A secret shared in three steps.

OneTimeRead separates a sensitive message from your everyday conversation. The link is the handoff.

1. Create it in your browser

Open the private creation page, enter up to 10 KiB of text, and choose 1 hour, 24 hours or 7 days. Your browser generates a new encryption key and encrypts the message before sending anything to the server.

2. Send the complete link

The server stores only the encrypted message and returns a random identifier. Your browser adds the decryption key after the # in the link. That fragment is not part of an HTTP request to our server.

Share the whole link through a trusted channel. Removing the fragment makes the message impossible to decrypt. Anyone who receives the complete link can use it; there is no account or separate recipient verification.

3. Reveal once, deliberately

Opening the link shows a confirmation page. It does not request or consume the message. Clicking Reveal secret requests the ciphertext once, removes its stored copy, and decrypts the message in the recipient’s browser.

If the link is never opened

The secret becomes unavailable at its expiration time. Expired records are removed by scheduled cleanup. The default expiration is 24 hours, and no link can last longer than 7 days.

Save what you need before leaving

A successful reveal cannot be undone. A lost connection during reveal can also make the secret unavailable, so create a new one if delivery is uncertain.

Create a One-Time Secret

A little less left behind.

Share the sensitive part once. Keep it out of the conversation history.

Create a One-Time Secret