Free · Encrypted · Self-destructing

One-Time Secret

Share a password, API key, or private note with a link that works exactly once. Encrypted in your browser before it ever leaves your device.

Why share secrets this way?

Passwords and API keys sent over email or chat sit there indefinitely — in your sent folder, in the recipient's inbox, in backups neither of you control. A one-time secret link solves that: it exists just long enough to be read once, then it's gone.

The text is encrypted in your browser before it's ever sent to our servers. We store only ciphertext — never the key, never the plaintext.

Choosing an expiration

Pick 1 hour for something you expect to be opened right away, or 7 days if the recipient might not check their messages immediately. Whichever you choose, an unopened link is deleted automatically once it expires.

When to add a passphrase

A passphrase is a second piece of information the recipient needs, separate from the link itself. Send the link one way and the passphrase another — over the phone, in a different app — so a single compromised channel isn't enough to expose the secret.

Frequently Asked Questions

Is this really only readable once?

Yes. The moment a secret link is opened, the encrypted data is deleted from our database — atomically, so even a retry or a second person opening the same link at the same time can't see it twice.

Do you ever see the secret's contents?

No. The text is encrypted in your browser before it's sent anywhere. The decryption key lives only in the link itself (after the # symbol), which never gets sent to our servers — only the encrypted ciphertext does.

What happens if the link expires before it's opened?

You choose how long a link stays available — 1 hour, 1 day, or 7 days. If it's never opened in that window, it's automatically deleted and can't be recovered by anyone, including us.

What does the passphrase option do?

It adds a second, separate requirement the recipient must know to unlock the secret — useful if you're sending the link over one channel (e.g. email) and the passphrase over another (e.g. text message), so no single intercepted message exposes the secret.

What if I lose the link after creating it?

There's no way to recover it. We don't store the decryption key or keep a history of created links — that's the same privacy-first design as the rest of Passivato.