RookSecret One-Time Secrets

Share passwords, tokens, and recovery codes through links that expire after one view or a time limit you choose.

Chat apps, ticket systems, and email threads often retain secrets forever. RookSecret lets you paste sensitive text once, generate a link, and let the recipient open it a single time (or until expiry) so the ciphertext is deleted from RookVPN servers afterward.

How burn-after-reading works

  1. Open rookvpn.com/secret.
  2. Enter the secret text (password, API key, seed phrase fragment, internal URL).
  3. Choose expiry: one view, multiple views with a cap, or time-based expiration.
  4. Copy the generated link and send it through your usual channel (Signal, corporate chat, SMS).
  5. When the recipient opens the link, they read the secret in the browser. After limits are reached, the server-side payload is removed.

Encryption protects data at rest on RookSecret. Treat links like physical keys — anyone with the URL can open the secret until it burns.

Request-a-secret workflow

RookSecret also supports request links: you ask someone else to fill in a secret (for example a vendor API key) without them emailing it in plain text. You share a request URL; they submit once; you retrieve from your side. Useful for onboarding contractors who are not on your password manager.

Operational practices

Comparison with RookFile

Use caseRookSecretRookFile
Short text / API keyBest fitOverkill
Large files or foldersNot idealSession upload up to 1 GB
Collaborative editingNoShared session text + files
Default encryptionServer-side + link entropyOptional E2EE sessions

See RookFile encrypted sessions for file transfer architecture.

Check the result

Create a one-view link with a dummy sentence, open it once, and reload. The second open must fail. If a chat app previewed the link, that preview was the view. Send a new link after the test, or the recipient gets an empty secret and assumes the tool is broken.

Do not put the secret text in the same message as the URL. Use RookPass when you still need to invent the password. Use RookFile when the payload is a file rather than a short secret.