once

private by design

Share something once.

Password-protected secrets that disappear after they’re revealed.

sealed in your browser64 KB max
Self-destructs after

or press ⌘ ↵

  1. 01Your browser encrypts the secret — plaintext never leaves this tab.
  2. 02The server receives only ciphertext it cannot read.
  3. 03Opening requires both the private link and the password.
  4. 04A successful reveal atomically deletes the stored copy.
  5. 05No accounts, no analytics, no secret history.

Honest footnote: no tool can erase what recipient devices, screenshots, or clipboard managers do afterward. What we control — our server — never sees plaintext, and forgets the ciphertext the moment it is read.

one-time secret sharing

Private sharing, without a permanent copy.

once is a free, browser-encrypted way to send passwords, API keys, recovery codes, access instructions, and private notes. No account, inbox, or searchable history.

the complete trip

How once works

  1. 01

    Seal in your browser

    Argon2id derives strong keys from your password, then AES-256-GCM encrypts your text locally. Plaintext never leaves this tab.

  2. 02

    Share two pieces

    Send the private link and password separately when you can. Opening the secret requires both.

  3. 03

    Reveal and destroy

    The first valid reveal atomically removes the encrypted copy from the server before your browser decrypts it.

privacy boundary

What the server sees

Ciphertext, KDF parameters, an expiry time, and an HMAC-protected proof. It never receives your plaintext, password, or the link secret stored after the # in the URL.

Good for

Passwords, API keys, recovery codes, credentials, access details, and private text.

Not a vault

Text only, up to 64 KB, with a fixed expiry. Keep anything permanent somewhere built for storage.

The honest limit: no website can erase screenshots, clipboard history, copied text, or records a recipient keeps after opening it.

the fine print

Questions, answered.

Is once free and accountless?
Yes. There is no account, sign-in, payment, analytics profile, or secret history. Create a link and share it.
Does the server ever receive plaintext?
No. Encryption and decryption happen in the browser. The server receives ciphertext, expiry data, KDF parameters, and an HMAC-protected unlock proof.
What happens after a wrong password?
The encrypted secret survives. Repeated failed attempts trigger a temporary cooldown, but a wrong password never consumes the note.
Can a revealed or expired secret be recovered?
No. A successful reveal permanently deletes the stored encrypted copy, and expired copies are purged. There is no recovery path or archive.