Send passwords with a self-destructing link

Passwords and private notes are encrypted in your browser. Links expire after a number of views or a period of time — whichever comes first.

Password generator

 

Human-readable passwords look like WordWordWord77$. Every password includes at least 2 numbers.

Generated in your browser with jspassgen and the EFF wordlist. Nothing is sent anywhere.

Expiration and security options

Whichever comes first. After that, the content is deleted from the server.

Share it separately (e.g. by phone). It's also mixed into the encryption key.

Only stored in this browser, to help you find it in My pushes.

End-to-end encrypted

Content is encrypted with AES-256-GCM before upload. The key is in the part of the link after #, which browsers never send to the server.

Self-destructing

Choose how many views and how long. Once either limit is hit, the encrypted content is permanently deleted.

Audit trail

See exactly when your link was opened, from where, and whether anyone guessed at the passphrase.

Frequently asked questions

How does SendThePass.com keep a password safe?

Everything is encrypted in your browser with AES-256-GCM before it is uploaded. The decryption key is in the part of the link after the # sign, which browsers never send to the server, so the server only ever stores encrypted data it cannot read.

What can the server see about my secrets?

Only encrypted data. The decryption key stays in your link and is never sent to the server, so it cannot read what you share. It does know when a link was created and opened, and the IP address, country and browser of each visit, which are shown to you in the audit log. The full link is the key: anyone who has it can open the secret until it expires, so add a passphrase for anything sensitive and send it separately.

What happens when a link expires?

A link stops working as soon as it reaches the number of views or the amount of time you chose, whichever comes first. When the last view is used, its encrypted content is deleted straight away; when the time runs out, it is permanently deleted by a clean-up that runs every hour. Expiring a link yourself, the recipient deleting it, or too many wrong passphrases deletes it immediately. The link’s status page and audit log are kept for 30 days after it expires, then deleted as well.

Will link previews in Slack, Teams or email use up a view?

Not with “Require a click to reveal”, which is on by default. The recipient has to click a button before the secret is decrypted, so chat apps and email security scanners that open links automatically do not count as a view.

What can I send?

Passwords and other text, such as API keys, recovery codes or private notes, and QR codes such as Wi-Fi details. You can add a passphrase, and by default the recipient can delete the secret as soon as they have saved it (you can turn this off).

How do I know whether my link was opened?

Every link has a private status page with an audit log showing when it was created and viewed, from which IP address, country and browser, and any failed passphrase attempts. You can also expire the link early from there.

Who runs SendThePass.com?

SendThePass.com is sponsored by HUFF DATA SYSTEMS and built by HUFF DATA SYSTEMS team members. HUFF DATA SYSTEMS provides managed IT, cybersecurity and cloud services.