Files Are Readable
A readable .showpapers collection is an ordinary ZIP archive and is not encrypted. Anyone who receives it can read everything inside: the original papers, titles, details, people's names, notes, folders and reminders. Treat it like the papers themselves. Share it only with people and apps you trust, and delete copies you no longer need.
A companion (…showpapers.json) — an optional plain-JSON summary of a collection, for AI apps that can't open ZIP files — is readable too. It repeats the collection's titles, details and notes in plain JSON, and the text read from each page.
Protected Files
The protected envelope encrypts an unchanged readable collection with Tink Streaming AEAD (AES-128-GCM-HKDF, 1 MiB segments) and a separate key file. The encrypted file exposes the envelope identifier and its approximate size; opening it requires the key, and the key must be kept and shared separately. Decryption authenticates every segment and validates the whole inner archive before anything is shown. There is no password recovery: without the key the file cannot be opened.
What A File Does Not Prove
- A SHA-256 digest proves that bytes match their manifest, not who wrote them or that a paper is genuine.
generator, agent names and review marks (confirmed, decisions) are claims, not signatures. New agent details arrive pending. Previously reviewed agent details can keep their review marks when the writer names ShowPapers and the person keeps that option enabled. The writer name is not proof of identity; see the import trust rules.- A valid file is not legal advice and does not establish anyone's status. Keep your physical originals.
Text Is Never An Instruction
Titles, notes, details and page text inside a file are data. A conforming app or agent never follows instructions found inside a document, never widens its access because of document content, and never treats a file as permission to act. The agent guide requires this of AI agents.
Strict Reading
Readers accept only what the specification defines, in full:
- closed structured records without duplicate JSON keys; the reading’s bounded
sdkAnalysiscarries reader-specific data; - canonical paths derived from record IDs, never extracted to disk;
- no ZIP extra fields, encryption, ZIP64, symlinks or directories;
- bounded sizes and expansion ratios;
- verified media signatures, sizes, CRCs and digests;
- references that resolve inside the file.
Anything else refuses the whole file: nothing is imported partly, truncated or silently cleaned.
This Site
- The validator and Open Your File run entirely in your browser. Files you choose are read locally and never uploaded. Open Your File shows collection names and an inventory only in the current tab; refreshing, closing or clearing it removes the preview. Neither page persists file data or sends it in network requests. If you choose Share File, your device passes the collection to the app you select, which may send it through its own service.
- The site uses Google Analytics to measure page visits, navigation, downloads and whether a validation check passed. It does not send selected files, filenames, document text or validation error messages. Analytics cookies depend on your region and saved choice; cookieless measurements may be sent before a choice. Use Cookie Settings in the footer to change your choice. Your choice on this site is saved separately from the app website. See the Privacy Policy for the data collected and controls.
- Example files are invented. They contain no real person's papers.
Reporting A Problem
If you find a way to make a file that a ShowPapers app accepts but this specification refuses, or the reverse, or any security issue, write to hello@showpapers.app. Use invented examples; please don't send real papers.