All projects
Product DevelopmentWeb ApplicationNext.jsReactSecurity

One-Time Secret – Share Passwords and Files as a Link That Works Once

Passwords sent by email or chat stay there forever. One-Time Secret sends them as a link that works once: encrypted with a key that exists only in the link, destroyed when it's read, with a receipt when it's opened. Text or files, free to use, designed, built and run by me.

Jump to a section
One-Time Secret – Share Passwords and Files as a Link That Works Once

Built with

  • Next.js
  • React
  • TypeScript
  • Node.js
  • MongoDB
  • Mongoose
  • Nodemailer
  • Zod
  • reCAPTCHA
  • Nginx

At a glance

What it is

share a password, key or file as a link that works once

Who it's for

anyone who needs to send credentials or a confidential file, especially to clients

Status

live, free to use; sending needs a free account with a confirmed email, and recipients need nothing


The problem

Passwords sent by email or chat stay there forever.

A password sent over email sits in two inboxes, and in every backup, until someone deletes it, which usually means never.


The idea

Send the secret as a link instead. The link works once: the secret is encrypted, destroyed the moment it's read, and never sits in an inbox. The sender gets a receipt when it's opened.

Write the secretGet a one-time linkRecipient opens itSecret destroyedSender notified

What I built

Secrets and files

Senders can share up to 50 KB of text, or a single file up to 25 MB (PDF, Office documents, images, text, key or certificate files), and choose how long the link lasts: an hour, a day, three days, a week or 30 days.

Delivery and receipts

The app can email the link for you when you create it. A dashboard shows each secret's status, emails you when it has been opened, and lets you revoke it until then.

Nothing for the recipient to sign up to

Recipients just open the link. Senders need an account with a confirmed email address.


Under the hood

The design starts from one assumption: if the database were ever stolen, the secrets inside it should still be unreadable.

  • The key lives only in the link. Each link carries a random token. The encryption key is derived from that token and is never stored, so the database holds only ciphertext and a keyed hash for lookup. Secrets are encrypted with AES-256-GCM, tied to their own record so they can't be swapped between rows.

  • Truly single-use. Reading a secret and deleting it happen in one atomic step. A test fires 20 simultaneous attempts and requires exactly one to succeed.

  • Safe from link scanners. Email security tools often "click" links automatically. Simply loading the link doesn't destroy the secret; only a deliberate reveal does.

  • Expiry built in. Unopened secrets are removed automatically when their time is up.

  • Files handled carefully. Files are encrypted in chunks, each checked before anything reaches the recipient, and uploads containing active content such as macros or PDF scripts are refused.

  • It won't run insecurely. In production the app refuses to start without strong separate secrets, HTTPS, a real email service and spam protection. Rate limits cover sign-in, sign-up, creating and revealing, and a strict content security policy applies to every page.

  • No secrets in the logs. The web server is set up so links are never written to its access logs.

  • Tested. An automated test suite covers the whole lifecycle, including a test that searches the entire database and fails if any plaintext or link token turns up.


Try it

One-Time Secret is free to use. Create a free account to send; whoever you send a link to doesn't need one.

Open One-Time Secret


Technical stack

Next.js 15 and React 19 in TypeScript, MongoDB with Mongoose, AES-256-GCM with HKDF key derivation, JWT sessions with jose, Nodemailer, Zod validation, reCAPTCHA v3 and Vitest, running as a Node.js service behind nginx on my own infrastructure.

Gallery

Product DevelopmentSecurityEncryptionSecure File SharingNext.js

Project Links

Interested in similar work?

Get in touch to discuss your project.

Start a conversation

Let's Work Together

Ready to Build Something Remarkable?

Whether you need a bespoke website, a full digital marketing strategy or a technical partner who understands business, I'm here.