RookSecret One-Time Secrets
Share passwords, tokens, and recovery codes through links that expire after one view or a time limit you choose.
Chat apps, ticket systems, and email threads often retain secrets forever. RookSecret lets you paste sensitive text once, generate a link, and let the recipient open it a single time (or until expiry) so the ciphertext is deleted from RookVPN servers afterward.
How burn-after-reading works
- Open rookvpn.com/secret.
- Enter the secret text (password, API key, seed phrase fragment, internal URL).
- Choose expiry: one view, multiple views with a cap, or time-based expiration.
- Copy the generated link and send it through your usual channel (Signal, corporate chat, SMS).
- When the recipient opens the link, they read the secret in the browser. After limits are reached, the server-side payload is removed.
Encryption protects data at rest on RookSecret. Treat links like physical keys — anyone with the URL can open the secret until it burns.
Request-a-secret workflow
RookSecret also supports request links: you ask someone else to fill in a secret (for example a vendor API key) without them emailing it in plain text. You share a request URL; they submit once; you retrieve from your side. Useful for onboarding contractors who are not on your password manager.
Operational practices
- Send the link and a separate out-of-band confirmation (phone call, existing signed chat) when stakes are high.
- Do not post RookSecret links in public tickets or forums.
- Prefer shorter expiries for high-risk credentials.
- Rotate any credential that might have been copied before you intended.
Comparison with RookFile
| Use case | RookSecret | RookFile |
|---|---|---|
| Short text / API key | Best fit | Overkill |
| Large files or folders | Not ideal | Session upload up to 1 GB |
| Collaborative editing | No | Shared session text + files |
| Default encryption | Server-side + link entropy | Optional E2EE sessions |
See RookFile encrypted sessions for file transfer architecture.
Related
- Client-side crypto tools — generate passwords locally with RookPass
- Remove EXIF metadata before sharing photos that include location data
Check the result
Create a one-view link with a dummy sentence, open it once, and reload. The second open must fail. If a chat app previewed the link, that preview was the view. Send a new link after the test, or the recipient gets an empty secret and assumes the tool is broken.
Do not put the secret text in the same message as the URL. Use RookPass when you still need to invent the password. Use RookFile when the payload is a file rather than a short secret.