A OneTimeSecret alternative, encrypted in your browser

OneTimeSecret popularised the one-time secret link: paste a password, get a URL that works exactly once. ShieldFive’s Secret Link does the same job — with the encryption moved into your browser.

The secret is sealed on your device before it is sent, the key travels in the link fragment, and the server only ever holds ciphertext that is deleted the moment it is read.

Encrypted before it is sent, not on arrival

The secret is sealed on your device with a fresh random key under XChaCha20-Poly1305, and that key lives only after the “#” in the link — a part of the URL browsers never transmit. What reaches the server is ciphertext with no key attached to it.

Read once, then gone

The first time the link is opened, the ciphertext is returned and immediately deleted. A second visit finds nothing — not an error page explaining the secret was there, just nothing to serve.

Hosted, but still checkable

OneTimeSecret’s answer to “why trust you” is that you can self-host it. This is a hosted service, so the answer here is the open-source @shieldfive/crypto core: you can read the exact code that seals the secret even though you don’t run the server.

EU-hosted, untracked

Ciphertext is stored in the EU, and there are no trackers on the create or view pages. Nothing readable is written to our servers at any stage, and there is no analytics record of who opened what.

Share a secret in seconds

Paste it, send the link, and it self-destructs after one view — no account required.

Create a secret link

Questions

Is ShieldFive self-hostable like OneTimeSecret?
OneTimeSecret is open source and can be self-hosted. ShieldFive Secret Link is a hosted service, but the cryptographic core it uses — @shieldfive/crypto — is open source and independently reviewable, so you can verify how the encryption works even though you don’t run the server.
Can you read the secret on the server?
No. The secret is encrypted in your browser and the key is in the part of the link after the “#”, which is never sent to us. We receive and store only ciphertext.
What happens after it is viewed?
The first time the link is opened, the ciphertext is returned and immediately deleted. A second visit finds nothing.