Documentation

Using Moveshot

Everything a vendor needs to send us a delivery, everything the studio needs to set one up, and an honest account of what makes transfers fast and what keeps them intact.

Sending us files

If someone at Big Shot Pictures sent you a delivery link, this is everything you need.

  1. Open the link

    Click it, or paste it into the box on the homepage. It opens your delivery directly — there is no account to create and no password to set.

  2. Add your files

    Drag files or whole folders onto the page, or use the picker. Folder structure is preserved exactly as you sent it, so a sequence arrives as a sequence.

  3. Start, and keep working

    The transfer runs in the background. You can add more files while it is going, pause it, close the laptop and come back later.

  4. Finish the delivery

    When everything is in, mark it finished. That seals the delivery and tells us it is complete — until you do, we treat it as still arriving.

Which client should I use?

The browser
The default. Nothing to install, works on a locked-down machine, and handles folders. Best for deliveries you can finish in one sitting.
Moveshot Desktop
macOS and Windows. Reads straight off your disk or a mounted volume and keeps its progress on disk, so restarts and multi-day uploads are routine. Use it for full turnovers and large image sequences.
The browser extension
Chrome and Edge. Once installed, the transfer no longer depends on a tab staying open — close it and the upload continues. Useful when you cannot install a desktop app but the upload will take hours.

Destinations

A destination is where a link's files land. It is resolved on our side, after the files are safely received, so a vendor never holds a credential to production storage.

NAS share
An on-prem path on the studio's storage, with path-escape rejection so a delivery can never write outside its own folder.
Google Cloud Storage
Resumable uploads with preconditions, so a retried commit cannot overwrite something newer.
Google Drive
Including shared drives, for deliveries that need to live where a production team already works.
Backblaze B2
Through the S3-compatible API, for archive-tier deliveries.
A folder on your Mac
Moveshot Desktop can be the destination: pick a local folder and point a link at it. The absolute path and the OS permission never leave your machine.

Routing happens after receipt, not during it. That separation is what lets a destination be slow, rate-limited or briefly unavailable without costing the vendor their upload — we already hold the verified files and keep retrying the commit.

Speed

A single stream over a long-haul link spends most of its life waiting for acknowledgements. Moveshot is built to keep the pipe full instead.

Parallel chunks
Files are split into chunks and many are in flight at once. Throughput stops being limited by one round trip and starts being limited by your actual bandwidth.
Bounded bytes in flight
There is a global cap on how much unacknowledged data exists at any moment. That is what keeps a fast link saturated without collapsing a shared office connection or exhausting memory.
One file at a time, then backfill
Chunks concentrate on the current file so it finishes and can be routed, while spare capacity fills from the tail of the queue. You get files landing steadily rather than everything at 90%.
Bounded file handles
A delivery with 40,000 frames does not open 40,000 files. The desktop agent holds a small pool and cycles through it.

Getting the most out of your connection

Use a wired connection if you have one — Wi-Fi is usually the narrowest part of the path for a large turnover. Send from the fastest disk the files live on rather than a slow external drive or a network volume mounted over the same link you are uploading through. If your office runs a proxy or an inspecting firewall, it will cap you well below your line rate; ask us and we will tell you what to allow.

Reliability

The interesting question is not how a transfer behaves when the network is perfect. It is what happens when it is not.

Every chunk is verified
Each chunk carries a SHA-256 hash that is checked on arrival. A chunk that does not match is rejected and re-sent — it is never written as if it were fine.
Acknowledgements are durable
We record what we hold before we say we hold it. After a reconnect, the client asks what already arrived and sends only the gaps.
Resume survives a restart
Progress lives in a journal — on disk for the desktop app, in the browser's own storage on the web. Close the lid, reboot, come back tomorrow: the delivery continues rather than starting over.
Adding files does not reset progress
A delivery can grow while it is running. New files join the queue; everything already received stays received.
Retries are idempotent
Registering the same file twice, or retrying a commit after a timeout, produces one file — not a duplicate and not a corrupted merge.

Received and Delivered

These are two different promises and Moveshot never merges them. Received means we hold the complete, verified files. Delivered means the destination committed them and returned a receipt. A delivery can be fully received while a destination is still catching up, and the status you see says which one is true.

Security & access

A delivery link is a credential. Moveshot treats it like one.

Shown once, stored hashed
A link's token is displayed exactly once, at creation. We keep only its hash, so nobody — including us — can recover it later.
Encrypted in transit
Every transfer runs over HTTPS. Tokens are never placed in logs.
Scoped to one delivery
A token opens its own link and nothing else. It grants no view of other vendors, other deliveries, or where anything is stored.
Destinations stay on our side
Storage credentials live in the backend. A vendor client never holds one, so a compromised laptop cannot reach production storage.
Revocable immediately
Revoke a link and new submissions are denied from that moment, whatever the expiry said.

Troubleshooting

“That does not look like a delivery link”
Paste the whole link, including the part after /d/. If it was split across two lines in an email, join it back up first.
The link says it is expired or revoked
It is closed on our side. Ask your contact at the studio for a new one — links cannot be reopened.
A file needs re-selecting
The browser lost permission to read it, usually after a reload, or the file changed on disk. Pick it again and the transfer continues from where it was.
The upload is slower than your connection
Try a wired connection and a local disk first. If it is still slow, a proxy or inspecting firewall is the usual cause — tell us and we will work out what to allow.
You closed the tab and lost progress
The browser needs its tab; the extension and the desktop app do not. For a long upload, use one of those.