Skip to content

Security

Secure Note Sharing

Secure Note Sharing

Write a note and get a link to share it. The note is encrypted in your browser with AES-256-GCM and travels inside the link; nothing is stored.

  • Free, no sign-up
  • Updated
  • Reviewed by Olgun Ozoktas
Runs in your browserNothing uploaded
0 of 4,000 characters

Share the password another way, not in the same message as the link.

The note is encrypted before the link is made.

How to share an encrypted note

  1. Write the note

    Type or paste the text into the Note box. It can be up to 4,000 characters, and the counter shows how many you have used.
  2. Add a password if you want one

    Leave the password empty and the link alone opens the note. Set one and the recipient also needs the password, which you should send another way, such as a phone call or a different app.
  3. Create the link

    Select Create link. Your browser encrypts the note and builds a link that contains it. Copy the link with the Copy link button.
  4. The recipient opens it

    When they open the link, this page shows Someone sent you a note. They select Reveal note (entering the password if there is one), and their browser decrypts it. The part after # is then removed from their address bar.

When it helps

Sending a password or API key

Put the credential in a password-protected note, send the link in one channel and the password in another. Someone who sees only one of the two cannot read it.

Wi-Fi details for a guest

Share the network name and password as a link instead of typing them into a group chat where they stay in plain text.

Short setup instructions

Send a few lines of configuration, a recovery code or a hand-over note that should not sit readable in an email thread.

Keeping the text out of the message itself

Anything that previews or indexes your messages sees a link rather than the note's text. It still sees the link, so for anything sensitive add a password.

Why share a note this way?

Pasting a password or an API key straight into chat or email leaves it readable in that thread for as long as the thread exists. This tool encrypts the note in your browser with AES-256-GCM and puts the encrypted note inside the link, after the # sign. Browsers do not send that part of a link to any server, so the note is never uploaded and nothing is stored. Add a password and the link alone is no longer enough to read it. The honest limit: because nothing is stored, a link cannot expire or delete itself after reading. It works for as long as someone has it.

Secure Note Sharing turns a short note into a link that contains the note, encrypted. Your browser encrypts the text with AES-256-GCM before the link is made. With no password, a random 256-bit key is generated and placed in the link after the # sign, next to the encrypted note, so anyone with the full link can read it. With a password, the key is derived from the password with PBKDF2-SHA-256 at 600,000 iterations and is not in the link at all, so the link alone is not enough. AES-GCM checks the data as it decrypts, so a wrong password or a single changed character makes the note fail to open instead of showing scrambled text.

Nothing is stored anywhere: not on a server and not in your browser's storage. That is why the link can be long, why the note has a 4,000-character limit, and why there is no expiry time and no burn-after-reading. The note exists for as long as the link does. Browsers do not include the part after # in the requests they send or in the Referer header, so the note is not sent to this site when the page loads. The page itself loads analytics and ads like every page on the site; they see the page address but not the part after #. When the recipient opens the note, the page removes the part after # from their address bar.

If you need to encrypt longer text or keep it as a file, the Text Encryption tool encrypts text with a password without a length limit set by a link. For public-key encryption between two people who have exchanged keys, use the PGP Encryption Tool. To make a strong password for the note, use the Password Generator, and check one you already have with the Password Strength Checker.

How it compares

Many secret-sharing services store the encrypted note on their server and give you a link to it. That design is what allows a note to expire or be deleted after one view, and it means the note depends on the service keeping it. This tool takes the other approach: the encrypted note is inside the link, so nothing is stored, nothing needs to be deleted, and the link keeps working without any server holding your data. The cost is that a link cannot expire or burn after reading, and the note has to be short enough to fit in a link.

Compared with PGP, there are no key pairs to create or exchange; the link (and the password, if set) is the secret. That makes it quick for one-off sharing but gives none of PGP's identity checks. Compared with pasting text into chat or email, the text is not readable in the message, but whoever holds the link can read it, so use a password and a separate channel for anything that matters.

Tips

  • Use a password for anything sensitive, and send it through a different channel from the link.
  • Send the whole link. If a chat app cuts it short, the note will not open; send it as a file or in a different app.
  • The link cannot be revoked. Rotate a password or key you shared once it has been used, rather than relying on the link going away.
  • Anything that stores the link, such as a chat history or browser history on the sender's side, keeps a copy that can open the note.
  • Use a long, random password; the Password Generator can make one.

Frequently Asked Questions

How is the note encrypted?

In your browser, with AES-256-GCM. With no password, a random 256-bit key is generated and put in the link after the # sign together with the encrypted note. With a password, the key is derived from it with PBKDF2-SHA-256 at 600,000 iterations and a random salt, and the key is not in the link.

Is the note stored anywhere?

No. The encrypted note is inside the link itself. It is not uploaded to a server and not saved in your browser's storage. Browsers do not send the part of a link after # to any server, and it is not included in the Referer header.

Who can read the note?

Anyone who has the full link, if you set no password. If you set a password, they need both the full link and the password. This is zero-knowledge only in that precise sense: the site never receives the note or the key.

Can I delete a note?

No. Nothing is stored, so there is nothing to delete, and a link keeps working for as long as someone has it. To keep a note private, do not share the link, or share it only with a password and send the password another way.

Does the note expire or self-destruct after reading?

No. Expiry and burn-after-reading need a server that holds the note and can delete it, and this tool stores nothing. The recipient can open the note as many times as they like with the same link.

Why is a note link so long?

Because the whole encrypted note is inside it. The link grows with the note: the encryption adds a fixed overhead, and the encrypted bytes are written as base64url text, which takes about four characters for every three bytes. A link with no password also carries the 256-bit key.

How long can a note be?

Up to 4,000 characters. The limit keeps the link short enough to paste into chat apps and email. For longer text, use the Text Encryption tool and share the result another way.

What happens if the password is wrong or the link is cut short?

The note does not open. AES-GCM checks the data while decrypting, so a wrong password or any missing or changed character fails with an error instead of producing garbled text. Ask the sender to check the password or send the full link again.

Why does the part after # disappear when I open a note?

After the note is revealed, the page removes the fragment from the address bar so the key is not left sitting in the open tab. The note stays on screen until you hide it or leave the page. The link in the original message still works.

Is it safe to send the link and the password together?

No. Anyone who sees that one message could open the note. Send the link one way and the password another, for example the link by email and the password by phone.

Rate This Tool

0/1000

Get Weekly Tools

Suggest a Tool