# TapTrail > TapTrail records a click path through a web app and turns it into a share link. The person who opens the link follows numbered steps on the live page — the page scrolls to each element, a marker pulses on it, a dotted line joins the steps and a tooltip says what to do. It is an interactive walkthrough, not a screen recording, and links expire. TapTrail is a drop-in script plus a small self-hosted Node server with no runtime dependencies. Add one script tag to a web app; anyone on that page can press Record (or Alt+Shift+R, Option+Shift+R or Ctrl+Shift+R on a Mac), click through the app, and get a share link that lasts 1 hour, 1 day or 3 days. A trail is a few kilobytes of element selectors and labels, so it replays at the follower's window size, in their own account, across page loads on the same site. Key facts: - Use it for: answering "where do I click?" in a support reply, handing off a task (rotate a key, invite a user), the path to a bug, a new teammate's first walkthrough of an internal tool, skipping a screenshare, and replacing a video after a release moved the controls. - Replay opens menus, tabs, accordions, side sheets and dialogs (including native ``) that hide the next step. Optional auto-tap presses safe controls (same-site links, tabs, section headers, buttons that open something) and refuses anything that deletes, pays, sends, publishes, signs out or submits. - Typed text is left out by default: a trail says which field was typed in, not what. A site can opt fields in with `data-tt-record`, and then the person recording chooses Keep or Leave out each time. Passwords, card numbers, one-time codes and token-like fields are never kept; emails and long numbers are masked as `[email]` and `[number]`. - `data-tt-ignore` keeps an area out of recordings entirely. - Recording can be limited to staff: load `taptrail.js?record=0` for everyone else and set `UPLOAD_SECRET` on the server so uploads need a short-lived HMAC token signed by your backend. - No accounts, no third-party analytics. Trails are stored on the server you run and deleted when they expire. - Not a fit for: docs that have to stay up (links last at most three days), steps on other sites (shown as a link instead), capturing form input, or session replay and analytics. Install: ```html ``` Script options: `?button=0` hides the record button (shortcut and `TapTrail.start()` still work); `?record=0` makes the page replay-only. JavaScript API: `TapTrail.start({ typed })`, `TapTrail.stop()`, `TapTrail.replay(id)`, `TapTrail.exit()`, `TapTrail.setToken(fn)`. ## Pages - [Home](https://taptrail.cc/): what TapTrail is, how it works in three steps, comparison with screen recordings, privacy summary, install snippet and options, FAQ - [Use cases](https://taptrail.cc/use-cases/): six situations where a click trail helps, and three where it is not a fit - [About](https://taptrail.cc/about/): how recording, sharing and replay work in detail, auto-tap rules, current limits - [Privacy](https://taptrail.cc/privacy/): exactly what a trail stores, typed-text rules, masking, retention, server logs - [Terms](https://taptrail.cc/terms/): rules for recording, sharing and following trails, and responsibilities for site owners ## Try it - [Live demo](https://taptrail.cc/demo/): a pretend admin app (Lumen Console) with menus, tabs, folded sections, dialogs and forms to record and replay a trail on ## Optional - [Full text for LLMs](https://taptrail.cc/llms-full.txt): longer reference covering recording, replay, the HTTP API, server settings and security