Gate
An address you choose
Limit access to a specific email address when the handoff is meant for one person. Possession of the URL alone does not satisfy the gate.
Verified recipients
Restrict a secret to an email address or a domain. Add a verification step before the recipient can claim the encrypted payload.
Recipient access
Illustrative handoff
Shared link
secretpaste.com/s/a3bCz1Key stays in the fragment
#29K4azt81Ygo1BtI…Verified recipients
The link carries the decryption key. A recipient gate adds a separate requirement: prove access to an allowed email address before the service will release the encrypted content.
Gate
Limit access to a specific email address when the handoff is meant for one person. Possession of the URL alone does not satisfy the gate.
Order
Use a domain restriction for a group with a shared email domain. Anyone who meets that rule still needs the complete secret link.
Key
Failed verification does not consume a view. Successful verification permits a claim; it does not give SecretPaste access to the decryption key.
A straightforward handoff
Use the recipient controls available in your plan to specify an email address or domain.
Share it directly with the intended recipient. Keep the private fragment attached to the link.
The recipient proves email access before requesting the encrypted payload and decrypting it in their browser.
“The recipient gets the secret. Our servers never get the plaintext or the decryption key.”
— The SecretPaste browser encryption boundary
Before you share
It proves access to the permitted mailbox during the verification flow. It is not a check of someone’s legal identity and does not prevent copying after a reveal.
No. Access checks must pass before a view is consumed. A failed or incomplete gate does not release the ciphertext.
Yes, a link can be forwarded. The next person must still satisfy the email or domain rule, and the secret must have an available view and remain unexpired.
Encrypted in your browser, gone after one view. Send a password, a token, or an environment file without leaving its contents in a message thread.
Explore featureStreamed to storage, never through our API. Share a file or a folder with browser encryption and a lifetime you control.
Explore featureOne atomic claim per view, then the ciphertext is gone. Give sensitive text or a file a clear end to its availability.
Explore featureCompare plans with recipient controls, then add an email or domain rule to your next private handoff.
See recipient controls