Send a password, API key, or file through a one-time link. It's encrypted in your browser, opened once by your recipient, and then permanently deleted. We never see what's inside.
Your one-time link
https://viewoncesecret.vercel.app/secret/SXDM1KiA2DNmtZH3#itODFee6xQZleJw8vynXDnM2wt77joUFo13VcngId/g=Paste your text or drop a file. We'll give you a link that works once, then deletes itself.
No accounts, no apps, no learning curve. The whole tool fits in a sentence and runs in your browser.
Type or paste your password, API key, or note. Or upload a file up to 15 MB. Your browser encrypts it instantly.
You get a unique link. Share it via Slack, WhatsApp, email — anywhere. The link itself contains the decryption key.
The first person to open it sees your secret. After that, the link is permanently deleted. No one — including us — can read it again.
Every secret is protected by four independent layers. None of them require you to trust us.
Your data is encrypted with AES-256 inside your browser before anything is sent.
We never see your data. The decryption key stays in the link, not on our servers.
After one view, the secret is permanently destroyed. There's nothing left to leak.
Our cryptography is auditable. You can verify exactly what runs on your device.
Anywhere you'd normally paste a password into a chat, send a ViewOnceSecret link instead.
Skip the awkward whiteboard. Send a one-time link they open on their phone and the password's gone forever after.
No more passwords pasted in Slack DMs sitting in search history. Read once and gone.
PDFs, contracts, screenshots, NDAs — anything up to 15 MB. Same one-time link rules apply.
Everything you might want to know before trusting us with a real password.
Yes — completely free, with no account or credit card required. We don't sell your data because we literally can't see it. The service is funded by our parent product, Gradiolex.
It expires automatically based on the time limit you set (1 hour, 1 day, 3 days, or 7 days). Once the timer ends, the link is permanently deleted whether anyone opened it or not.
No, and that's intentional. Once a link is viewed or expires, the encrypted data is irreversibly destroyed. Even with a court order, we'd have nothing to hand over.
We don't see the content of any link — it's encrypted with a key that stays in your browser. We keep minimal server logs for abuse prevention (IP, timestamp) and delete them within 30 days.
Yes. Many teams use it for sharing credentials, API keys, and internal documents. For organizations needing audit logs or SSO, our team plan is in development — email us to join the waitlist.
Email keeps a permanent copy in both inboxes and on multiple servers. ViewOnceSecret leaves no copy anywhere after one read. Plus, your message is encrypted; email usually isn't.
Free forever, no signup, no card. Open the page, paste your secret, send the link. We'll handle the rest.