Share credentials across your team without leaving them in chat
Passwords pasted into Slack, email or a ticket linger in logs, search indexes and backups long after they’re needed. Rotating them is the only real fix — and rotation is exactly what a leaked credential forces.
Secret Link gives your team a one-time, browser-encrypted link for a password, connection string or recovery code. It is read once and gone, and it never sat in plaintext on a server in between.
Nothing left in the channel
A credential pasted into chat is copied into search indexes, exports and backups you do not control. A burn-after-reading link removes the artefact: once the recipient opens it, there is nothing left in the thread for an audit or an attacker to find.
Encrypted before it leaves the laptop
The secret is sealed on your device with a random key under XChaCha20-Poly1305 from the open-source @shieldfive/crypto core, and the key rides in the link fragment browsers never send. Our server stores ciphertext it cannot open.
A bearer link — treat it that way
Whoever opens the link first reads the secret and burns it. Send it over a channel the intended recipient controls, and if it is opened before they get to it, treat the credential as exposed and rotate. That is the correct operational posture, not a caveat.
Free for the whole team
Anyone can create a link with no account. A shared team account is optional and adds link history plus higher caps — up to 5 views and 30 days instead of one view and 7.
Share a secret in seconds
Paste it, send the link, and it self-destructs after one view — no account required.
Create a secret linkQuestions
- Can the whole team use it without accounts?
- Yes. Anyone can create a link for free. A shared team account (with history and higher limits) is optional.
- Is it safe to send a link over Slack or email?
- The link is a bearer capability — whoever opens it first reads the secret and burns it. Send it over a channel the intended recipient controls, and if it is opened unexpectedly, treat the secret as exposed and rotate it.
- Can we require a password on top of the link?
- An optional password on the link is on the near-term roadmap; today the link fragment is the single decryption factor.