Skip to main content

One Time Link

Server-processed

Share a secret note through a link that self-destructs after one view. End-to-end encrypted in your browser — the server only ever stores ciphertext.

One Time Link

Was this helpful?

Guides

Share a password, API key, private message or any other secret through a link that works once and then destroys itself. Type your secret, get a link, send it to the recipient — the moment they open it, the note is shown and permanently deleted. It's end-to-end encrypted: the secret is scrambled in your browser before it ever leaves your device.

How does it work?

  1. You type a secret and click Create. Your browser encrypts it and generates a random key.
  2. The encrypted blob (and nothing else) is stored on our server for a limited time; the key is placed in the fragment of the link — the part after the #, which browsers never send to any server.
  3. You share the link. When the recipient opens it, their browser fetches the encrypted blob, decrypts it locally with the key from the link, and — for a one-time link — the server deletes it so it can never be opened again.

What does "end-to-end encrypted" mean here?

The encryption and decryption happen entirely in the two browsers. Our server only ever holds an opaque encrypted blob: it cannot read your secret, and neither can anyone who compromises the server or intercepts the stored data. The decryption key lives only in the link's #fragment, which is never transmitted to us. In short, we couldn't read your secret even if we wanted to.

Should I use the passphrase?

Add a passphrase when the link might be seen by someone it's not meant for — because the key is in the link, anyone who gets the link can open it. A passphrase is mixed into the encryption so the note cannot be decrypted with the link alone — the recipient needs both the link and the passphrase. Send the passphrase through a different channel than the link (e.g. link by email, passphrase by text).

What are the expiry options?

You choose how long the link stays valid — from 15 minutes up to 7 days. When the time runs out, the encrypted blob is automatically deleted whether or not it was ever opened. With destroy after first view on (the default), it's also deleted the instant it's opened, whichever comes first.

What happens if the passphrase is typed wrong?

The recipient can try again — the encrypted note is held in their browser's memory during the attempt, so a typo isn't fatal. Only reloading the page loses it (for a one-time link, the server copy is already gone by then).

Is it truly private?

Yes. Your secret is encrypted before it leaves your browser, the key never reaches our server, and one-time links are deleted on first read. The main thing to protect is the link itself — treat it like the secret it carries, and prefer a passphrase for anything sensitive.

one time linksecretshareself-destructencryptedburn after reading

Love the tools? Lose the ads.

One payment clears every ad from your account, for good. No subscription, no tracking.