Share credentials across your team without leaving them in chat

Passwords pasted into Slack, email or a ticket linger in logs, search indexes and backups long after they’re needed. Rotating them is the only real fix — and rotation is exactly what a leaked credential forces.

Secret Link gives your team a one-time, browser-encrypted link for a password, connection string or recovery code. It is read once and gone, and it never sat in plaintext on a server in between.

Nothing left in the channel

A credential pasted into chat is copied into search indexes, exports and backups you do not control. A burn-after-reading link removes the artefact: once the recipient opens it, there is nothing left in the thread for an audit or an attacker to find.

Encrypted before it leaves the laptop

The secret is sealed on your device with a random key under XChaCha20-Poly1305 from the open-source @shieldfive/crypto core, and the key rides in the link fragment browsers never send. Our server stores ciphertext it cannot open.

A bearer link — treat it that way

Whoever opens the link first reads the secret and burns it. Send it over a channel the intended recipient controls, and if it is opened before they get to it, treat the credential as exposed and rotate. That is the correct operational posture, not a caveat.

Free for the whole team

Anyone can create a link with no account. A shared team account is optional and adds link history plus higher caps — up to 5 views and 30 days instead of one view and 7.

Share a secret in seconds

Paste it, send the link, and it self-destructs after one view — no account required.

Create a secret link

Questions

Can the whole team use it without accounts?
Yes. Anyone can create a link for free. A shared team account (with history and higher limits) is optional.
Is it safe to send a link over Slack or email?
The link is a bearer capability — whoever opens it first reads the secret and burns it. Send it over a channel the intended recipient controls, and if it is opened unexpectedly, treat the secret as exposed and rotate it.
Can we require a password on top of the link?
An optional password on the link is on the near-term roadmap; today the link fragment is the single decryption factor.