Securely sharing authentication details

Send us a password or an API key as a one-time secret, never in an email or a chat message. The link works once and the content is gone after it.

Send us a secret

  1. Go to onetimesecret.com.
  2. Put the sensitive part in the text field: the password, the API key, the token. Leave the username out of it.
  3. Optionally add a passphrase. That encrypts the secret and stores the passphrase as a bcrypt hash, so only somebody who has the passphrase can open it.
  4. Set how long it may live. Too short and it is destroyed before we get to it; a working day is usually right.
  5. Create the secret link and send it to us.

If you need a password rather than already having one, the site can generate a random one for you and show it once before you share the link.

Keep the username away from the password

Put only the secret behind the link and the rest in the message, like this.

Username and password

Username: someone@example.com
Password: https://onetimesecret.com/secret/397rosam041tsvt4azmv0tth3evs6x2

API credentials

Client ID: ZYDPLLBWSK3MVQJSIYHB1OR2JXCY0X2C5UJ2QAR2MAAIT5Q
Client Secret: https://onetimesecret.com/secret/397rosam041tsvt4azmv0tth3evs6x2

Whoever intercepts the message then has half of the pair, and the half that is worth nothing on its own. If you set a passphrase, we need it too, so put it in the same message. Be aware of what that costs: anyone who reads the whole message then has both halves, and the passphrase only protects you if the link leaks on its own. For something that would be serious to lose, give us the passphrase another way instead, by telephone for example.

Open a secret we sent you

Click the link, type the passphrase if you are asked for one, and read what is behind it. It is shown once and destroyed straight away, so copy it where it needs to go before you close the page.

If you see Unknown Secret - It either never existed or has already been viewed, the secret is gone. Either the link had already been opened, or it expired. Tell us: we will send a new one, and if there is any doubt about who opened it, we change the credential rather than resend it.

After it reaches us

Authentication details you send us are stored in an encrypted vault. Nothing sensitive stays in the ticket, the mailbox or the chat, which is the whole point of the exercise.

The same holds in your direction. Anything you paste into an email or a chat message stays on a mail server, in a chat history and in somebody's backup, for as long as those keep it. A one-time secret leaves nothing behind but a link that no longer works.

See also

Was this article helpful?

1

Still stuck?

Our support team will take a look with you.

Comments

0 comments

Article is closed for comments.