An API key belongs outside the chat history.

Hand over a token without making the credential itself a permanent part of the conversation.

Start with the right credential

Create a key with the minimum permissions needed. Where the provider supports it, choose a short lifetime or a key dedicated to the recipient. Sharing a broad production credential is risky even through an encrypted link.

Share the key as encrypted text

Paste it on the private creation page and choose an expiration. Your browser encrypts the text locally; the server stores ciphertext and returns a random identifier. Send the complete link to your intended recipient through a trusted channel.

Separate context from access

You can describe the integration, environment and permissions in your regular conversation. Keep the actual key in the one-time secret. Ask the recipient to store it in a secret manager rather than source code or a shared document.

One-time delivery is not revocation

After reveal, the stored message is gone, but the API key can still work at its provider. Rotate it if the complete link goes to the wrong person or you suspect exposure. OneTimeRead has no access to revoke third-party credentials.

Create a One-Time Secret

A little less left behind.

Share the sensitive part once. Keep it out of the conversation history.

Create a One-Time Secret