Secreta
One-time secret links encrypted in your browser; the key stays in the link, never on your server.
For teams that share passwords, keys and logins. Often replaces 1Password, Onetime Secret or Bitwarden.
Single license $79 · Extended license $179 · paid once, yours for good
What it does
AES-256-GCM with a key made in your browser. The key travels in the link and never reaches the server.
Destroy a secret after one view, or set a view limit. Links expire after anything from an hour to 30 days, or never.
Send a client a request link. What they type is encrypted to a key only you hold, and they need no account.
Send the same secret to several people, each with their own link and key. See whose has been opened. The names stay your note.
With a passphrase set, the link alone opens nothing. Someone needs both the link and the phrase.
A certificate, key file or .env goes with the secret, encrypted with the same key. Photos lose their location data first. Off until you switch it on.
Require sign-in to create secrets, then see who made and viewed what. Metadata only, never contents.
Set the longest life and the most views a link can have. The form, the API and agents all keep to it.
Show any new link as a QR code, drawn in your browser. The code carries the whole link, key included.
One file, secreta-send, encrypts on your own machine and prints the link.
Save the requests you send again and again. Each use still makes its own key pair.
Connect your own agent over MCP and the API. It can create a link but never open one: reading a secret destroys it.
Also: single sign-on, two-factor sign-in, roles, webhooks, backups and an installable phone app.
What Secreta deliberately doesn’t do.
- Files up to 5 MB by default (25 at most), encrypted like the text; not previewed and not in the database backup.
- HTTPS is required in production — the encryption happens in the browser, and browsers only expose Web Crypto on a secure origin.
- Opening a link spends a view even if a passphrase attempt is wrong: the server cannot tell whether decryption succeeded — recipients are warned before revealing.
- A lost passphrase cannot be recovered. There is no reset, because the key never reached this server.
- Secreta sends no email at all: invitations and share links are handed over, never posted.
- Free tools such as PrivateBin cover one-off sharing; Secreta adds team accounts, sharing ceilings, an audit trail, SSO and an API on a server you already run.
- Collecting credentials from clients? Request links do it without email and without an account on their side.
What renting costs instead
9 months of 1Password (secure sharing) costs what Secreta costs once.
Read Sep 3, 2026 · source3 months of Onetime Secret costs what Secreta costs once.
Read Sep 7, 2026 · source48 months of Bitwarden (Send feature) costs what Secreta costs once.
Read Sep 3, 2026 · sourceThe full comparison: every rival, what each does better, and who should stay with them →
Replacing one of these? 1Password (secure sharing) alternative · Onetime Secret alternative · Bitwarden (Send feature) alternative
Release history
For Secreta, 4.1 makes two changes that every app gets. What’s new in 4.1 →
For Secreta, 4.0 means updates from inside the app: the Updates page checks for a new release with your license key, verifies Ownware's signature, takes a backup and… What’s new in 4.0 →
3.3 lets the same secret go to several people, each with their own link and its own key, so you can see whose has been opened. What’s new in 3.3 →
3.2 let secrets travel both ways: send a client a request link, and what they type is encrypted in their browser to a key only you hold.
Secreta 3.1 moved team management into the app: invite, deactivate and reactivate members, with yourself and the last admin protected, plus a change-password route…
Sharing gets ceilings, not suggestions: the longest life any secret may have, the most views it may allow, optionally a passphrase above a view count — applied…
The owner layer every Ownware app carries.
What’s in the zip
The tree as the zip ships it — the working leftovers the packager deletes are not listed
- .htaccess
- API.md
- Dockerfile
- LICENSE.txt
- QUICKSTART.txt
- README.md
- assets/
- bin/
- config.sample.php
- controllers/
- deploy/
- index.php
- install/
- manifest.json
- offline.html
- router.php
- src/
- sw.js
- tests/
- views/
src/Secret.php: a real module, the first 24 of 264 lines
Chosen as the largest module in src/ that is not one of the shared cores — this product's own logic, not a file every product carries.
<?php
/**
* Secret.php — Secreta's server-side domain core.
*
* ZERO-KNOWLEDGE CONTRACT
* -----------------------
* The real confidentiality of a secret comes from a 256-bit AES-GCM key that is generated
* IN THE RECIPIENT-FACING BROWSER and travels only in the URL fragment (after '#'), which
* browsers never transmit to the server. The server therefore CANNOT decrypt a secret — it
* only ever handles ciphertext.
*
* As defense-in-depth, the server ALSO encrypts the stored ciphertext at rest with an
* install-local key (config `secret`). That protects a stolen database file, but is NOT the
* source of confidentiality — the browser key the server never sees is.
*
* Every method here is pure (no DB, no network, no globals) except where noted, so the test
* suite can exercise the whole crypto contract offline. The PHP AES-GCM helpers below use
* exactly the same primitive as the browser (AES-256-GCM, ciphertext ‖ 16-byte tag), so a
* blob produced by one side decrypts on the other.
*/
declare(strict_types=1);
final class Secret
{Runs on: Two-minute web installer; PHP 8.1+ with pdo and openssl, MySQL or SQLite, standard shared-hosting compatible; HTTPS required in production. Tested on PHP 8.3. Or run it in Docker: the Dockerfile is in the zip.
