Share a password, API key or sensitive note with a link that works exactly once. Everything is encrypted right here in your browser before it leaves your machine—our server only ever stores scrambled bytes, and the decryption key never touches it at all.
No account, no email address, nothing to sign up for. Write your note, get a link, send it however you like. The moment someone opens it, it's gone for good—and there's no way for us to recover it, because we never had it to begin with.
This browser doesn't support the Web Crypto API, which this tool relies on to encrypt and decrypt notes on your device. Please try a current version of Chrome, Firefox, Edge or Safari.
The tool itself is still being built—check back soon. Everything below is exactly how it'll work once it's live, including the same API other tools will be able to call directly.
This link works once. Copy it now and send it however you'd like—if you navigate away without copying it, there's no way to get it back and you'll need to create a new note.
Decrypting…
This note has now been permanently deleted from our server—reloading this page won't bring it back, so copy it somewhere safe before you leave.
#, in the URL fragment, which browsers never send to any server. It only ever exists on devices that have the link.crypto.subtle, using AES-256-GCM. Plaintext never reaches our server in either direction.See our Privacy Policy for how the site more generally handles data.
The same service behind this page is reachable directly, for scripting a note into a deploy pipeline, a CLI tool, or anywhere else. Encrypt and decrypt client-side exactly as this page does—the API only ever stores and returns opaque encrypted bytes.
POST /api/notes—create a note. Body: { "ciphertext": "<base64url>", "ttl_seconds": 3600 }. Returns { "id": "<note id>" }.GET /api/notes/{id}—fetch and permanently delete a note in one step. Returns { "ciphertext": "<base64url>" }, or a 404 if it's already been read, expired, or never existed.GET /api/notes/{id}/exists—check whether a note is still unread, without consuming it. Returns { "exists": true } or { "exists": false }.