How to share a password without leaving it behind.
Passwords pasted directly into email, text messages, tickets, and chat can remain in synchronized histories and backups. A one-time encrypted link limits how long a retrievable copy exists.
A safer five-step workflow
- Confirm the recipient and the channel you intend to use.
- Create the password—or generate a new one—on the sending device.
- Create a VanishKey link. Encryption happens before upload.
- Send the complete link. If you add a passphrase, send it separately.
- Have the recipient use it promptly, then rotate temporary credentials.
Why not paste the password directly?
A direct message can be copied into inboxes, notification previews, exports, backups, and logging systems. A VanishKey message is encrypted on the sender's device, can be retrieved once, and expires unopened after one hour. The delivery channel still carries a capability link, so protect it as you would the password itself.
When a password manager is better
VanishKey is for ad-hoc delivery—not ongoing shared access. Use a managed password-manager vault when a team needs durable access, revocation, role controls, recovery, or an audit trail. Avoid sharing a credential at all when your system can issue a short-lived invite, delegated account, or scoped token instead.
Important boundary
Anyone who obtains the complete link can attempt the one-time reveal. An optional passphrase reduces that single-channel risk, but compromised devices, malicious browser extensions, screen capture, and an already exposed delivery account remain outside VanishKey's control.
Share the secret—not a permanent copy.
No account. One reveal. One-hour maximum lifetime.