Access within a team
Pass server passwords, API keys or database credentials to colleagues without them living in a chat forever.
Browsers do not let websites add bookmarks, for good reason – otherwise every site would do it uninvited. This shortcut takes a second:
D
Tap your browser’s share icon and choose “Add to Home Screen” or “Add bookmark”.
Encrypted in your browser. Deleted automatically once it has been opened.
This page needs your browser’s Web Crypto interface. It is only available over a secure HTTPS connection and in current browsers. We deliberately disable the form rather than transmit your message unprotected.
Open the page over https:// and use a current version of Firefox, Chrome, Edge or Safari.
Credentials have to be handed over constantly – to colleagues, to contractors, to a neighbour for the wifi. Almost always through channels that were never built for it.
An email sits in several mailboxes, in backups and in the archive. A chat history sits on every device and in the cloud backup. Still there in five years.
Forwarded, quoted, pasted into a group. Before long nobody knows how many people have seen that one password.
An old mailbox is taken over, a laptop is sold, an account is breached. Those old credentials often still work.
The only thing that really helps: the secret must never be left lying anywhere in the first place.
Your message is encrypted in your browser – before anything reaches us.
We only hold encrypted text. The key sits behind the # sign in the link – browsers never send that part to a server.
Opening it removes it from the database at once. A second attempt finds nothing – for us either.
Not because we promise not to, but because we simply do not have the key. Encryption uses AES-256-GCM; add a password and a second key is derived from it with 600,000 PBKDF2 rounds. Both happen in your browser.
Pass server passwords, API keys or database credentials to colleagues without them living in a chat forever.
The new freelancer needs access once. Afterwards it should not still be sitting in their inbox.
The wifi password for guests, credentials for the family, a number nobody else should read.
So you know what you are relying on – and what you are not:
Whoever opens the message can photograph it or write it down. No encryption in the world prevents that.
Whoever opens the complete link before the recipient reads the message. That is what the password option is for – and why link and password should travel separately.
We protect the path in between. A compromised computer or a malicious browser extension is outside what we can secure.
Paste the password above and create a link. The content is encrypted in your browser, and the resulting link can be opened exactly once – after that the message is gone. Send the link through a channel only the recipient reads, and add a password for particularly sensitive credentials.
Because they stay there. An email ends up in several mailboxes, in backups and often in archives; a chat history stays on every device and in the cloud backup. Anyone who gains access to one of those accounts months later still finds the password. A one-time link only exists until it is first opened.
Encryption happens in your browser before the data reaches our server. The key sits behind the # sign in the link, and browsers never transmit that part of an address to a server. What we hold is therefore unreadable ciphertext.
No – not because we promise not to, but because we do not have the key. Even if somebody copied our entire database, all they would hold is encrypted data. We could not hand over content on an official request either.
The message is lost. The key exists only in that link, we never stored it and cannot recover it. Always copy the link in full, including the part behind the # sign.
Every message is deleted automatically after 7 days at the latest – even if it was never opened. With self-destruct enabled it disappears the moment it is first retrieved.
Whoever opens the complete link before the recipient can read the message – no encryption prevents that. That is what the password option is for: an attacker then needs the link AND the password. Send the two through different channels, for example the link by chat and the password by phone.