Free, no account, end-to-end encryptedRequest a secret →

"I'll email you the login." It is an ordinary sentence and it feels harmless. Yet a password pasted into an email almost never goes away.

Where it ends up

  • In your Sent folder, and in the recipient's inbox, on every synced device.
  • In the backups of both mailboxes, often kept for months or years.
  • In forwards: a colleague forwards the thread to a contractor, who forwards it again.
  • In search: typing "password" into a compromised mailbox brings back years of credentials.

The day one of these mailboxes is breached, every credential in it is breached too. And nobody remembers sending them.

What it should be

Shared credentials should have three properties:

  1. Readable once, then gone from the server.
  2. Expiring if not opened, after a few hours or days.
  3. Never readable by the intermediary that carries them.

That is exactly what a Sésame Éclair link does. The secret is encrypted in your browser. The link works once (or as many times as you choose), then it is destroyed. What remains in the email or chat is a dead link.

In practice

  • Paste the credentials on the home page, pick a short expiry and, for sensitive access, a PIN.
  • Send the link by email or chat, and the PIN through another channel (text message, call).
  • Keep the tracking link: it tells you whether the secret was read and lets you destroy it early.
  • To receive credentials from clients, create a drop link: they submit the encrypted secret, and only you can read it.

For credentials you use every day, a password manager remains the right tool: Sésame Éclair is for the moment you need to hand them over.

← All posts