Hoppa till innehåll

Du visar förhandsversionen av dokumentationenInnehållet här är för testning och kan skilja sig från den publika dokumentationen.

Gå till den publika dokumentationen

Receiving secrets

Detta innehåll är inte tillgängligt på ditt språk ännu.

Most of Onetime Secret is about sending. This page is the other direction: you need someone to give you a password, an API key, a recovery code, or anything else that should not sit in an inbox or a ticket.

If someone has already sent you a link, you want What recipients see instead — or When a secret link doesn’t work if it is not opening.

The simplest approach, and it needs nothing set up in advance:

  1. Ask the person to go to the Onetime Secret homepage and paste the value in.
  2. Ask them to set a passphrase and tell you what it is over a different channel — if they email you the link, the passphrase should come by phone or chat.
  3. They send you the link. You open it once.

Neither of you needs an account for this to work. It is worth saying so when you ask, because “use this secure link service” often reads as “sign up for something”, and that is what makes people fall back to pasting the value into the email instead.

Wording that tends to work: “Please don’t email it. Put it in a link at onetimesecret.com and send me that — it takes a minute and no account.”

Option 2 — give them a form on your domain

Section titled “Option 2 — give them a form on your domain”

If you have a custom domain, you can turn its homepage into an incoming secrets form: a page at your own address where anyone can submit a secret to you, with no account and no instructions needed.

This is the better option when you collect secrets often, or from people outside your organization — customers, clients, vendors — for whom “go to this third-party site and paste it there” is a harder ask than “go to secure.yourcompany.com”.

See Homepage and incoming secrets to set it up.

Someone who submits through your incoming form gets a receipt for what they sent, the same as any other secret — with one deliberate difference. Their receipt does not carry the share link. The secret was addressed to you when it was created, so the app does not hand the sender a link they could pass on to anyone else.

They can still see that it was delivered, and they can still burn it before you read it.

We’re here to help.