One-Time Secret Alternatives: Six Ways to Share a Secret That Expires
One-Time Secret, Yopass, Password Pusher, Bitwarden Send, password-manager share links and a photo-based approach for teams — what each one is good at, where it is weak, and the three questions that pick the right one: who runs the server, what stops a link preview spending your single view, and can you take it back?
One-Time Secret made a simple idea popular: paste a secret, get a link, and the link shows the secret exactly once before it is destroyed. It is a big improvement over a password sitting in an inbox for ten years.
If you are looking for an alternative — free, self-hosted, with files, with an audit trail, or something you can revoke — these are the options worth knowing, grouped by what they are good at.
Described as of September 2026. Check each project’s site for current limits and pricing.
Three questions that decide
- Who runs the server, and can it read the secret? Tools that encrypt in your browser store only ciphertext; the key travels in the link’s
#fragment, which browsers do not send to the server. Otherwise you are trusting the operator — or you self-host. - What stops something else opening the link first? Chat previews and corporate mail scanners fetch links. A single-view secret can be spent before the human sees it.
- Can you take it back? For link tools the honest answer is: only until it is opened.
The link tools
One-Time Secret
The original. Open source, can be self-hosted, optional passphrase, configurable expiry. Simple and widely recognised, which matters when you ask a client to click something. Encryption happens on the server, so on the public site you are trusting the operator; self-hosting moves that trust to you.
Yopass
Open source, small, easy to self-host. Encrypts in the browser, so the server only ever holds ciphertext. Expiry of an hour, a day or a week, a one-time-download option, and it handles files as well as text. A good default for technical teams.
Password Pusher
Open source, self-hostable, expires after a number of views or days, whichever comes first. Its useful extra is a retrieval step — the recipient must click before the secret is revealed — which defeats most link previews and scanners. Also offers an audit log of views.
Bitwarden Send
Part of Bitwarden rather than a separate site. End-to-end encrypted, text or files, with a deletion date, an expiry, a maximum access count and an optional password. If your organisation already runs Bitwarden, this is the path of least resistance.
A password manager’s item link
1Password and others can share a single vault item by link, with an expiry and, optionally, a restriction to named email addresses that must verify themselves. Best when the secret already lives in your vault and the recipient is outside it.
The messenger option
If both of you use Signal, disappearing messages with a short timer do the job with no link at all. WhatsApp’s View Once does not cover text. More in How to Send a Self-Destructing Message on iPhone and Is It Safe to Send a Password over WhatsApp?.
When a link is the wrong shape: WaxSeal
All of the above share three traits. The secret is delivered by a link — exactly what staff are trained not to click, and exactly what scanners open. It works for whoever holds the link. And once opened, it is gone from your control.
WaxSeal is built for organisations that need the opposite:
- No link. The sender picks any photo; WaxSeal marks it with an invisible reference that survives WhatsApp, WeChat, Telegram and Instagram compression. You send a photo, in the app the recipient already uses. There is nothing for a preview bot to fetch.
- Bound to a device, not to possession. The secret is encrypted on the sender’s device for the chosen recipients’ devices, whose keys live in the Secure Enclave. A forwarded photo opens for nobody else.
- The vault cannot read it. It holds ciphertext and signed authorisation records. WaxSeal Cloud is hosted by us; a self-hosted option for regulated teams follows in Q4 2026.
- Control after sending. Burn after reading, read limits, expiry, an optional PIN with five attempts — and revocation: withdraw a seal, or a lost device, and the photo simply stops opening.
The limits, stated plainly: both sides need the app (iPhone, iPad, Mac); sending to other people happens inside a team workspace, with recipients free; and revoking ends further authorised opening — it cannot un-show what was already read, so you still rotate a credential you no longer trust. For two friends and a Wi-Fi password, a one-time link is the right tool. Pricing for teams is on the WaxSeal pricing page.
Quick chooser
| You need… | Use |
|---|---|
| the quickest free link, recipient is non-technical | One-Time Secret |
| the server never to see the secret; self-hosting; files | Yopass |
| protection from link previews; a view log | Password Pusher |
| it inside the password manager you already have | Bitwarden Send or an item link |
| no link at all, between two Signal users | Signal disappearing messages |
| device-bound recipients, revocation, delivery through any chat — for a team | WaxSeal |
Whichever you choose, two habits matter more than the tool: send any passphrase or PIN on a different channel, and change first-login passwords after first use.
One secret deserves its own rules: a card number. Most of the time you should not be sending it at all — see How to Send Credit Card Details Securely. And if your instinct is to reach for your mail provider’s built-in option instead, read Is Gmail Confidential Mode Actually Secure? first.
Frequently asked questions
Is there a free alternative to One-Time Secret?
Are one-time secret links safe?
Why does my one-time link say the secret was already viewed?
Can I revoke a secret after someone has opened it?
StegoSafe hides AES-256-encrypted secrets inside ordinary photos — in a deniable format with no header or marker — and can split them across several photos with Shamir Secret Sharing. Runs fully offline on iPhone, iPad and Mac; one universal purchase. For organisations that must send a secret and control it afterwards, see WaxSeal
Get StegoSafe →