Passwords and secrets

Share a password with a link that works once

Stop leaving logins in chat history. Send the password as a one-time link, send the username somewhere else, and delete the link early if plans change.

Self-destructs
views
● 1 view then gone AES-256 at rest 0 / 32,768 bytes

The safe way to send a password with TxtVanish

  1. Paste only the password. Leave out the username, the email address and the website. On its own, a password is much less useful to anyone who stumbles across it.
  2. Keep it at 1 view. The link opens once, after the recipient presses “Show message”. Chat-app previews can’t use it up.
  3. Add a link password if it might travel. Switch on Password and choose something you can say out loud. Tell it to the recipient by phone or in person, not in the same chat as the link.
  4. Send the rest separately. The link goes one way, and the username and website go another, such as a different app or a call.
  5. Watch your sender link. When it shows the message as opened, you know it arrived. If it was opened and the recipient says it wasn’t them, change the password immediately.

Why not just paste it into the chat?

Because the password outlives the reason you sent it. Email stays in your Sent folder and their inbox until someone deletes it. Microsoft Teams keeps chats indefinitely by default unless an administrator sets a retention policy. Slack’s paid plans keep messages for the life of the workspace unless someone changes that. WhatsApp copies land in phone backups. A year later, the password is still sitting there, searchable by anyone who gets into either account.

We went through each of these, using the companies’ own documentation, in where does a password go after you send it.

Rule of thumb Nothing that could log someone in should survive in a chat history. If it has to be sent, send it in a form that disappears.

Sharing with more than one person

For a small team, choose Custom → After N views and set it to the number of people who need it. Each person presses “Show message” once. For a group you can’t count, a short time limit such as 1 hour plus a link password works better than a view limit.

If the same people need a password again and again, a shared vault in a password manager is the better tool. TxtVanish is for the one-off handover: a contractor’s first login, a Wi-Fi password, a code your colleague needs today.

API keys, tokens and recovery codes

Use the Code tab for API keys, .env files and config, so spacing and line breaks arrive exactly as you sent them, and the recipient gets a one-click copy button. Two-factor recovery codes work fine as plain text.

After a contractor or a colleague has finished with a key, rotate it. A one-time link keeps the key out of chat history, but it can’t stop someone from keeping a copy.

After it’s been shared

Questions

Should I send the username and password in the same message?

No. Put only the password in the TxtVanish link and send the username, email or website by another channel, such as a call or a separate chat. Someone who finds one half can’t log in with it.

What does adding a password to the link do?

The recipient has to type that password before the message opens. Tell them the link password by phone or in person, so a forwarded or intercepted link alone isn’t enough.

What should I do if the link shows as opened but the recipient says they didn’t open it?

Assume someone else saw it and change the password straight away. Your sender link shows exactly when the message was first opened.

Can I share API keys and two-factor recovery codes the same way?

Yes. Use the Code tab for keys and config so formatting stays intact, and plain text for recovery codes. Ask the recipient to move them into a password manager right away.