Zum Inhalt springen

Sie sehen die Vorabversion der DokumentationInhalte dienen hier nur zu Testzwecken und können von der Live-Dokumentation abweichen.

Zur Live-Dokumentation

Homepage and Incoming Secrets

Dieser Inhalt ist in Ihrer Sprache noch nicht verfügbar.

When you set up a custom domain, the address — for example secrets.yourbrand.com — has its own homepage. Two settings decide what that homepage does: whether it is enabled at all, and which interactive experience it offers when it is. The two experiences are the classic secret-creation form (Homepage Secrets) and the incoming-secrets form (Incoming Secrets).

You manage both from your Domain Dashboard at any time. The settings are domain-specific, so each of your custom domains can behave differently.

Homepage Secrets is the setting that controls whether visitors to your branded homepage can create and share secrets directly from your interface.

On your Domain Dashboard you can configure the visibility of your branded homepage. Enabling this feature allows your clients, customers, or team members to create and share secrets directly from your branded interface.

Preview panel showing branded interface

If you would rather use your custom domain only for the secret links you generate yourself — and not present a public secret-creation page — you can disable the homepage entirely.

Homepage disabled view
  • Changes process immediately upon saving.
  • Allow up to 5 minutes for CDN cache refresh.
  • Settings are domain-specific.

Most of Onetime Secret is about sending a secret: you create a one-time link and share it with someone. Incoming Secrets flips that direction. It gives you a destination page on your custom domain where other people — customers, clients, vendors, or colleagues — can send a secret to you, without needing an account of their own.

This is useful whenever you need to collect sensitive information rather than distribute it, for example:

  • A client sending you credentials, API keys, or account details during onboarding
  • A customer submitting a document or value you need to handle securely
  • A vendor returning a password or token you provisioned for them
  1. You enable an incoming page for your verified custom domain.
  2. You configure who receives the submitted secrets (a preconfigured list of recipients).
  3. You share the page’s address — for example secrets.yourbrand.com — with the sender.
  4. The sender writes their secret and submits it; it is encrypted and delivered as a one-time link to your configured recipients.

We’re here to help.