How file distribution works
- 1
Upload
You upload files via the dashboard. Your browser encrypts them before upload.
- 2
Assign
Files are linked to specific products.
- 3
Download
Users with active subscriptions can download files via the C++ client.
- 4
Decrypt
The C++ client decrypts them in memory with your app’s SDK key.
Uploading files
In the dashboard, navigate to App → Files → [Select product] → Upload file.
Single file upload
- Click Upload file
- Select your file (any format)
- File is encrypted in your browser and stored
- File becomes available for download by subscribed users
Folder upload
- Click Upload folder
- Select a folder with multiple files (must be a zip)
- Folder is encrypted in your browser and stored
- Users can download and extract the folder
Replacing and rolling back
To ship an update, click Replace on a file or folder and pick the new version. It keeps the name, so your app downloads it right away.
The version it replaced is kept. If something goes wrong with the update, click Roll back to make it current again. The version you rolled back from is kept in turn, so you can switch back. One previous version is kept per file or folder; older ones are deleted after 8 days.
In end-to-end encrypted apps your browser signs the rollback, so Vaultix can’t roll anything back on its own. Nothing is re-encrypted, and your app needs no update.
Downloading files
Users can download files with the C++ client after authentication:
C++Copy
Vaultix::VaultixClient client("https://vaultix.cc/api");
client.SetApiKey("ap_your_api_key");
client.SetContentKey("vxk_your_app_key"); // App Settings → End-to-end encryption
// Authenticate first
if (client.AuthenticateWithKey(userKey)) {
std::string productId = "prod_xxxxxxxxxxxxx";
// Method 1: Download by file name
bool success = client.DownloadFile(productId, "update.exe", "./local/update.exe");
if (success) {
std::cout << "File downloaded and decrypted!" << std::endl;
}
// Method 2: List all files and download by ID
auto files = client.ListFiles(productId);
for (const auto& file : files) {
std::cout << "File: " << file.name << " (ID: " << file.id << ")" << std::endl;
client.DownloadFileById(productId, file.id, "./" + file.name);
}
// Method 3: Download entire folder
bool folderSuccess = client.DownloadFolder(productId, "content_pack", "./content_pack");
if (folderSuccess) {
std::cout << "Folder downloaded and extracted!" << std::endl;
}
}
Encryption details
Apps are end-to-end encrypted: files, folders and variables are encrypted in your browser with keys only you and the team members you approve hold. Vaultix stores and forwards them but can’t read or swap them.
| Property | Details |
|---|
| Content | AES-256-GCM in 1 MiB chunks, a random key per file |
| Keys | X25519 and Ed25519, from your 24-word recovery phrase; team members get their own access, opened with their password |
| Authenticity | Every upload is signed by an approved team member; the SDK checks the signature |
| At rest | Sealed file keys are locked again with a server key kept outside the database |
| Delivery | Every download is encrypted again with a one-time key |
| Integrity | Size and SHA-256 are checked after decryption; Vaultix only stores a keyed hash |
Copy the SDK key from App Settings into your app with SetContentKey. The C++ client does the rest with OpenSSL. Older apps keep server-held keys until you turn end-to-end encryption on in App Settings.
File organization
Files are organized hierarchically:
Example
My App
Product: Premium Tier
update_v1.2.exe
config.json
assets_folder/
Users can only access files from products they have active subscriptions to.
Access control
File access is controlled by subscriptions:
- User must have an active subscription to the product
- Subscription must not be expired or paused
- JWT token must be valid (auto-managed by C++ client)
- If HWID binding is enabled, user must be on the bound device
Access denied?
If a download fails, check: subscription status, expiry date, HWID binding, and whether the product contains files.
Download tracking
Every file download is tracked and logged:
- View download count per subscription in the Subscriptions page
- Monitor unusual download activity (e.g., multiple downloads in short time)
- Useful for detecting account sharing or abuse
Best practices
- Use descriptive file names (e.g.,
v1.2.3_update.exe instead of file.exe) - Organize related files into folders for easier distribution
- Update with Replace, so the previous version stays ready for a rollback
- Test file downloads with a test user before releasing to customers
- Monitor download counts for unusual patterns