Secure credential handoff
For contractors, clients, IT support, and employee onboarding
Short answer: OncePad is a free, no-account service for sharing a password, secret, or file through an end-to-end encrypted link. The link contains no decryption key, works once, and expires after 24 hours. Files may be up to 25 MB.
The handoff is where credentials escape
A credential may be safe in a vault before and after onboarding yet leak through the Slack message, email, ticket, or shared document used to transfer it. A one-time encrypted handoff removes that durable plaintext copy without requiring the recipient to create an account.
Contractors and clients
Send the OncePad link in the project channel or ticket, then give the passphrase by text or a call. Prefer a scoped, temporary credential, and ask the recipient to move it immediately into their password manager or secrets vault. Revoke it when the engagement ends.
Employee onboarding and IT support
Use separate links for the initial password, recovery codes, VPN configuration, or support token rather than bundling identity, login URL, and credential together. Require a password change at first sign-in and use the service's Erase it now control if the recipient or channel was wrong.
A handoff is not lifecycle management
OncePad does not verify identity, track which employee opened a link, rotate credentials, revoke third-party sessions, or retain an audit trail. Teams that need those controls should use an identity provider, enterprise password manager, or privileged-access system; the one-time link only handles delivery.