OnetimeSecret — Share Sensitive Data With a Self-Destructing One Time Secret Link
It is an open-source privacy tool that lets professionals share a sensitive one time secret through a single-view encrypted link. Each one burns after one read, leaving zero residue across email, chat, and cloud inboxes.
Try OnetimeSecret NowOnetimeSecret In Numbers
Performance Ratings
Secure One-Time Secret Sharing That Vanishes After Viewing
- Share passwords, API keys, and credentials via encrypted self-destructing links
- Recipients view your secret only once before it is permanently deleted
- End-to-end encryption ensures only the intended recipient can access data
- No account required for fast, frictionless confidential information sharing
Send your first secure one-time secret in under a minute.
OnetimeSecret vs. Traditional Methods
See how the service compares to traditional ways of sharing sensitive information.
| Feature | OnetimeSecret | Traditional Methods |
|---|---|---|
| Account Required | No | Yes |
| Data Retention | None (self-destruct) | Stored permanently |
| Encryption | Yes | Varies |
| Read Limit | One-time only | Unlimited |
| Privacy | High | Low |
| Trace Left | None | Full history |
OnetimeSecret FAQ
OnetimeSecret Pros & Cons
// ADVANTAGES
- One read and the note vanishes — no trace remains
- Optional password protection for extra security
- End-to-end encryption with client-side key handling
- Post-read, all data is wiped from infrastructure
- Zero sign-up needed — just write and share
- Simple, distraction-free interface
// LIMITATIONS
- Read receipts are not available by design
- No built-in scheduling or expiry beyond read-once
- Not intended for large files or attachments
- There is no way to re-read a note after it has been opened
- No recovery mechanism exists for unread lost links
How OnetimeSecret Works
OnetimeSecret in simple steps.
Step 1: Compose Your Secret
Visit OnetimeSecret and paste the password, credential, or confidential message into the secret composition field. Choose an optional passphrase and select an expiry timer that matches the sensitivity of the payload.
Step 2: Generate the Encrypted Link
OnetimeSecret encrypts the secret locally and produces a unique single-view URL. The plaintext is never stored alongside the link, so the recipient must open the URL to recover the original content.
Step 3: Share and Watch It Burn
Deliver the secret link to the intended recipient through any communication channel you trust. OnetimeSecret destroys the secret the instant it is viewed, leaving behind only a confirmation receipt.
OnetimeSecret is a privacy-focused service that lets people transmit sensitive information through self-destructing messages. Founded on the principle that confidential data should never linger on servers indefinitely, the secret offers a simple way to send a password, API credential, or private note that disappears after a single viewing. OnetimeSecret serves developers, IT teams, journalists, and everyday users who need a reliable channel for one-time communication.
OnetimeSecret Mission
OnetimeSecret exists to make confidential sharing frictionless and safe. The mission centers on giving every user a trustworthy mechanism to transmit a single piece of sensitive data without leaving a permanent trail. By combining ease of use with strong cryptographic guarantees, OnetimeSecret aims to set the standard for ephemeral messaging.
OnetimeSecret Security & Privacy
OnetimeSecret protects every payload with client-side encryption before it leaves the browser, meaning the server only stores ciphertext. Recipients retrieve the original content via a unique link that burns after one access. This architecture minimizes attack surface and ensures that sensitive data remains inaccessible even to platform operators.
OnetimeSecret Milestones
2012
OnetimeSecret launched as one of the earliest open-source projects offering self-destructing message functionality to the public.
2017
the secret introduced optional passphrase protection, enabling recipients to decrypt payloads only with a shared secret phrase. For independent figures, see the GitHub Repository.
2024
OnetimeSecret released a redesigned API and web interface, improving usability and expanding enterprise adoption worldwide.
Why Choose OnetimeSecret
Trusted by millions of users worldwide.
Burn-After-Reading Link Delivery
It generates a single-use link that is permanently destroyed the moment the recipient opens it. Every one is bound to one IP-context and one viewing event, so even forwarded URLs cannot reveal the data a second time.
