-
-
Official Ring review: Cannot verify because capture time is unavailable. The recipient receives no image or private note.
-
The owner revoked a second pending check. The recipient's permission closes.
-
Official Ring Playground video inside Aperture. Edited demonstration still; source capture time remains unavailable.
-
A fixed question about one approved area, with a two-check budget and 15-minute permission. Edited demonstration still.
Inspiration
A parcel handoff can lead to a small question: is the parcel still visible on the doormat? A camera owner may be willing to answer that question while keeping the surrounding footage private. I built Aperture around that limited permission. The owner chooses one object, one area, and how long someone can ask about it.
This is a proposed use case. I have not yet tested the pickup workflow with customers.
What it does
The owner saves a private reference, marks an area, and previews the exact question before creating a pass. Each pass has an expiry, a check budget, and a cooldown. Anyone with its bearer link can request that question; the recipient cannot change the object or area.
The owner reviews each request and approves one of three outcomes: Visible, Not visible in the approved area, or Cannot verify. The recipient receives the approved result and its timing. Reference images, review frames, video streams, and private notes stay in the owner's workspace. The owner can revoke a pass, including while a check is pending.
Aperture connects to the official Ring API for device discovery, image requests, and private WHEP live video. In the verified Ring Playground demonstration, the Package simulation played inside Aperture. I saved a reference frame, created a 15-minute pass with two checks, requested a check, reviewed a second frame, and revoked a second pending request.
The demonstrated answer is Cannot verify. A browser-saved live frame has no verified Ring capture timestamp, so Aperture will not release a definite visibility answer from it. The recipient sees that source time is unavailable and sees the owner's approval time separately. The server enforces this even if a client submits a different answer.
How I built it
The interface uses React, TypeScript, and Vite. A Node.js server stores accounts, references, passes, and checks in SQLite. Sharp strips image metadata and normalizes uploaded or downloaded images. An interactive Three.js illustration explains the permission model, with a keyboard-accessible SVG fallback.
The Ring adapter calls the official REST endpoints directly. It discovers the permitted camera and module, keeps the short-lived Playground credential in server memory, and negotiates WHEP video for the owner. Recipient endpoints cannot return the stream, source identifiers, images, or private notes.
SQLite transactions serialize check budgets, completion, and revocation. Permission is checked again after asynchronous media work and before releasing an answer. Pass tokens are random and stored as hashes. Deleting a reference removes its related images, passes, and observation records.
I used Codex to implement and test the app and Claude desktop for an independent code review. The demo uses Deepgram Aura 2 Thalia narration and FFmpeg encoding. These are development and presentation tools; Aperture does not use AI to recognize objects or decide its answers.
Challenges I ran into
My first image request reached back before the current Ring authorization window and returned TIME_RANGE_NOT_AUTHORIZED. I changed the requested interval to begin no earlier than the verified connection time.
The authorized image request then returned a redirect, but the media download returned MEDIA_NOT_FOUND for the tested Playground events. Live video was available. I added a browser-frame path so the owner could complete the private review workflow, with explicit unknown source timing and a required Cannot verify result. I did not treat the browser's save time as the camera's capture time.
Revocation also had to survive delayed network responses. The final checks cover a stream response arriving after permission closes, cleanup of late frames, and refusal to release a result after expiry or revocation.
Accomplishments
The official Ring simulator flow reached the recipient and the revocation state inside the app. The current automated suite passes 38 tests covering account isolation, finite answers, budgets, expiry, media handling, and Ring integration boundaries. Claude independently reviewed the final changes and ran the suite.
The recipient screen keeps the answer small enough to understand while distinguishing source time from approval time. The verified flow preserved that distinction even when the source could not establish freshness.
What I learned
Seeing a stream play does not establish when its footage was recorded or whether an archived image can be downloaded. Those are separate properties, and the interface needs to preserve that uncertainty through to the recipient.
I also learned to check permission after slow work finishes. Checking only when a request begins leaves a gap for a pass that expires or is revoked while media is loading.
What's next
I want to verify the timestamped snapshot path with authorized real-device media, add production OAuth account linking, and test the parcel handoff with camera owners and recipients. Customer feedback will determine whether the pass is worth the extra step compared with an ordinary message.
Before unrestricted sign-up, the app needs managed authentication, password recovery, operational monitoring, and a retention policy. The current release is intended for a controlled private deployment.
Run and judge it
Source: https://github.com/himanshu748/aperture
Requires Node.js 22.13 or newer and npm. From the repository:
npm ci
npm run build
npm test
npm start
Open http://localhost:4332 and register a private local account with a password of at least 12 characters. There is no seeded account or sample data. Use your own authorized Ring Developer Playground session and its short-lived token; enter it only in Aperture's private Ring source screen.
- Connect Ring and select the discovered camera/module. Start a Package event in the official Playground, then select Start private live view in Aperture.
- Select Use this frame as a private reference, name the object, and mark its permitted area. The frame is labeled browser-saved with unavailable capture time.
- Create a 15-minute, two-check pass and open its link in a recipient browser session. Request a check.
- In the owner's Requested checks, start the reference-bound private live view. Restart the Playground event if needed. Select Save frame for this review, inspect it, and approve Cannot verify.
- Confirm that the recipient receives the finite result, unavailable source time, and separate approval time without the frame or private note.
- After the pass cooldown, request the second check. Revoke the pass while the request is pending and confirm that access closes. Disconnect Ring when finished.
The README and RING-DEMO.md cover the snapshot path, exact security boundaries, and remaining limits. The recorded browser proof used owner and recipient tabs in the same browser; separate-account isolation is covered by API tests.
Demo notes and credits
The 108.8-second English demo is an edited walkthrough of verified browser stills with Deepgram Aura 2 Thalia narration and captions. It is not a continuous recording or physical-device demonstration. The Ring flow demonstrates private review, a conservative answer, and revocation; it does not establish current-world object visibility or successful archived-media retrieval.
Ring Package simulation footage: “Thief stealing our package” by frollard, https://www.youtube.com/watch?v=TfTFu8lGrwk, licensed under CC BY 4.0, https://creativecommons.org/licenses/by/4.0/. Ring provides a clipped version. I edited browser captures into the walkthrough and preserved the visible Ring watermark.
Log in or sign up for Devpost to join the conversation.