Share secrets that disappear.
Send passwords, API keys, and sensitive notes through a link that destroys itself once it's been read.
Instructions, notes, recovery codes, API keys, access tokens — anything sensitive.
Every secret expires. After this point it is destroyed permanently, even if nobody opened it. The maximum is 30 days.
Encrypted in this browser before it is sent. The decryption key travels only in the link, after the #.
truePassNote trust metrics
- 0
- Secrets created securely
- 0
- Secrets successfully opened
- 0
- Secrets readable by PassNote
How it works
Create your secret
Write a note or generate a strong password or passphrase.
Encrypt locally
Your browser encrypts the secret. We never see the contents.
Share the link
Send the secure link to your recipient through any channel.
They open it once
The recipient decrypts and reads it directly in their browser.
It self-destructs
After viewing — or your custom rules — it's gone forever.
What PassNote protects — and what it can't
Encrypted in your browser
PassNote encrypts your secret content in this browser before it is sent. The server stores the encrypted content together with limited lifecycle information needed to operate the link.
The key stays in the link
The decryption key is the part of the recipient link after the #. The PassNote application does not send that part to the server. A separate password may also be required when password protection is enabled.
Revealing is deliberate
Simply loading the page does not reveal or use a view. The recipient must deliberately press Reveal or successfully pass the password step.
Permanent destruction
When a secret expires, is revoked or uses its final allowed view, PassNote permanently removes the encrypted secret content, its IV, any password verifier and the encrypted recipient-link recovery payload. Limited lifecycle information may remain for seven days so the management page can explain what happened.
What PassNote cannot do
PassNote cannot protect a secret from a compromised browser, device or browser extension, and cannot confirm the identity of the person using a recipient link.