Send a secret
For handing a password, API key, certificate, or any other short secret to a specific person. You create it once, they open it once, and then it's gone. Creating requires an InternalCars sign-in; the recipient needs nothing but the link.
Step by step
- Open Send a secret and sign in with your InternalCars account if you aren't already.
- Type the secret. You can also attach files — certificates, key files, configs — up to 5 MB total. Text, files, or both.
- Optionally set a passphrase. The recipient then needs it to decrypt, on top of having the link. Send it a different way than the link — the link over email, the passphrase over a call — so one leak isn't enough on its own.
- Pick how long the note lasts if nobody opens it: 5 minutes, 1 hour, 1 day, or 7 days. Choose the shortest that works.
- Hit Encrypt & create link. The encryption happens in your browser before anything is uploaded.
- Copy the share link and send it to the recipient.
The manage link
Along with the share link you get a manage link, shown only once. Keep it to yourself. If you sent the secret to the wrong person or just change your mind, open it and hit Destroy now to kill the note before anyone reads it. The manage link can only destroy — it can't read the note — so losing it is annoying, not dangerous.
Good habits
- Treat the share link like the secret itself — anyone holding the whole link can open the note (once).
- Never send the link and the passphrase in the same message or channel.
- Tell the recipient to copy what they need right away; the note is destroyed the moment they reveal it.
Lost the link?
We can't resend it — we never had the key, and the note may already be gone. Create a new one. Same if the wrong person opened it first: it's already destroyed, so make a new note and consider a passphrase sent separately.
Next: what the recipient sees, or how the encryption works.