Home Password Strength Clean URL One-time Encrypt

Share a one-time secret with a self-destructing link

Turn a password, API key, or recovery code into a one-time encrypted link. The key lives after # in the URL. The first read burns it. The recipient does not sign up.

How a one-time secret and self-destructing link work

People search “one-time secret,” “self-destructing message,” or “share a password securely” when chat and email would keep plaintext in history. This page encrypts the note with AES-256-GCM in the browser, stores ciphertext briefly, and puts the decryption key after # — that fragment is not sent with the HTTP request.

The recipient opens the reading page and decrypts without an account. The first successful read burns the ciphertext. You can also set a 1-hour, 24-hour, or 7-day expiry, and up to 10 reads. Each note is capped at 32 KB — passwords, key fragments, and short notes, not whole files. Use online file encryption for files.

  • Send the full link. Without the part after #, it cannot be decrypted
  • A lost or already-burned link cannot be recovered. Create a new one if you need to send again
  • It does not stop screenshots or forwarding. It reduces repeat opens and server-side plaintext storage

FAQ

Does the recipient of a one-time secret need an account?

No. Creating and reading both work without an account. The recipient opens the reading page. After the first successful read the note is burned; opening it again shows that it has already been destroyed.

Can the server see the plaintext I shared?

No. The text is encrypted in the browser before ciphertext is uploaded. The decryption key lives in the URL fragment after # and is not sent with the HTTP request. The algorithm is AES-256-GCM; see MDN AES-GCM.

Can I recover a lost or expired self-destructing link?

No. There is no server-side plaintext copy. Send the full link and open it before it expires. To send again, create a new link.

Does a self-destructing link stop screenshots?

No. It reduces repeat opens and long-lived server plaintext. It cannot stop copy, screenshots, or forwarding. Use it only when you trust the other person to read once and stop.