7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

Onetime Secret

Open source

Service for sharing passwords and sensitive text through single-use links that self-destruct after one view, available hosted or self-hosted.

onetimesecret.com
Onetime Secret homepage screenshot
GitHub stars
3k
Last commit
yesterday
Repository age
13 years
Version
v0.26.14
Licence
MIT
Self-hosted
Yes

About Onetime Secret

Onetime Secret keeps passwords and other sensitive information out of chat logs and email inboxes. You paste a secret and receive a link that can be opened only once; after that the content is gone, so only the intended recipient sees it. The project is written in Ruby and released under the MIT license.

You can try it on the hosted service at OnetimeSecret.com or run your own instance, and a Docker quick start is provided. A first run creates an administrator account, called the colonel, with a generated password. The project warns that losing the SECRET key cannot be recovered and makes existing secrets unreadable, so it must be backed up.

For production, the self-hosting guide covers a reverse proxy, a fuller authentication setup with PostgreSQL and RabbitMQ including MFA and WebAuthn, and hardening, along with Docker Compose files and configuration references. It suits IT teams, support staff, and developers who regularly need to send credentials to colleagues or customers. The maintainers note that AI tools helped with parts of development.

Key features

  • Single-use links that self-destruct after viewing
  • Hosted service and self-hosted option
  • Docker and Docker Compose deployment
  • Optional full authentication with MFA and WebAuthn
  • Administrator account created on first run
  • Configurable through environment settings

Good fit for

  • →Sending passwords to customers without email history
  • →Sharing API keys with teammates safely
Built with
Ruby
Tags
secrets
password-sharing
security
privacy
self-hosted
ruby
docker
one-time-link

Onetime Secret: questions and answers

What is Onetime Secret used for?
Onetime Secret is a service for sharing passwords and sensitive text through single-use links that self-destruct after one view, available hosted or self-hosted. It is a good fit for sending passwords to customers without email history and sharing API keys with teammates safely.
Is Onetime Secret open source?
Yes. Onetime Secret is open source under the MIT licence. Its source code is on GitHub at onetimesecret/onetimesecret and is written mainly in Ruby.
Is Onetime Secret free?
Yes. Onetime Secret is open source, so the software itself is free to use. A managed cloud version is also available, with paid plans from €35 per month.
Can I self-host Onetime Secret?
Yes. Onetime Secret can be self-hosted on your own server or infrastructure.
What are some alternatives to Onetime Secret?
Similar open-source tools in the Security category include Password Pusher, Cryptomator and VeraCrypt. SaaS products in the same category include Aura, DeleteMe and DoHackersKnow.Me.
Is Onetime Secret actively maintained?
Yes. The most recent commit to Onetime Secret was on 2 October 2026, and the latest release is v0.26.14, published on 30 September 2026. The project has 3k stars on GitHub.

Open-source alternatives to Onetime Secret

See all

SaaS alternatives to Onetime Secret

See all