How to share a password securely

By email, Slack, text or phone — without leaving it readable forever

Short answer: OncePad is a free, no-account service for sharing a password, secret, or file through an end-to-end encrypted link. The link contains no decryption key, works once, and expires after 24 hours. Files may be up to 25 MB.

Why email and chat are the wrong place

A password pasted into an email or a chat message is copied to servers you don't control, kept in searchable history and backups for years, and readable by anyone who later gets into either account. It is also the first thing an attacker searches for. The problem is not the channel's encryption in transit — it is that the password stays there, in plain text, forever.

What "securely" actually requires

  • Encrypted before it leaves you — in your browser, not on someone's server.
  • One-time — the first person to open it is the only person who ever can.
  • Short-lived — if nobody opens it, it should expire on its own.
  • Nothing readable in the message you send — so the chat history holds nothing.
  • Two channels — the thing that opens it must not travel with the link.

Share a password securely in 30 seconds

  1. Go to oncepad.com and paste the password. Your browser encrypts it under a generated 7-word passphrase — end-to-end, before anything is uploaded.
  2. Send the link the normal way — email, Slack, a ticket. It carries no key, so it is safe there.
  3. Give the passphrase on a different channel: read it out on a call, or send it by text if the link went by email.
  4. They open the link, type the seven words, and see the password once. It is destroyed on the server the moment it is revealed — or after 24 hours if they never open it.

Sharing a password by text message or over the phone

SMS is the least private channel of all — it is unencrypted and often synced to several devices. Never text the password itself. Text the link (which holds nothing readable) and say the passphrase out loud, or send the link by email and the passphrase by text: two channels, either order.

With a teammate, a client, or a family member

The recipient needs nothing: no account, no app, no plugin — just a browser. That makes this the simplest way to hand a Wi-Fi password to a guest, a login to a contractor, or a shared account to a new hire. For credentials a team uses every day, a password manager with sharing is the right long-term home; a one-time link is for the hand-off itself.

If it doesn't get opened, or you sent it by mistake

Unopened secrets expire after 24 hours and are wiped from memory. If you sent one to the wrong person, the confirmation screen has an Erase it now button that revokes it before anyone can open it. Either way, nothing was ever written to disk.