How to Build a URL Shortener
Build a URL shortener: short codes, custom slugs, fast redirects, click analytics that respect privacy, a short domain, and stopping spammers from abusing it.
Mythex Team · · 5 min read
A URL shortener stores a long web address under a short code and redirects anyone who visits the short link. The core is tiny — one table and one redirect route — which is why it is a classic first project. What makes a real one useful is the rest: a short domain, custom slugs, click counts, editing where a link points, and keeping spammers from using your domain to hide phishing links. Decide early whether it's for you and your team, or open to the public, because public shorteners attract abuse fast.
What a URL shortener needs
Data
| Table | Fields |
|---|---|
| Links | Short code, destination URL, owner, title, created date, active flag, optional expiry |
| Clicks | Link, time, referrer, country, device type |
| Domains (optional) | Custom short domains and their owners |
Put a unique index on the short code. Two links with the same code is the one bug that must be impossible.
Pages and routes
- The redirect route —
/{code}looks up the code and redirects. This is the only route most visitors ever touch, so it must be fast and never show your app's interface. - Create link — paste a URL, optionally choose a custom slug, get the short link with a copy button.
- Link list — your links with click counts, search, and on/off switches.
- Link detail — clicks over time, top referrers, countries, devices. Edit the destination.
- Not-found page for unknown or disabled codes.
- QR code for each link — cheap to add and often asked for.
Decisions and trade-offs
Redirect type. A 301 (permanent) redirect may be cached by browsers, so repeat visitors skip your server: you lose clicks and can't change the destination for them. Use 302 or 307 if you track clicks or allow editing. That's what most tracking shorteners do.
Short codes. Random codes of six or seven characters (letters and digits) are hard to guess and have plenty of room. Avoid confusing characters (0/O, 1/l) if people will type links by hand. Sequential codes reveal how many links you have and let anyone walk through them.
Custom slugs. /launch beats /x7Kp2q. Reserve words your app uses (login, api, admin), block offensive slugs if the tool is public, and decide whether slugs are case-sensitive. Case-insensitive is friendlier.
Speed. A shortener adds a hop before every visit. Keep the redirect route to a single indexed lookup, and record the click after sending the redirect (or in the background) so tracking never slows the visitor down. Apps on hosting that sleeps when idle may take a moment longer on the first visit after a quiet period; for a personal or team tool that's usually fine.
Click analytics and privacy. Counting clicks, referrers and rough country is standard. Storing full IP addresses and building profiles of individuals is where privacy law starts to apply. Store what you'll actually look at, and aggregate where you can. See how to add analytics to your app.
The domain. The link is only as short as its domain. Buy a short domain and point it at the app — see how to connect a custom domain. Many hosts prefer a subdomain (go.yourbrand.com) to a bare root domain, which is simpler to connect.
Abuse. If anyone can create links, spammers will use your domain to disguise phishing and malware, and your domain can end up on block lists. For a public shortener: require accounts, rate-limit creation, check destinations against a malicious-URL list such as Google Safe Browsing, block links to your own shortener (redirect loops), and build an admin switch to disable any link instantly. A private, team-only shortener avoids most of this.
A first prompt that works
Build a URL shortener web app for my team. Logged-in users paste a destination URL and get a short link with a random 7-character code (no 0, O, 1 or l), or choose a custom slug. Slugs are unique and case-insensitive; reserve login, api, admin, app and settings. The public route /{code} looks up the code with a single indexed query and returns a 302 redirect; record the click (time, referrer, country, device type — no full IP address) without delaying the redirect. Unknown or disabled codes show a simple not-found page. Users see a list of their links with click counts, can edit the destination, disable a link, download a QR code, and open a detail page with clicks per day, top referrers and countries. Validate that destinations are http or https URLs and not links to this shortener. Store everything in a database.
Build steps
- Create and redirect. Make a link and open it in a private window. Check the response is a 302, not a page that then redirects with JavaScript.
- Codes and slugs. Try a duplicate slug, a reserved word, mixed case and a very long URL.
- Click tracking. Click from a few devices and check the counts and referrers.
- Edit and disable. Change a destination and confirm the old short link now goes to the new place; disable one and confirm it stops.
- Validation. Try
javascript:links, links to the shortener itself and malformed URLs. All should be rejected on the server. - Domain. Connect your short domain and test links on it.
- Abuse controls, if the tool will be public: rate limits, a destination check and an admin view of recent links.
Common mistakes
- 301 redirects with click tracking. Browsers cache them and your numbers go wrong.
- Redirecting in the page. Load the app, then redirect with JavaScript, and every click feels slow. Redirect from the server.
- No unique constraint on codes. Collisions will eventually happen.
- An open public shortener with no controls. It will be abused, and your domain's reputation goes with it.
- Accepting any URL scheme. Only allow http and https destinations.
- Losing links when you move. Own the short domain yourself so links survive a hosting change.
When a ready-made product is the better choice
Established link management services offer branded domains, detailed analytics, team features, QR codes, integrations and abuse handling out of the box. If links are central to your marketing and you want no maintenance, pay for one.
Build your own when you want a simple team shortener on your own domain without per-seat pricing, links tied into your own product (share links, referral links, tracked links in emails), or full control of click data. It's also a good first backend project. Pair it with a link-in-bio page, and run through the security checklist for AI-built apps before opening it to anyone else.
Building it with Mythex
In Mythex you describe the shortener in chat and test redirects in the live preview. Mythex adds a dedicated database for links and clicks when the app needs one. Published apps and their databases sleep when idle and wake on the next visit, which keeps a quiet shortener cheap to run. Publish to a mythex.ai link, and on Pro connect your own short domain or buy one inside Mythex — see custom domains. The URL shortener template is a ready-written starting prompt with custom slugs and click analytics.
Questions
Should a URL shortener use a 301 or 302 redirect?
A 301 tells browsers the move is permanent, so they may cache it and skip your server next time, which means missed clicks and links you can't change. Most shorteners that track clicks or allow editing use 302 or 307 temporary redirects.
How are short codes generated?
Either as random strings from letters and numbers, checked against existing codes, or by encoding a database ID in base 62. Random codes are harder to guess; sequential ones reveal how many links exist. Six or seven random characters gives billions of combinations.
Do I need a short domain?
Not to work, but the point of a shortener is a short, trustworthy link. A short custom domain you own also means the links keep working if you move hosting.
How do I stop people abusing a public URL shortener?
Require sign-up to create links, rate-limit link creation, check destinations against a malicious-URL list such as Google Safe Browsing, block your own domain as a destination, and give yourself a quick way to disable links.