Naoko Shoto logo

Notes

Notes support complete GitHub Flavored Markdown with custom extensions:

  1. Inline Code & Code Blocks with syntax highlighting:
async function publishNote(content: string, privateKey: CryptoKey) {
  const timestamp = Date.now().toString();
  const signature = await signMessage(privateKey, `${timestamp}.${content}`);
  
  return fetch('/api/notes/webhook', {
    method: 'POST',
    headers: {
      'Content-Type': 'application/json',
      'X-Timestamp': timestamp,
      'X-Signature': signature,
    },
    body: JSON.stringify({ content }),
  });
}
  1. Blockquotes & Emphasis:

"Simplicity is the ultimate sophistication." — Leonardo da Vinci

  1. Links & Custom Syntax: You can highlight key ideas using custom highlight markers and visit Naoko Shoto's Designworks to explore the full portfolio.

How does the cryptographic webhook work? 🔐

Instead of vulnerable static bearer tokens or passwords, this endpoint (/api/notes/webhook) uses asymmetric Ed25519 digital signatures:

  • Your Private Key never leaves your machine (or your browser's Web Crypto keystore).
  • When sending a request, your client signs a payload combining the timestamp and your Markdown content:
    message = timestamp + "." + content
    
  • The server verifies the X-Signature header against your configured Public Key (WEBHOOK_PUBLIC_KEY).
  • Replay protection rejects stale requests whose timestamps fall outside a 5-minute window.

Click the "Webhook & API Drawer" button at the top of this page to generate a key pair, test live publishing, or copy terminal snippets! 🚀