Create link
Features About How it works Security Pricing News
v3.0 live — zero-knowledge • end-to-end encrypted • SOC2

SHARE
ONLY ONCE.
VANISH FOREVER.

once.io is the burn-after-reading internet. Passwords, files, API keys, love letters — create a link that self-destructs after one view. No inbox clutter. No leaks. No second chances.

ONCE.IO/APP
🔒 prod-db-password.txt
👁 1 view remaining⏳ expires in 04:59
🔥 VIEWED → BURNED → GONE
AES-256Zero-knowledgeNo signupAPI + CLI
0links burned
0% leak-free rate
Team sharing secrets securely with once.io
Trusted by 40k+ teams
Encrypted data center and privacy
Zero-knowledge architecture

Built for developers • lawyers • founders • journalists • humans

FintechDevOpsHealthcareLegalCryptoJournalismHR & HiringGaming
Features — why once

BUILT TO DISAPPEAR BEAUTIFULLY

Everything you share should have an expiry date. once.io gives every secret a fuse — one view, one hour, one day — then cryptographically shredded.

01 / SECRETSOne-time password sharing

One-time secrets

Paste passwords, tokens, seed phrases, API keys. Get a link that dies after opening. No forward, no screenshot rescue — just gone.

02 / FILESEphemeral file sharing

Burning files up to 5GB

Contracts, scans, videos, dumps. Client-side encrypted before upload. Download once, server wipes instantly with proof log.

03 / APIDeveloper API for ephemeral links

API + CLI for teams

Generate ephemeral links from CI/CD, Slack, Terraform. POST /v1/burn and rotate credentials without Slack leaks.

04 / VAULT

🔐 Passphrase armor

Add a second factor: recipient must know a passphrase. Brute-force protection + anti-bot view counting.

05 / PROOF

🧾 Burn receipts

Cryptographic receipt: who viewed, when, from where — without storing content. Perfect for audits and legal handoffs.

06 / CUSTOM

⚡ Custom domains

Share via go.yourcompany.link with your logo, expiry policy, SSO and DLP rules. White-label trust.

About — our manifesto

THE INTERNET NEVER FORGETS. WE DO.

once.io was born in 2019 from a simple rage: screenshots of passwords in Slack, eternal Gmail attachments, “temporary” Drive links that live for 7 years. We asked — what if sharing defaulted to forgetting?

We are a remote-first crew of cryptographers, designers and ex-journalists across Lisbon, Berlin and Kyoto. We believe privacy isn’t a feature, it’s a default. Every line of once.io is built so that even we cannot read your data. Zero-knowledge, open crypto, minimal metadata, EU hosting, instant purge.

2019founded, bootstrapped
27 peopleno trackers, no ads
2019 →First burn-link. 10k secrets in week one. Hacker News frontpage.
2022 →Zero-knowledge rewrite. Client-side AES-GCM, audited by Cure53-style review.
2025 →4.8M burns, SOC 2 Type II, EU AI Act ready. Launch of once Enterprise Vault.
once.io team manifesto and privacy culture
4.8M+secrets burned and counting.
Zero breaches. Zero recoveries. By design.
How it works

PASTE. LINK. POOF.

No account needed for basics. Three steps, eleven seconds, zero footprint.

Step 1

✍️ Drop your secret

Type text, upload file, or pipe via CLI. Encrypted in your browser before it leaves.

Paste secret
Step 2

🔗 Get once-link

Set views = 1, timer, passphrase. Copy once.io/… link to share anywhere.

Get secure link
Step 3

👁 One view

Recipient opens once. Content decrypts locally. Countdown starts.

One view
Step 4

🔥 Burned

Keys shredded, blocks overwritten, receipt issued. Even we can’t restore.

Burned forever

For humans: no signup sharing

Send Wi-Fi passwords to Airbnb guests, medical docs to clinics, private photos that can’t be re-shared. Works on any phone, no app.

For machines: ephemeral DevOps

$ npm i -g once-cli
$ once burn .env --views 1 --ttl 1h
→ https://once.io/a8f3… # burned after CI pull

Use cases

WHO BURNS WITH ONCE?

Startup founders sharing credentials
Startups → onboard safely
Lawyers sharing contracts
Legal → client privilege
Journalists protecting sources
Press → protect sources
Security — trust nothing

ZERO-KNOWLEDGE OR IT DIDN’T HAPPEN

We can’t sell, leak or subpoena what we never had. Encryption happens on your device. Servers see only opaque blobs.

Security audit and encryption

🛡️ AES-256-GCM + X25519

Modern, audited primitives. Keys live in URL fragment (#) never sent to server.

🧬 Perfect forward burn

Each link = unique key. Memory zeroed, SSD blocks crypto-shredded, backups excluded by design.

📜 Compliance without creep

SOC 2 Type II, GDPR, HIPAA-ready flows, EU residency, DPA + burn receipts for auditors.

Pricing

PAY FOR FORGETTING

Free forever for one-offs. Pro for power burners. Enterprise for regulated amnesia.

Spark — Free

$0

For quick burns

  • 10 burns / month
  • Files up to 100MB
  • 1 view + 24h expiry
  • No account needed
Start free

🔥 Burner — Pro

$8/mo

For teams & freelancers

  • Unlimited burns
  • Files up to 5GB
  • Passphrase + custom TTL
  • Custom domain + receipts
  • API + Slack + CLI
Go pro

Vault — Enterprise

Custom

For banks, clinics, gov

  • SSO / SCIM, audit log
  • EU / US residency
  • DLP + retention policies
  • 99.99% SLA, dedicated HSM
Talk to us
Wall of love

4.9 ★ FROM PARANOIDS

★★★★★

“We killed passwords-in-Slack in one day. once-cli is now in every pipeline. Burn receipts saved our SOC2 audit.”

Maya K. — DevOps Lead
Fintech, 200 people
★★★★★

“I send client contracts via once.io. They feel VIP, I feel safe. The self-destruct animation? Chef’s kiss.”

Jonas R. — Attorney
Berlin law boutique
★★★★★

“Sources trust me more when I send a link that literally cannot be forwarded. Essential for investigative work.”

Amara O. — Journalist
Independent reporter
FAQ

QUESTIONS? BURN THEM.

Short answers. Long privacy.

FAQ about one-time links
No. Keys are in the URL hash we never receive. After burn, decryption is mathematically impossible — even for us.
TTL expires it automatically. You get a “expired unviewed” receipt and can re-issue in one click.
Content: never in plaintext. Metadata: minimal, 24h rolling logs, EU-only. No trackers, no ad pixels.
Yes. 10 burns/month, no card. We make money on Pro teams, not your data.
No tech can fully block OS screenshots, but we add view-once blur, watermarking, and forward-blocking to raise the bar.
Journal — fresh burns

LATEST DROPS

Product notes, encryption guides, privacy essays. Each story lives forever — unlike your secrets.

No stories yet

Our journalists are encrypting the first drop. Meanwhile — go burn your first link.

What is a once-link?

A URL that self-destructs after one view. Perfect for passwords, keys and private files.

Zero-knowledge 101

Why we can’t read your data even if we wanted to — and why that matters.

● READY TO FORGET?

CREATE YOUR FIRST BURN-LINK IN 11 SECONDS

No signup. No trace. Just paste, share, vanish. Join 40,000+ teams who stopped leaking in chat.

🔥 Burn something now Our manifesto
Free 10 burns/mo • AES-256 • EU hosting • Cancel anytime (we’ll forget you)