shouldiuse.io

Categories

VERDICT

Should I use Onetimesecret?

Secure one-time message sharing with self-destructing links - onetimesecret.com

Worth it. Buy it for free, one-off password sharing — sysadmins and IT teams widely rely on it for that exact job. Skip it if you need zero-knowledge encryption, audit trails, or a real password vault.

Confidence

Medium. Based on 30+ public web sources: Reddit threads, official docs, GitHub, and security disclosures. No numeric review ratings found.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support qualityNo support evidence in sources
  • Security posture

Pricing

$0

Free

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Identity PlusNot disclosed in sources
Team PlusNot disclosed in sources

Best for

  • Sysadmins onboarding new users
  • One-off credential handoffs to outsiders
  • MSPs and IT teams
  • Self-hosters wanting open source

Not for

  • Teams needing a password manager or vault
  • Zero-knowledge purists — secrets are encrypted server-side
  • Compliance-driven orgs needing audit trails
  • Client-facing teams with non-technical recipients

Gotchas - check before you buy

high

Phishing clones of exist — always verify the exact domain before pasting secrets.

medium

Not zero-knowledge per a competitor's analysis — encryption happens on their servers, not your browser.

low

Free tier limits secret lifetime and features; paid Identity Plus and Team Plus extend expiry options.

Pros and cons

Pros

  • Free for individuals and teams
  • Links self-destruct after viewing
  • Open source with official Docker images for self-hosting
  • Widely used and recommended by sysadmins
  • Custom domains let teams run a branded secret service

Cons

  • Competitor analysis claims server-side encryption, not zero-knowledge
  • Fraudulent clones of the site have been reported
  • High-severity vulnerability publicly disclosed by a researcher
  • Confusing for non-technical recipients
  • No vault features — ephemeral, single-use only

Sources & method

Analyzed 10/04/2026 - 12 sources - Active security program with disclosure channels; no known breaches, but two researcher disclosures surfaced publicly.

official x5review x5security x2
  • High-severity vulnerability responsibly disclosed, A researcher publicly disclosed a high-severity finding via a LinkedIn bug-bounty post; fix status unconfirmed in sources.
  • API key exposed in bootstrap payload, A security research post describes an API key exposed in a bootstrap payload.

Key stats

  • Value for money: 5/5

    Rating

  • $0

    Starting price

  • 12

    Sources

  • Analyzed

  • Value for money: 5/5. Core one-time links are free
  • Ease of use: 4/5. Simple flow; concept confuses some recipients
  • Feature depth: 3/5. Deliberately single-purpose: links, API, custom domains
  • Support quality. No support evidence in sources
  • Security posture: 3/5. Active program; high-severity bug disclosed
  • Yes Free tier Free for individuals and teams
  • 2 Paid plans Identity Plus and Team Plus
  • 2012 Online since Creator blog posts date to Jan 2012
  • Yes Self-hosting Official Docker image available

Pricing

Free

$0

  • Self-destructing secret links
  • Basic limits on lifetime and options

Identity Plus

Not disclosed

  • Extended secret controls
  • Custom domain support

Team Plus

Not disclosed

  • Team sharing features
  • Auto-expiring links

Security

Active security program with disclosure channels; no known breaches, but two researcher disclosures surfaced publicly.

  • High-severity vulnerability responsibly disclosedA researcher publicly disclosed a high-severity finding via a LinkedIn bug-bounty post; fix status unconfirmed in sources.⁸
  • API key exposed in bootstrap payloadA security research post describes an API key exposed in a bootstrap payload.

What users say

Sysadmins broadly recommend it for one-off password delivery; the recurring complaint is explaining one-time links to non-technical users.

“onetimesecret.com seems to be very popular in orgs”
Reddit, r/sysadmin
“Explaining a "One Time Secret" to users is infuriating...”
Reddit, r/sysadmin
“OneTimeSecret.com Password Only, no context.”
Reddit, r/sysadmin

Companies that use it

  • University of Adelaide12
Full analysis

Based on 30+ public web sources: Reddit threads, official docs, GitHub, and security disclosures. No numeric review ratings found.

Free, dead-simple one-time links for passwords. Great for IT handoffs; not a vault and not zero-knowledge.

Methodology

Based on 30+ public web sources: Reddit threads, official docs, GitHub, and security disclosures. No numeric review ratings found.

Sources

  1. review
  2. review
  3. review
  4. official
  5. Onetime Secret pricing docsdocs.onetimesecret.com
    official
  6. Onetime Secret homepageonetimesecret.com
    official
  7. security
  8. security
  9. review
  10. review
  11. official
  12. University of Adelaide custom instanceonetimesecret.adelaide.edu.au
    official

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.