Understand what protects your secret.

A clear security boundary matters more than a sweeping promise. Here is what OneTimeRead does, and what you still need to protect.

Encryption happens in the browser

OneTimeRead uses the browser’s Web Crypto API with AES-GCM, a fresh 256-bit key, a random 12-byte IV and a 128-bit authentication tag for each secret. The server receives ciphertext, the IV, a format version and an allowed expiration. It never needs your plaintext or decryption key.

The key lives in the fragment

The complete link contains the key after #. Browsers exclude this fragment from the HTTP request. Keep the full link private: the identifier and key together grant access to anyone who has them.

Private pages have no third-party resources

Creation, reveal and secret API routes are separated from the public site. They use first-party resources only, a restrictive Content Security Policy, no-referrer and no-store headers. Analytics, advertising and session recordings are restricted to public information pages.

A claim is atomic

Reading requires a deliberate POST request. The server uses a database transaction and a row lock so that two competing claims cannot both receive the message. The record is deleted before the successful response is completed. Page loads, previews and ordinary crawlers do not consume it.

What this does not protect against

Use HTTPS and a trusted device. Do not treat one-time sharing as a substitute for rotating credentials, limiting access or revoking an exposed key.

Anonymous does not mean no request metadata

Network connections reveal an IP address to infrastructure. A short-lived keyed identifier derived from the connection’s origin supports creation rate limits; it is kept separate from the secret record. See our privacy notice for the handling of public pages and abuse controls.

Report a problem

Contact hi@valle.dev with the affected route and a safe reproduction. Do not include a live secret, full secret link or private credential.

A little less left behind.

Share the sensitive part once. Keep it out of the conversation history.

Create a One-Time Secret