This browser does not support the encryption this form needs. Try a more recent browser.
Share a secret, once
Paste a password, token or note. You get a link that works exactly once and then destroys itself.
- Stored encrypted
- Destroys itself
- No account needed
- Hosted in the EU, GDPR-ready
Without an account these limits apply
- The secret can be viewed once.
- It expires after 24 hours at most, even if nobody looks.
- 8 KB of text at most, no attachments.
- You get no notification when it is opened.
- The secret appears in no list at all: the link is the only copy. Lost is lost.
How it works
-
1
Paste
Your secret travels to the server encrypted. The key stays in the link.
-
2
Share
Send the link by chat or email. The password itself is never in it.
-
3
Gone
After one view or after the expiry time the content is irrecoverably destroyed.
An account can do more
Several views per secret, a lifetime of up to 30 days, 64 KB of content, a notification the moment someone looks, an overview of your secrets and the button to destroy one yourself.
Log inFrequently asked questions
What you probably want to know before pasting a password into a website you found five seconds ago.
How does sharing a password once actually work?
You paste the secret into the form and get a link back. The first time somebody opens that link and clicks to reveal, the content is shown and destroyed immediately afterwards. A second visitor gets the same message as somebody guessing at random: this secret does not exist.
Is SecretsMonkey end-to-end encrypted?
Yes. Your browser encrypts with WebCrypto (AES-256-GCM), nothing to install. The key never reaches the server: it lives only after the # in the link, and browsers never send that part anywhere. For a secret request (Pro and Business), the responder encrypts straight to your public key instead, since you are not there live when the answer arrives. We never see more than encrypted data.
What could someone do with a copy of the database?
Nothing. It only holds encrypted content and a hash of the lookup id — no key to open anything with, because the server never had one. Without the full link, # and all, the stored text is worthless. Whoever holds the link holds the secret, so treat it like the password itself.
Will a link preview in chat or email destroy my secret?
No. A GET on a share link never decrypts: it only renders a confirmation page. The secret is shown and consumed only when the button is genuinely clicked. Chat clients and mail scanners that fetch links ahead of time cannot eat a secret in transit.
Do I need an account?
No. Without one you can share a secret of up to 8 KB, viewable once, with a lifetime of up to 24 hours. With an account a secret can be viewed up to ten times, live for up to thirty days, hold 64 KB, notify you the moment somebody looks, and appear in an overview where you can destroy it yourself.
How long does a secret last?
Until it has been viewed or until its expiry time passes, whichever comes first. You pick the expiry: 15 minutes, 1 hour, 4 hours or 24 hours without an account, up to thirty days with one. After that the content is irrecoverably gone, even if nobody ever looked.
Can I ask somebody to send a secret to me?
Yes, this is a Pro and Business plan feature. You create a request link and send it to whoever holds something for you. They fill in the secret without an account and without learning anything about you beyond the description you wrote yourself. Nobody has to email a password again just because it needed to travel in that direction.
Where is the data held, and who runs it?
In the European Union, under the GDPR, operated by MonkeySoft in the Netherlands. There is no tracking, no advertising network and no third-party analytics in the page. Secret content never reaches a log file, an error report or a repopulated form.