Black Friday Our biggest deal of the year is coming soon Get notified →
Free tool · Password sharing

Share a password once. Then it's gone.

Someone has shared credentials with you

Send login details, API keys and other secrets without putting them in plain text in an email, Slack message or text. They're encrypted in your browser and the link self-destructs after it's read.

They were encrypted in the sender's browser and only this link can unlock them. Copy what you need now: if the link was set to burn after reading, it won't work again.

  1. Write itEnter the credentials. They're encrypted in your browser before anything is sent.
  2. Get a linkThe key lives in the link, after the #. Our server only ever stores encrypted data.
  3. It's destroyed after viewingOpened once, then deleted from our server. Links nobody opens expire on their own.

Credentials to share

Encrypted in your browser
After it's opened

Secure link created

Send this link to the recipient. They will be able to view the credentials once.

This link is the only way to access these credentials. The encryption key is embedded in the link. Without it, nobody can decrypt the data.

The credentials will be permanently destroyed after the first view.

Expires:

Decrypting credentials...

Decrypted successfully

These credentials have been permanently destroyed from our server.

Destroyed. This link will not work again.

Credentials unavailable

AES-256-GCM encryption. Credentials never reach our server in readable form.

  • Encrypted in your browser
  • The key never reaches our server
  • Burn after reading
  • Links expire in 1 hour to 7 days
How it works

Write it, send a link, and it's gone

  1. Write it

    Enter a username, password, URL or notes. Your browser makes a fresh AES-256 key and encrypts everything before it leaves your device.

  2. Get a link

    Our server stores the encrypted data and returns an ID. Your browser adds the ID and the key to the link, after the # sign.

  3. It's destroyed after viewing

    Your recipient's browser fetches the encrypted data and decrypts it with the key from the link. With burn after reading on, the server deletes it straight away.

What's in the link

Browsers never send the part of a link after the # to the server. That's where the key lives.

https://portal.premiervpn.net/share-password#note-id/encryption-key
The page

This page. It loads the code that encrypts and decrypts in your browser.

The note ID

Tells our server which encrypted blob to hand over. On its own it unlocks nothing.

The key

Decrypts the blob. It stays in the link and in the browsers that open it, never on our server.

Why use it

Why not just email the password?

Email is kept for years

A password sent by email sits in your Sent folder, the recipient's inbox, any email backups and possibly your company's archive. A secure link expires and self-destructs, so the password only exists for as long as the link does.

Slack and Teams are searchable

Messages in Slack, Teams or Discord are indexed and searchable by people in your workspace. A database password shared in a channel will turn up when someone searches "password" next year. A self-destructing link doesn't leave the password behind.

Zero knowledge

The encryption key never reaches our server. Even if our database were breached, attackers would find only encrypted data with no way to decrypt it. Compare that with your email provider, who can read every message in your account.

Common uses

  • Wi-Fi passwords for guests
  • Server logins for a contractor
  • A shared account for a colleague
  • API keys for a developer
  • 2FA recovery codes for family
More free tools

Other ways to stay private online

PremierVPN

Private by default, not just for passwords

PremierVPN encrypts your whole connection, keeps no activity logs and has UK-based support around the clock. Every plan comes with a 30-day money-back guarantee.

Questions

About secure password sharing

How does secure password sharing work?
Everything you enter is encrypted in your browser with AES-256-GCM before it is sent. Our server stores only the encrypted data. The key to unlock it is added to the link after the # sign, and browsers never send that part of a link to a server, so we never see it.
Can PremierVPN read what I share?
No. Your credentials never reach our server in readable form, and the key stays in the link. Without the link, the stored data is just encrypted noise, to us and to anyone else.
What happens after the link is opened?
With burn after reading switched on (the default), the credentials are permanently destroyed from our server as soon as they are viewed, and the link stops working. With it switched off, the link keeps working until it expires.
How long does a link last?
You choose: 1 hour, 24 hours or 7 days. After that the credentials are gone, whether or not anyone opened the link.
What if I lose the link?
It can't be recovered. The key only exists in the link, so nobody, including us, can decrypt the credentials without it. Just create a new link.
How should I send the link?
Treat the link like the password itself, because whoever opens it first sees the credentials. Burn after reading helps here: if your recipient finds the link has already been used, someone else may have seen it, so change the password.

Stay Ahead of Online Threats

Get VPN tips, security insights, and exclusive offers delivered straight to your inbox. No spam — just the essentials.

Unsubscribe at any time. We respect your privacy.

PremierVPN Support