ashnote.io · secure I/O for secrets
Share secrets that self‑destruct.
Stop pasting passwords, API keys and .env files into chats and email. AshNote turns them into end-to-end encrypted one-time links that burn after reading, and we couldn't peek even if we wanted to.
ashnote.io/d/…#key ← the key never leaves your browser
🔒 secrets shared securely
How it works
01
Encrypt in your browser
Paste a secret. It is encrypted with AES-256-GCM before it leaves your machine. Our servers only ever store ciphertext.
02
Share one link
The decryption key rides in the URL fragment, which browsers never send to any server. Send the link over any channel, even an insecure one.
03
It burns after reading
One read (or a time limit you choose) and the drop is hard-deleted. No archive, no trash bin, no way back, for anyone.
Built for teams that get audited
Credentials in Slack history are an ISO 27001 finding waiting to happen. The AshNote Team plan adds what auditors ask for:
💬 Slack & Microsoft Teams apps
/ashnote replaces pasted secrets with encrypted one-time links, right where your team works.
📋 Audit trail
Who shared, when it was read, when it burned: metadata only, content is never stored.
🇪🇺 EU-hosted & open source
German data centers, GDPR-clean by architecture, verifiable client-side crypto.
How AshNote compares
vs OneTimeSecret →
The veteran of one-time links: flat pricing, no chat apps.
vs Password Pusher →
Great CLI, but SSO only when you self-host.
vs Yopass →
Same crypto philosophy, as a license to run yourself.
Frequently asked questions
How do I share a password securely?
Paste it into AshNote. It is encrypted in your browser with AES-256 before anything leaves your machine, and you get a one-time link to share instead of the password itself. The link self-destructs after it is read.
Can AshNote read my secrets?
No. The decryption key travels only in the part of the link after the # symbol, which browsers never send to servers. Our servers store ciphertext they cannot decrypt. This is called a zero-knowledge architecture.
What happens after the link is opened?
The encrypted drop is deleted from our servers the moment the final read is consumed: not flagged as deleted, actually gone. Expired drops are purged automatically. A burned link is indistinguishable from one that never existed.
Can link previews in Slack, Teams or Outlook burn my one-time link?
No. Revealing a secret always requires an explicit click. Preview bots that fetch the URL never consume a read.
Is AshNote GDPR-compliant and where is it hosted?
AshNote runs on EU infrastructure in German data centers. Since secrets are encrypted client-side and self-destruct, there is no personal data for us to process from the content you share.
Do I need an account, and what does signing in add?
No account is needed to share a secret. Signing in with a free Google, Microsoft or GitHub account is optional and adds: revoking your own links (burn a drop instantly, even with reads left), larger files (2 MB) and longer expiry (30 days), a list of your active drops, and saved defaults. Login is free; the paid Team plan is separate.
What does AshNote cost?
Sharing self-destructing secrets is free, no account needed. The Team plan adds a compliance audit trail, Slack and Microsoft Teams apps, and SSO for your organization.