Send passwords with a self-destructing link
Passwords and private notes are encrypted in your browser. Links expire after a number of views or a period of time — whichever comes first.
Password generator
Human-readable passwords look like WordWordWord77$. Every password includes at least 2 numbers.
Generated in your browser with jspassgen and the EFF wordlist. Nothing is sent anywhere.
Your secret link
The link is saved in My pushes on this browser so you can check views or expire it early.
End-to-end encrypted
Content is encrypted with AES-256-GCM before upload. The key is in the part of the link after #, which browsers never send to the server.
Self-destructing
Choose how many views and how long. Once either limit is hit, the encrypted content is permanently deleted.
Audit trail
See exactly when your link was opened, from where, and whether anyone guessed at the passphrase.
Frequently asked questions
How does SendThePass.com keep a password safe?
Everything is encrypted in your browser with AES-256-GCM before it is uploaded. The decryption key is in the part of the link after the # sign, which browsers never send to the server, so the server only ever stores encrypted data it cannot read.
What can the server see about my secrets?
Only encrypted data. The decryption key stays in your link and is never sent to the server, so it cannot read what you share. It does know when a link was created and opened, and the IP address, country and browser of each visit, which are shown to you in the audit log. The full link is the key: anyone who has it can open the secret until it expires, so add a passphrase for anything sensitive and send it separately.
What happens when a link expires?
A link stops working as soon as it reaches the number of views or the amount of time you chose, whichever comes first. When the last view is used, its encrypted content is deleted straight away; when the time runs out, it is permanently deleted by a clean-up that runs every hour. Expiring a link yourself, the recipient deleting it, or too many wrong passphrases deletes it immediately. The link’s status page and audit log are kept for 30 days after it expires, then deleted as well.
Will link previews in Slack, Teams or email use up a view?
Not with “Require a click to reveal”, which is on by default. The recipient has to click a button before the secret is decrypted, so chat apps and email security scanners that open links automatically do not count as a view.
What can I send?
Passwords and other text, such as API keys, recovery codes or private notes, and QR codes such as Wi-Fi details. You can add a passphrase, and by default the recipient can delete the secret as soon as they have saved it (you can turn this off).
How do I know whether my link was opened?
Every link has a private status page with an audit log showing when it was created and viewed, from which IP address, country and browser, and any failed passphrase attempts. You can also expire the link early from there.
Who runs SendThePass.com?
SendThePass.com is sponsored by HUFF DATA SYSTEMS and built by HUFF DATA SYSTEMS team members. HUFF DATA SYSTEMS provides managed IT, cybersecurity and cloud services.