Encryption
Encrypted before it leaves
Your browser encrypts the text with AES-256-GCM. SecretPaste stores ciphertext and delivery metadata; we never receive the plaintext or the decryption key.
Text secrets
Encrypted in your browser, gone after one view. Send a password, a token, or an environment file without leaving its contents in a message thread.
Project access
Illustrative handoff
Shared link
secretpaste.com/s/a3bCz1Key stays in the fragment
#29K4azt81Ygo1BtI…Text secrets
Some things need to be shared, but do not need to become a permanent part of a conversation. Paste the text, choose its lifetime, and send a private link through the channel you already use.
Encryption
Your browser encrypts the text with AES-256-GCM. SecretPaste stores ciphertext and delivery metadata; we never receive the plaintext or the decryption key.
Recipient
The recipient chooses when to open the secret. Visiting the page or generating a link preview does not use up a view.
After delivery
Set an expiry and a view allowance. When the link reaches either limit, the service stops delivering the secret. A recipient can still keep a copy after opening.
A straightforward handoff
Open the homepage and paste the password, token, recovery code, or other text you need to share.
Choose your options and select Create link. Encryption happens in your browser before upload.
Send the complete link to your recipient. They choose Reveal to decrypt it in their own browser.
“The recipient gets the secret. Our servers never get the plaintext or the decryption key.”
— The SecretPaste browser encryption boundary
Before you share
No. In browser mode, encryption happens before upload and the decryption key stays in the URL fragment. The service receives neither the key nor the plaintext.
No account is needed to open a standard link. If you enable recipient verification, they must prove access to the permitted email address.
Yes. A recipient can copy or capture the text after revealing it. Burning a link prevents another delivery through SecretPaste; it cannot erase a recipient’s copy.
Streamed to storage, never through our API. Share a file or a folder with browser encryption and a lifetime you control.
Explore featureOne atomic claim per view, then the ciphertext is gone. Give sensitive text or a file a clear end to its availability.
Explore featureKnow when, where and on what device it was opened. See delivery events and the coarse context available for a reveal, without keeping the secret itself.
Explore featureShare text or a file with a link that has an ending. Start with the browser composer.
Share text