Free · No account · End-to-end encrypted
One secret, one read, no trace.
Paste a password or an API key and get a link encrypted in your browser. It self-destructs after reading. We never see the content.
- AES-256 encryption in your browser, before anything is sent
- Single-use link, protected by a code if you wish
- No account, no trackers, hosted in the EU
A password sent by email never really goes away
| Criterion | Email, Slack, Teams, text | Sésame Éclair |
|---|---|---|
| Lifetime | Until someone deletes it, on the sender's and the recipient's side | One read, or the expiry you choose (5 minutes to 30 days) |
| Copies | Histories, backups, search indexes, compliance exports | A single encrypted block that we cannot read |
| Third-party access | Anyone who gets into the mailbox or account, even years later | The link opens only once; a code sent separately can be added |
| Knowing it was read | Depends on the tool | Yes, through a private tracking link |
Send the link through your usual channel: once read, it leads nowhere.
Three steps, no trace
Paste
Your password, key or .env file. It is encrypted in your browser.
Send
The link, by email, Slack or text. The code, if any, through another channel.
Read, then gone
One read, then the secret disappears from our servers.
We cannot read your secrets. Check it.
The key stays in the link
It lives after the # sign, which browsers never send to servers.
Standard encryption
AES-256-GCM and Argon2id through native browser implementations. No home-made cryptography.
Published format
Full specification and public test vectors. External audit planned before 1.0.
Zero trackers
No third-party scripts, no analytics, no ads. Strict security policy.
Everything you need, for free
Available
Encrypted in your browser
AES-256-GCM before anything is sent. The key stays in the link, after the #, and never reaches us.
Available
Self-destruction
After 1 to 10 reads, or at the date you choose (5 minutes to 30 days). An expired secret is unreadable at once.
Available
PIN or passphrase
An extra layer, sent through another channel. 5 attempts, then the secret is destroyed.
Available
Read receipt
A private tracking link tells you whether the secret was read, and lets you destroy it first.
Available
Safe from link previewers
Slack, Teams or Outlook may open a link before you do. The secret is only revealed when you click “Reveal”.
Available
Delayed reveal
The secret only opens from a chosen date, for example a new hire's first day.
How we compare
| Service | Encryption | No account | Price |
|---|---|---|---|
| Sésame Éclair | In the browser | Yes | Free |
| Onetime Secret | Server side (“encrypted on our servers”) | Yes | Free, then €35 to €125/month |
| Password.link | In the browser (zero-knowledge, per its page) | Yes | Limited free, then €59.99 to €99.99/month excl. VAT |
| Password Pusher | At rest, server side | Yes | Free, then $19 to $49/month |
| scrt.link | End to end | Yes | Limited free, then $12 to $60/year |
| Bitwarden Send | End to end | No | Free text with an account, files at $19.80/year |
Facts taken from each service's public pages. Details and sources in each comparison.
Who is it for?
Web agencies and freelancers
Client credentials do not belong in a mailbox that stays searchable for years.
Dev and DevOps teams
A key pasted in Slack stays in exports, backups and search indexes.
IT support and helpdesk
A temporary password should never stay readable for more than a few minutes.
Individuals and families
The gate or alarm code does not need to stay in a family chat.
Frequently asked questions
Can you read my secrets?
No. The secret is encrypted in your browser before it is sent, with a key that stays in the link, after the # sign. Browsers never send that part of the address to servers. We only receive an unreadable encrypted block.
Is it really free?
Yes, with no account, no ads and no time limit. A paid enterprise plan (white label, teams, SSO) will come later, without removing any free feature.
What happens after it is read?
The secret is deleted from our database in the same operation as the read. If someone opens the link again, they see the same message as for an unknown link.
What if Slack or Outlook opens the link before my recipient?
No risk. The link page does not contain the secret. It is only sent after a click on “Reveal”, which link previewers do not do.
Can the recipient keep a copy of the secret?
Yes, and no service can prevent it: once displayed, a secret can be copied, written down or photographed. Sésame Éclair guarantees that the link opens only once and that nothing remains on our side; it does not control what the recipient does afterwards. Only send secrets to people you trust.