Passphrase Lock and Custom Expiry
the secret lets the sender attach a passphrase to the one time secret link for an additional layer of authentication. Users also choose a custom expiry ranging from minutes to weeks, ensuring that stale or forgotten items cannot leak information later.
Open-Source Privacy Architecture
It publishes its source code publicly and supports self-hosted deployments for organizations with strict compliance mandates. the secret never logs sensitive contents and encrypts every payload in transit using modern cryptography standards.
What is OnetimeSecret?
OnetimeSecret is a privacy-first web application designed for transmitting sensitive information through self-destructing URLs. the secret addresses a common security gap: sending a password, API token, or recovery phrase through email or chat, where the message persists indefinitely in inboxes and backups. Each item is encrypted in the browser, wrapped in a single-use one time secret, and erased after one successful read. It supports plain text and file attachments, custom expiration windows, and optional passphrase protection. Because the secret is open source, security teams can audit the code or self-host the service behind a corporate firewall. In 2026, it remains a reference standard for ad-hoc ephemeral sharing among developers, IT administrators, and support agents who cannot rely on a full enterprise vault but still need auditable transmission.
The elegance of the system is in its constraint — one read, one chance, zero residue.
Key Features and Advantages
The core advantage is its simplicity paired with strong cryptographic guarantees. A sender pastes any sensitive item into the composition box, sets an expiry from five minutes to thirty days, optionally adds a passphrase, and receives a single-view URL. The service encrypts the payload before storage and never persists the plaintext after the recipient opens it. the secret also supports custom domains for organizations that want branded URLs, bulk generation through a REST API, and self-hosted Docker images for regulated industries. Compared with ordinary password managers or chat apps, it removes the need to share persistent credentials, dramatically shrinking the attack surface when onboarding contractors or sharing temporary access.
Security and Privacy
OnetimeSecret protects every payload with industry-standard encryption and a strict zero-retention policy. The plaintext is never written to long-term storage, and the encrypted content is bound to a single viewing context. Recipients must open it within the chosen expiry window or the data is automatically purged. Optional passphrase protection adds a second factor that only the sender and recipient know. the secret has been independently audited, the source code is publicly available on GitHub, and self-hosted deployments allow security teams to keep everything inside their own infrastructure. By combining ephemeral storage with open-source transparency, it delivers a pragmatic privacy model for short-lived data exchange.
How It Works
The service operates through a three-stage pipeline: encrypt, distribute, and burn. First, the sender composes a one time secret in the browser; the client encrypts the data with a randomly generated key before transmitting it to the server. Second, it returns a unique URL that embeds the decryption key in the URL fragment, meaning the server itself never sees the plaintext. Third, when the recipient opens the link, the server retrieves the encrypted payload, the browser decrypts it locally, and the server immediately marks it as consumed. Subsequent requests for the same URL return a polite notification that the content has already been destroyed. This end-to-end design ensures that even operators cannot read what was shared.
Use Cases and Benefits
OnetimeSecret fits dozens of real-world workflows where permanent credential storage is undesirable. Developers share API keys with contractors during onboarding and revoke access the moment the link is opened. Support agents transmit temporary login credentials to customers without leaving passwords in ticket histories. Journalists exchange confidential tips through encrypted messages that vanish after a single read. Security teams provision recovery codes for executives during incident response, generating a unique URL for each one. The benefits are consistent across every scenario: the data lives only as long as it must, the recipient never needs an account, and the sender gains verifiable confirmation that the payload was retrieved. For organizations already using tools such as PrivNote, Yopass, or PrivateBin, it offers a mature, actively maintained alternative with enterprise-grade reliability and a thriving open-source community.
Final Verdict on OnetimeSecret
It delivers exactly what its name promises: a frictionless way to share secret data through a self-destructing link. The combination of single-view encryption, optional passphrase protection, and open-source transparency makes it a trustworthy choice for developers, IT teams, and privacy-conscious professionals. Compared with PrivNote and Yopass, OnetimeSecret offers richer customization, stronger community governance, and a self-host path for regulated organizations. If your workflow involves sending a password, token, or sensitive note that should not survive in inboxes, it is one of the most dependable tools available in 2026.