About Onetime Secret
Onetime Secret keeps passwords and other sensitive information out of chat logs and email inboxes. You paste a secret and receive a link that can be opened only once; after that the content is gone, so only the intended recipient sees it. The project is written in Ruby and released under the MIT license.
You can try it on the hosted service at OnetimeSecret.com or run your own instance, and a Docker quick start is provided. A first run creates an administrator account, called the colonel, with a generated password. The project warns that losing the SECRET key cannot be recovered and makes existing secrets unreadable, so it must be backed up.
For production, the self-hosting guide covers a reverse proxy, a fuller authentication setup with PostgreSQL and RabbitMQ including MFA and WebAuthn, and hardening, along with Docker Compose files and configuration references. It suits IT teams, support staff, and developers who regularly need to send credentials to colleagues or customers. The maintainers note that AI tools helped with parts of development.
Key features
- Single-use links that self-destruct after viewing
- Hosted service and self-hosted option
- Docker and Docker Compose deployment
- Optional full authentication with MFA and WebAuthn
- Administrator account created on first run
- Configurable through environment settings
Good fit for
- →Sending passwords to customers without email history
- →Sharing API keys with teammates safely
- Built with
- Ruby
- Tags
- secrets
- password-sharing
- security
- privacy
- self-hosted
- ruby
- docker
- one-time-link
Onetime Secret: questions and answers
- What is Onetime Secret used for?
- Onetime Secret is a service for sharing passwords and sensitive text through single-use links that self-destruct after one view, available hosted or self-hosted. It is a good fit for sending passwords to customers without email history and sharing API keys with teammates safely.
- Is Onetime Secret open source?
- Yes. Onetime Secret is open source under the MIT licence. Its source code is on GitHub at onetimesecret/onetimesecret and is written mainly in Ruby.
- Is Onetime Secret free?
- Yes. Onetime Secret is open source, so the software itself is free to use. A managed cloud version is also available, with paid plans from €35 per month.
- Can I self-host Onetime Secret?
- Yes. Onetime Secret can be self-hosted on your own server or infrastructure.
- What are some alternatives to Onetime Secret?
- Similar open-source tools in the Security category include Password Pusher, Cryptomator and VeraCrypt. SaaS products in the same category include Aura, DeleteMe and DoHackersKnow.Me.
- Is Onetime Secret actively maintained?
- Yes. The most recent commit to Onetime Secret was on 2 October 2026, and the latest release is v0.26.14, published on 30 September 2026. The project has 3k stars on GitHub.
Open-source alternatives to Onetime Secret
See allPassword Pusher
Security
🔐 Securely share sensitive information with automatic expiration & deletion after a set
Apache-2.0★ 3.2k
Cryptomator
Security
Cryptomator for Windows, macOS, and Linux: Secure client-side encryption for your cloud st
GPL-3.0vs Tresorit★ 16k
VeraCrypt
Security
Disk encryption with strong security based on TrueCrypt
OSS★ 12kCryptgeon
Security
cryptgeon is a secure, open source note / file sharing service inspired by PrivNote writte
MIT★ 1.5k
Infisical
Security
Infisical is the open-source platform for secrets, certificates, and privileged access man
OSSvs Doppler★ 30k
SafeLine
Security
CyberServal open-source WAF is a self-hosted WAF with 20.9K GitHub stars. Block SQL inject
GPL-3.0vs Cloudflare★ 23k
SaaS alternatives to Onetime Secret
See all
Aura
Security
Consumer identity theft protection bundling credit monitoring, VPN and antivirus
SaaS
DeleteMe
Security
Subscription that removes personal information from people-search sites and data brokers
SaaS
DoHackersKnow.Me
Security
Privacy scan that checks the dark web for your exposed passwords, contact details and personal data
SaaS
GitGuardian
Security
Detects leaked secrets and credentials in code repositories and developer tools
SaaS
Incogni
Security
Service that requests removal of your personal data from data broker databases
SaaS
OneTrust
Security
Privacy, consent management and governance, risk and compliance software
SaaS

