trade-off is that the key has to travel to the reader through some other channel, and a lost key means a lost upload. The README does not describe a recovery path, so do not treat an encrypted upload as backed up.

The raw endpoint is the other feature worth understanding before you enable it. The README gives `server.com/raw/pig-dog-cat` as the way to serve file content directly, and lists serving configuration files for testing as a use case. That is convenient, and it is also the reason to think about MICROBIN_PRIVATE and the basic auth variables together: a raw URL is a plain GET with no session, so whatever protection the instance has applies to it or does not. The README does not document per-upload raw access rules.

Two operational limits are visible in the repository. The Docker image is distroless, so there is no shell inside the container for debugging; you inspect it from outside. And the compose file sets restart: always, which means a misconfigured instance will restart in a loop rather than fail once and stay down.

## MicroBin compared with PrivateBin and Opengist

The search questions people ask are about PrivateBin and about alternatives generally, so the comparison is worth stating plainly. PrivateBin is a PHP pastebin whose defining choice is zero-knowledge encryption in the browser: the server stores encrypted blobs and the decryption key lives in the URL fragment, which never reaches the server. MicroBin supports client-side encryption too, but it is one mode among several, alongside plain text pastes, file uploads, URL redirection and raw serving. If your only requirement is that the server can never read a paste, PrivateBin's model is narrower and easier to reason about. If you also want to shorten links, drop a file and serve raw content from the same instance, MicroBin covers more ground in one binary.

Opengist appears in the same search results and sits at a different point again: it is a self-hosted Gist-style service built around Git, so snippets are repositories with history. MicroBin has no version history concept in the README; uploads are editable or not, and they expire or they do not. Choose Opengist when the history matters, MicroBin when the paste is disposable.

## Licence, maintenance and upgrade cost

MicroBin and MicroBin.eu are published under the BSD 3-Clause License, and Cargo.toml declares license = "BSD-3-Clause". That is a permissive licence: you can run, modify and redistribute it, including in commercial settings, provided the copyright notice and licence text are kept. This is a description of the licence file, not legal advice; if you plan to redistribute a modified binary, read LICENSE and SECURITY.md yourself.

The repository is not archived, and the last push was on 2026-09-08, which is recent. The latest release in the list is v2.1.4 from 2026-03-08, and Cargo.toml sets the package version to 2.1.4, so the crates.io version and the tagged release line up. Upgrades are cheap in the Docker case: pull the image and restart, with the data in the named volume or your bind mount. The Cargo case is a `cargo install microbin` away, but note that rust-version 1.88.0 means your toolchain has to keep up. One dependency detail worth knowing before you pin versions: Cargo.toml carries a comment that the rustls-rustcrypto version must support the rustls version, and rustls must match what reqwest expects, which is why rustls-rustcrypto is pinned at 0.0.2-alpha. If you build from source with a custom TLS provider, that comment is the constraint you are working inside.

## Conclusion

Adopt MicroBin if you want a pastebin, file drop and URL shortener in one small process, and you can run it behind a reverse proxy with basic auth or an uploader password set. Do not adopt it as a multi-tenant service where strangers share one instance and must not see each other's uploads: the README describes a postbox use case, but the listing and privacy settings are instance-wide, not per user. Before you commit, verify which database backend you are running (MICROBIN_JSON_DB or SQLite), confirm where MICROBIN_DATA_DIR points and that the process user can write there, and check that your chosen authentication variables are actually set in the environment.

## FAQ

### What is MicroBin?

MicroBin is a self-hosted paste bin web application written in Rust that also handles file uploads and URL redirection. The README describes it as a single self-contained executable that needs only a few megabytes of memory and disk.

### MicroBin vs PrivateBin: what is the difference?

PrivateBin is built around zero-knowledge browser encryption, so the server stores only encrypted blobs. MicroBin also offers client-side encryption, but it is one mode among several, alongside plain pastes, file uploads, URL shortening and raw content serving from the same instance.

### What are alternatives to MicroBin?

The search results around MicroBin include PrivateBin, a PHP pastebin focused on zero-knowledge encryption, and Opengist, a self-hosted Gist-style service built on Git with snippet history. MicroBin differs from both by combining pastes, file uploads and URL redirection in one binary.

## Sources

- [License: BSD-3-Clause](https://github.com/szabodanika/microbin/blob/master/LICENSE)
- [Project website](https://microbin.eu)
- [README](https://github.com/szabodanika/microbin/blob/master/README.md)
- [Releases](https://github.com/szabodanika/microbin/releases)
- [szabodanika/microbin on GitHub](https://github.com/szabodanika/microbin)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/szabodanika-microbin
