hopefully this isn't honestly being used for sharing anything sensitive considering that it's actually storing inputted data in workers kv.
I understand it's more of a developer demo project, to accompany the app kit, just pointing out the security discrepancy here - something to consider reworking.
have a look at how we're handling similar use-case product/project here at Auth0 with sharelock