Highport orbital control
Welcome aboard
Highport is a service for running your personal website and the things you publish online, at a domain that belongs to you. The rest of this page is about which part of the manual you need.
You publish your pages from an account you already have and point your domain at us, and we serve them at your address. Highport keeps a copy of the files so a visitor's request can be answered without going back to your server, and hands them back when somebody asks.
This manual is the station explaining itself. The first four pages are for people reading a site somebody else published, and the other twenty-two are for the people doing the publishing. None of it is required in order to read a site. If you want the short version instead, How it works is one page.
A site here belongs to whoever published it
Every site is registered to the person who published it, and the files are theirs. We did not write the page. We cannot edit it. We are a host for those files and nothing more. The originals stay in the publisher's own account, which is the copy that counts, so taking a site down here removes nothing from the account it came from.
Nothing of ours runs on the page either. What you were reading is a file somebody stored earlier and we handed back. We inject nothing into it and assemble nothing at the moment you ask, so the bytes you receive are the bytes the publisher stored.
The publisher is held to the same shape. One fixed security policy applies to every site we serve, and no publisher can relax it. Under that policy a page may load nothing from another address and may contact no other address. A third-party analytics script, an image fetched from somebody else's server, a request phoning home in the background: none of it can be on a page we serve. What we ourselves record is a separate question, and the next section answers it.
Reading a site costs you nothing
No account, no sign-in, no cookie. We set no cookie on a published site unless you sign in to that particular site. A publisher's own page can still set one in your browser using its own script; that one is theirs, and it is dropped on the way back to us instead of being read. The public pages on highport.space, this manual among them, set no cookie at all, and requests to them are never written to the log described below.
Reading anonymously is written down as a request, not as a person. The line holds the domain, the path, the status, the size and how long the response took. It carries no address, no request headers and no cookie. There is nothing in it that identifies you. It exists so that bandwidth can be accounted for and so a publisher can see the traffic to their own domain. Those detailed records are kept for thirty days, and the hourly totals that outlive them hold nothing at all about a reader who did not sign in.
Some sites ask you to sign in before they will show you a page. This is where the paragraph above stops holding. Once you have signed in on a domain, that domain's owner gets a row attributed to your account: which account, how many requests, how many bytes, and when you were last there. It is kept for 400 days, and at present there is no way to have it removed. Whether to ask is the owner's decision, not ours. Sites that ask who you are covers what you would be agreeing to and what the owner does and does not learn. If a site here stops answering altogether, When a site is unavailable has the short list of reasons and what each one looks like.
What you can do without signing in
Two directories, both public, neither of which asks who you are.
| Where | What it lists |
|---|---|
| Tile browser | Every ready-made design published here, with its author. Each tile's own page lists what it asks a site owner to fill in, and how many sites use it |
| Sites | Every address published here, and what is serving at it |
A tile is a design somebody else built and published for other people to fill in. A card with your name and your links on it. A notice for a domain you are not using yet. A status page. A site built from one shows which tile it used and who made it; a site whose owner brought their own files shows the address alone. If the word is new, Tiles, from the outside is the short account of what one is and why a stranger's design is safe to visit.
What signing in is for
The Hub, at hub.highport.space, is where publishing happens. Signing in there is for publishing, not for reading. It uses the account you already have, a Bluesky account or any other account on AT Protocol. There is no Highport account to create, no password to invent, and no email address to hand over. Your own server is what shows you the consent screen and issues the credentials.
You need it to register a domain, to publish or edit a site or a tile, and to see anything you own. Everything else here reads without it. Site owner authentication, the first page for site owners, is the full account of what the grant does and does not give us.
Signing in to a published site is a second, unrelated thing. It happens on that publisher's own domain, you never arrive at Highport to do it, and it identifies you on that one domain and nowhere else. Sites that ask who you are is the page for it.
How this manual is arranged
Twenty-seven pages in four sections. You are on the first page of the first section, and most people who arrive here need one more page at most.
| Section | Who it is for | Start at |
|---|---|---|
| Visitors — 4 pages | You are on a site somebody else put here, or one has just asked you to sign in | the three pages below |
| Site owners — 12 pages | You want a page at a domain you own, and everything that happens to it afterwards | Site owner authentication, then Bringing your domain alongside |
| Tiles — 4 pages | You are choosing a ready-made design, or building one for other people to use | Tiles |
| Advanced — 7 pages | You are debugging, integrating, or curious about the mechanism | Validate before you write |
The other three pages in this section, in order:
- Sites that ask who you are — a site asked you to sign in before showing you a page. What that is, and what its owner learns.
- When a site is unavailable — the small number of reasons a site here stops answering, and what the page says when it does.
- Tiles, from the outside — what a tile is, why a design by a stranger is safe to visit, and where to browse them.
None of this is required reading. The station runs the same either way. The manual is here for the day it does something you were not expecting.
Visitors · 1 of 4