Create
Your browser encrypts the secret before upload. The decryption key stays in the complete link—not in VanishKey storage.

Your browser encrypts the secret before upload. The decryption key stays in the complete link—not in VanishKey storage.
Send the link however you prefer. Its reveal capability stays after the #, beyond ordinary link previews.
Opening the complete link retrieves and permanently deletes the encrypted copy, then decrypts it on the recipient's device. Unopened links expire after one hour.
Boring cryptography done carefully—not a hand-wavy "military-grade" label.
AES-256-GCM + HKDF Domain-separated AEADPBKDF2 600k Optional passphrase256 + 256 Split capabilities# so ordinary HTTP requests and link previews never send it.ATOMIC Single-use retrievalSecurity boundary: anyone holding the complete URL (and passphrase, if set) can reveal the secret. Direct email intentionally passes that URL through VanishKey and Mailgun. Keys never live in the ciphertext store.
Give people, AI agents, and automated workflows the same private way to share credentials without placing them in chat or logs. Our lightweight client encrypts locally and returns a single-use link.
Local encryption • no readable secret storage • one-time access