Free, no account, end-to-end encryptedRequest a secret →

Free · No account · End-to-end encrypted

One secret, one read, no trace.

Paste a password or an API key and get a link encrypted in your browser. It self-destructs after reading. We never see the content.

  • AES-256 encryption in your browser, before anything is sent
  • Single-use link, protected by a code if you wish
  • No account, no trackers, hosted in the EU

Share a secret

Encrypted in your browser before anything is sent. We never see the content.

Options1 read · expires in 24 hours · no code
Number of reads
Expiration

The secret cannot be opened before this date.

Extra protection

Encrypted too. The recipient sees it before revealing the secret.

One name per line, 10 at most. Each person gets their own link, with its own read receipt, and can be destroyed separately.

Restrict access (advanced)

The secret only opens from these networks or countries. A VPN can bypass the rule: it is a safeguard, not absolute protection.

A password sent by email never really goes away

CriterionEmail, Slack, Teams, textSésame Éclair
LifetimeUntil someone deletes it, on the sender's and the recipient's sideOne read, or the expiry you choose (5 minutes to 30 days)
CopiesHistories, backups, search indexes, compliance exportsA single encrypted block that we cannot read
Third-party accessAnyone who gets into the mailbox or account, even years laterThe link opens only once; a code sent separately can be added
Knowing it was readDepends on the toolYes, through a private tracking link

Send the link through your usual channel: once read, it leads nowhere.

Three steps, no trace

  1. Paste

    Your password, key or .env file. It is encrypted in your browser.

  2. Send

    The link, by email, Slack or text. The code, if any, through another channel.

  3. Read, then gone

    One read, then the secret disappears from our servers.

We cannot read your secrets. Check it.

The key stays in the link

It lives after the # sign, which browsers never send to servers.

Standard encryption

AES-256-GCM and Argon2id through native browser implementations. No home-made cryptography.

Published format

Full specification and public test vectors. External audit planned before 1.0.

Zero trackers

No third-party scripts, no analytics, no ads. Strict security policy.

See what the server receives

Everything you need, for free

Available

Encrypted in your browser

AES-256-GCM before anything is sent. The key stays in the link, after the #, and never reaches us.

Available

Self-destruction

After 1 to 10 reads, or at the date you choose (5 minutes to 30 days). An expired secret is unreadable at once.

Available

PIN or passphrase

An extra layer, sent through another channel. 5 attempts, then the secret is destroyed.

Available

Read receipt

A private tracking link tells you whether the secret was read, and lets you destroy it first.

Available

Safe from link previewers

Slack, Teams or Outlook may open a link before you do. The secret is only revealed when you click “Reveal”.

Available

Delayed reveal

The secret only opens from a chosen date, for example a new hire's first day.

All features

How we compare

ServiceEncryptionNo accountPrice
Sésame ÉclairIn the browserYesFree
Onetime SecretServer side (“encrypted on our servers”)YesFree, then €35 to €125/month
Password.linkIn the browser (zero-knowledge, per its page)YesLimited free, then €59.99 to €99.99/month excl. VAT
Password PusherAt rest, server sideYesFree, then $19 to $49/month
scrt.linkEnd to endYesLimited free, then $12 to $60/year
Bitwarden SendEnd to endNoFree text with an account, files at $19.80/year

Facts taken from each service's public pages. Details and sources in each comparison.

Frequently asked questions

Can you read my secrets?

No. The secret is encrypted in your browser before it is sent, with a key that stays in the link, after the # sign. Browsers never send that part of the address to servers. We only receive an unreadable encrypted block.

Is it really free?

Yes, with no account, no ads and no time limit. A paid enterprise plan (white label, teams, SSO) will come later, without removing any free feature.

What happens after it is read?

The secret is deleted from our database in the same operation as the read. If someone opens the link again, they see the same message as for an unknown link.

What if Slack or Outlook opens the link before my recipient?

No risk. The link page does not contain the secret. It is only sent after a click on “Reveal”, which link previewers do not do.

Can the recipient keep a copy of the secret?

Yes, and no service can prevent it: once displayed, a secret can be copied, written down or photographed. Sésame Éclair guarantees that the link opens only once and that nothing remains on our side; it does not control what the recipient does afterwards. Only send secrets to people you trust.

All questions

Ready to send your first secret?

Free, no account, in under 10 seconds.

Share a secret