∪Magnet Link

Magnet Links, Decoded: One Hash, No Server, and a Swarm That Can See You

A magnet link identifies content by its cryptographic hash instead of its location. Here is what each part of a magnet URI means, how a client finds peers with no .torrent file, and what the swarm learns about you.

Share X in f
Magnet Link Editorial Team

A normal link says where something is: a server name and a path. A magnet link says what something is. It carries a cryptographic fingerprint of the content, and your BitTorrent client uses that fingerprint to find other computers that have the same data. There is no central server to fetch it from, which is why magnet links keep working long after a website that published them has gone.

Anatomy of a magnet URI

Magnet links follow the magnet: URI scheme. A BitTorrent magnet link has this shape (the values below are placeholders, not a real torrent):

magnet:?xt=urn:btih:0123456789abcdef0123456789abcdef01234567
  &dn=example-dataset.zip
  &tr=udp%3A%2F%2Ftracker.example.org%3A6969

Each parameter does a specific job:

  • xt (exact topic) is the only essential part. urn:btih: means “BitTorrent info-hash”, followed by the hash itself. In BitTorrent v1 this is a SHA-1 hash of the torrent’s info dictionary, written as 40 hexadecimal characters (or 32 in base32). BitTorrent v2 uses SHA-256 and the prefix urn:btmh:.
  • dn (display name) is a suggested file name for your client to show while it looks for metadata. It is a label only; nothing verifies it.
  • tr (tracker) lists one or more tracker addresses the client can ask for peers. A link can include several, or none at all.
  • Less common parameters include xl (exact length in bytes), ws (a web seed: an ordinary HTTP URL serving the same files) and so (select only certain files).

Because the info-hash is derived from the content’s metadata, changing a single byte of the files or their names produces a different hash. That is what makes the link self-verifying: whatever your client downloads is checked against the hashes it expects, piece by piece.

How a client finds peers without a .torrent file

A .torrent file contains the info dictionary: file names, sizes and the hash of every piece. A magnet link contains only the hash of that dictionary. So the client’s first job is to find peers and ask them for the metadata. It has three main ways to find them:

  1. Trackers. If the link lists tr addresses, the client asks each tracker, “who has this info-hash?” The tracker replies with a list of IP addresses and ports.
  2. The Distributed Hash Table (DHT). Most clients join a global DHT (based on the Kademlia design) in which millions of nodes each store a small slice of “info-hash to peers” records. The client queries nodes whose IDs are numerically close to the info-hash until it reaches ones that know about peers. This is what lets a magnet link with no trackers still work.
  3. Peer Exchange (PEX). Once connected to a few peers, the client learns about others from them directly.

With at least one peer found, the client requests the info dictionary using the metadata-exchange extension, checks that it hashes to the value in the link, and from then on behaves as if you had opened a .torrent file.

Why magnet links replaced .torrent files

Magnet links are tiny, can be pasted as text, and do not require anyone to host a file. They also resist tampering: a site cannot substitute different content without the hash changing. The trade-off is a short delay at the start while the client fetches metadata, and a dependency on at least one peer being reachable. If nobody in the DHT or on the listed trackers has the content, a magnet link simply stalls at “retrieving metadata”.

What the swarm can see about you

BitTorrent is a public protocol. To exchange data, peers need to connect to each other, which means every peer you connect to can see the public IP address and port you are connecting from, along with the info-hash you are sharing. Trackers log the same information, and DHT queries reveal your interest in an info-hash to the nodes you ask. Anyone can join a swarm and record the addresses in it, and rights holders routinely do exactly that.

A few settings change the picture:

  • Protocol encryption in the client hides BitTorrent traffic from casual inspection by your internet provider, but it does not hide your IP address from peers.
  • Disabling DHT and PEX limits discovery to the trackers you choose, at the cost of finding fewer peers. Private trackers often require this.
  • A VPN with port forwarding, or running the client on a remote server, means peers see the VPN or server address rather than your home connection. The VPN provider then sees your traffic instead, so its logging policy matters.

Legal use

Magnet links and BitTorrent are legal technologies. Linux distributions, open datasets, public-domain archives and some game updates are distributed this way because it spreads bandwidth costs across everyone downloading. What can be illegal is downloading or sharing copyrighted material without permission, and in a swarm, downloading usually means uploading too. Only use magnet links for content you have the right to share.

The short version

A magnet link is a content fingerprint, not an address. The xt hash identifies the data, trackers and the DHT find computers that have it, and the client verifies everything it receives against that hash. It is an elegant, serverless design, and a public one: everyone in the swarm can see who else is in it.