Guides
OncePad is a free, no-account, one-time handoff. These pages are how to use it for a specific job.
Short answer: OncePad is a free, no-account service for sharing a password, secret, or file through an end-to-end encrypted link. The link contains no decryption key, works once, and expires after 24 hours. Files may be up to 25 MB.
- one-time file sharing — Send an end-to-end encrypted file up to 25 MB with no account. The key stays out of the link, the file downloads once, and an unopened link expires after 24 hours.
- one-time secret link — Share a password, private note, API key, or file through an encrypted one-time secret link. It carries no decryption key, works once, and expires after 24 hours.
- credential handoff — Hand credentials to a contractor, client, IT technician, or new employee without leaving the password in chat, email, a ticket, or an onboarding document.
- share a private key — Send an SSH key, certificate, connection string, service-account JSON, or .env file through a one-time browser-encrypted link and a separate passphrase.
- send sensitive documents — Send a tax form, ID scan, signed document, or client file up to 25 MB through an end-to-end encrypted link that permits one download and expires after 24 hours.
- share a password — Sending a password by email or chat leaves it readable forever. Share it instead with a one-time, end-to-end encrypted link and a passphrase you say out loud — no account needed.
- share API keys & .env — API keys, tokens and .env files don't belong in chat history or tickets. Send them with a one-time encrypted link that self-destructs after it is read.
- self-destructing message — Send a self-destructing message that can be read once and then disappears — encrypted in your browser, burned on read, gone after 24 hours, no account and nothing to install.
- FAQ — Everything about OncePad's one-time secret sharing: how the encryption works, what the server can see, expiry, passphrases, link previews, limits, and what happens when things go wrong.