Send an API key that self-destructs after one view
An API key emailed to a colleague or pasted into a ticket stays readable forever — in the mailbox, the ticket history, and every backup of both. That is a standing secret waiting to leak.
Secret Link turns it into a one-time, browser-encrypted URL. The key is sealed on your device, the decryption key never reaches our servers, and the ciphertext is deleted the moment the link is opened.
A ticket is forever; this is not
A key pasted into an issue tracker outlives the task, the project and often the employee. A one-time link is read and deleted, so the secret’s lifetime is the handover rather than the retention policy of every system it passed through.
Opaque bytes, never logged
Paste a token, a .env snippet or a connection string. It is encrypted on your device before anything is sent, treated as opaque bytes on our side, and never written to a log.
Expiry for the link nobody opens
If the recipient never gets to it, the ciphertext expires on its own — up to 7 days anonymously, up to 30 days signed in — and is purged. An unread secret does not sit there indefinitely waiting to be found.
This is not key rotation
A one-time link limits exposure to a single read; it does not make a long-lived key safe. For high-value credentials, keep rotating on a schedule and treat any shared secret as due for rotation sooner.
Share a secret in seconds
Paste it, send the link, and it self-destructs after one view — no account required.
Create a secret linkQuestions
- Is the key ever stored in plaintext?
- No. It is encrypted in your browser before anything is sent, and only ciphertext reaches ShieldFive.
- What if the recipient never opens the link?
- It expires after the time you set — up to 7 days for anonymous links, up to 30 days when signed in — and the ciphertext is deleted.
- Should I still rotate the key afterwards?
- For high-value keys, treat any shared secret as needing rotation on a schedule. Secret Link limits exposure to a single read; it does not replace key rotation.