Open source · Zero knowledge · No accounts

Send a secret.
It opens once.

A password, an API key, or a whole file becomes one encrypted link. The first open reveals it and destroys it, and the key never touches the server. Nobody can read it in between. Not even us.

New secret

encrypts locally
0 bytes
or drop a file · up to 8 MB, encrypted before upload
What it does

Three ways to move a secret

Send one, ask for one, or ship a whole file. Same crypto underneath, same burn at the end.

Send a text secret

Paste a password or key, get a one time link. The first open burns it, and everyone can see that it burned.

Send one →

Drop a file

Up to 8 MB, split into chunks and sealed in your browser, with the chunk order cryptographically pinned. The link behaves exactly like a text secret.

Send a file →

Ask for a secret

Flip the direction. Your browser makes a keypair, and whoever opens your ask answers into a mailbox only this browser can unlock.

Create an ask →

Every mode shares the dials: a passphrase second lock, expiry from one hour to seven days, and one to five views before the burn.

How it works

The key never touches the server

Everything is sealed in your browser before upload. The rest is not a policy you have to trust; it is how URLs work.

Nobody has opened this one yet. It is holding exactly one view.

PlaintextAKIA4T7QZ2X9V0RB1MPD

Decrypted in this tab, with the key after the #. The server handed over ciphertext and forgot it in the same step.

404. Same link, second visitor. There is nothing left on the server to hand over, and no copy of the key anywhere to ask for.

Public id The only thing the server ever sees.
Decryption key Never sent to any server, by how browsers work.

Our end to end tests fail the build if the fragment ever appears in a request.

The key rides the fragment

Everything after # in a URL stays inside the browser. The key lives there, so it reaches your recipient without ever crossing the server.

Burns exactly once

Read and delete are one atomic step. If fifty people click at the same moment, exactly one sees the secret.

Expires on its own

Unopened secrets wipe themselves after one hour, one day, or seven days. Nothing waits around.

Optional passphrase

A second lock, checked on the recipient's device. A typo burns nothing, and there is nothing for attackers to guess against.

No accounts, no tracking

No signup, no cookies, no analytics, no third party scripts. The page cannot talk to anyone but this server.

Open source

A small Go codebase with zero dependencies, MIT licensed. Audit it in an afternoon, host it anywhere.

Command line

The same tool lives in your terminal

One static binary is the server, the site, and the client. A link made in the terminal opens in the browser, and the other way round.

Reads stdin, writes stdout, fits into pipes
Encrypts locally, before anything touches the network
Self hosts with a single command
$ go install github.com/realanshuman/sendkey/cmd/sendkey@latest
~/ sendkey
$ sendkey send "AKIA-EXAMPLE-SECRET-KEY"
one-time link (burns after 1 view, expires in 24h):
https://sendkey.xyz/s/H6847TzgXETB#HLsZDskZ-NQFE5xolu…

$ sendkey send -file backup.tar.gz
encrypting and uploading: 16/16 chunks
https://sendkey.xyz/s/Qm93kd0Xw1Tz#R6cdQpWvZ2xNb4Ml…

$ sendkey get 'https://sendkey.xyz/s/H6847…#HLsZ…'
AKIA-EXAMPLE-SECRET-KEY

$ sendkey get 'https://sendkey.xyz/s/H6847…#HLsZ…'
sendkey: server: this secret has expired or
already been viewed
FAQ

Straight answers

Can you read my secret?
No. The secret is encrypted in your browser before it is uploaded, and the key never reaches us. It lives after the # in the link, which is the one part of a URL browsers never send to any server. What we store is scrambled data we cannot open.
Can I see when my secret was opened?
Yes. After you create a link, the page below it shows Waiting to be opened and switches to the exact time the moment someone reads it, with no reload. Keep the tab open to watch it. The record that carries the timestamp holds no ciphertext at all: opening a secret still destroys it, the receipt is only the fact that it happened.
Can I send files?
Yes, up to 8 MB. Drop a file on the composer and it is split into chunks, each encrypted in your browser under a fresh file key, with the chunk order cryptographically bound so the server cannot reorder or swap pieces. The link looks and burns exactly like a text secret. The CLI speaks the same format: sendkey send -file report.pdf.
Can someone send a secret to me instead?
Yes. An ask link flips the direction. Your browser generates a keypair; the link you share carries the public half, and whoever opens it answers into an encrypted mailbox that only your browser can unlock. One answer per ask, burned on first read, and both sides see the same pixel fingerprint so you can compare keys out of band. Create one at sendkey.xyz/ask.
What if someone else opens the link first?
Then they see the secret, and your recipient sees a dead link. That sounds scary, but it means you always find out. Send the link over a channel you trust, keep the expiry short, and add a passphrase for anything serious.
What does SendKey not protect against?
Whoever holds the link before it is opened can read the secret, so treat the link with the same care as the secret itself. And like every tool that encrypts in the browser, it relies on the page being delivered honestly. If that matters for you, use the CLI or host it yourself.
Can I host it myself?
Yes, and for anything serious you should. It is one Go binary with no dependencies: run sendkey serve and you are live. Secrets stay in memory, or in Redis when you point it at one. It also deploys to Vercel unchanged.

Stop pasting secrets into chat

Chat history is saved, synced, and backed up forever. A SendKey link opens once and dies.