Technical owners can install it with one line and their license key: curl -fsSL https://ownware.io/install.sh | sh -s -- secreta <your license key>
Nothing is obfuscated or encoded; what you read is what runs. Manual · API · the test run
Which license do I need?
It comes down to how many installations you need. Running your own business on one site is the Single license. A second domain of your own, or sites you build or run for other people, is the Extended license.
- Install it on one domain or subdomain you own or operate
- Change the source however you like for that installation
- Run your own business on it commercially, client work included
- Re-download the current build any time from your buyer portal
- A second site, or an installation you hand to a client as theirs, needs the Extended license
- No reselling, redistributing or sublicensing the source
- Not for offering it to other people as a hosted service
- Everything the Single license grants
- Install it on as many domains as you own or operate — no cap on the number
- Up to ten client installations, one per client project, handed over or hosted for each client; for more, buy another Extended license
- White-label: remove or replace the product name and logo in the screens of client installations
- Still no reselling or redistributing the source itself
- Running it as a multi-tenant service others sign up for needs a SaaS agreement
Every download carries the full terms as LICENSE.txt. The complete wording is on the terms page.
After you buy
The app’s Updates page installs a new release with your license key, with the release’s signature checked and a backup taken first. Your download link always serves the current build. Download again any time from your order page or the buyer portal; there is no renewal fee.
Email support for installation and for defects in the code as delivered: a person reads and answers every message. It does not cover custom development or server administration. What support covers
Refunds are handled by Lemon Squeezy as merchant of record, case by case. EU consumers keep the statutory 14-day right until delivery starts. Refund terms
It keeps running: your server, the full PHP source, no license check that can fail. If no stable release is published for 365 days, the domain limit lifts; after three such years your copy becomes MIT-licensed. The terms have the exact wording: continuity.
Questions
Is zero-knowledge just a marketing word here?
What does the server actually store?
Do I need HTTPS?
Can I share files instead of text?
Can a lost passphrase be recovered?
Is there a per-user or monthly charge?
Does it log the recipient's IP address?
Can an AI agent fetch a secret for me?
What stops the recipient copying the secret once they have opened it?
How do I remove a team member?
Covered in these guides
More about Secreta
Self-hosted one-time secret links, encrypted in the browser. The key stays in the link and never reaches your server, so the server stores only ciphertext.
The problem it solves
Every team shares secrets: a database password, a Stripe key, a server login. It ends up pasted into Slack, email, or a ticket — where it sits forever, searchable, in a dozen inboxes and backups. The quick share becomes a permanent liability.
With a hosted tool you rely on the vendor's server. With Secreta, the server is yours and it holds only ciphertext. For credentials, that trust is the whole problem.
Every feature
- Team accounts managed in the app. Invite, deactivate and reactivate members from the Team page — with two refusals that cannot be waived: you cannot deactivate yourself, and you cannot deactivate the last active admin. Deactivation stops sign-in and touches no secret they created.
- Change your own password. Current password proven, 8+ characters, same-password reuse refused — and the route takes no user id at all, so no path exists to change anyone else's. The audit row records that it changed, never the value.
- Browser-side encryption. AES-256-GCM encryption happens in the browser with a key generated locally that never reaches the server.
- Burn after reading. Destroy a secret after one view, or set a custom view limit.
- Configurable expiry. Expire links after 1 hour, 6 hours, 1 day, 3 days, 7 days or 30 days, or never, unless your sharing policy sets a shorter ceiling.
- Passphrase: the link alone is not enough. With a passphrase set, the link alone is NOT enough: the data key is wrapped under PBKDF2-SHA-256 (150k iterations) of the link key plus the passphrase — an attacker needs both the link and the phrase.
- Team accounts and audit log. Require sign-in to create secrets, then review who made and viewed what — metadata only, never contents.
- Self-hosted, one-time purchase. Runs on PHP 8.1+ with MySQL or SQLite on standard shared hosting, with no subscription or per-secret fees.
- Installable mobile app (PWA). Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is not stored offline on the device; what you see is read live.
- Hand it across a desk. Show any new link as a QR code, drawn in your browser; the code carries the whole link, key included.
- Ask for a secret, not just send one. Send a client a request link; what they type is encrypted in their browser to a key only you hold, and you open it once. They need no account, and the server stores nothing it can read.
- Send a file, not just a password. A certificate, a key file or an .env goes with the secret, encrypted in your browser with the same key; photos lose their location data first. Off until you switch it on.
- Share from the terminal. One file, secreta-send, encrypts on your own machine and prints the link.
- One link per person. Send the same secret to several people and each gets their own link with its own key, so you can see whose has been opened. Names stay your note: the person opening a link never sees them.
- Updates from inside the app. The Updates page installs a new release with your license key: Ownware's signature is checked, a backup is taken first, and the app puts the previous version back by itself if the update is interrupted or the database step or start-up check of the new version fails. It never checks by itself.
- Backups by themselves. Automatic backups, an optional copy to S3-compatible storage you own, and a weekly check that the latest backup reads back. The Health page names anything that needs attention.
- Own It 4.0.1 — fixes and an up-to-date manual. For Secreta, 4.0.1 fixes an installer that had lost its styling, a rollback that a page opened during an update could stop and a command-line update that ended in an error after putting the previous version back. Its manual, FAQ and QUICKSTART now cover everything 4.0 added, including two Nginx rules that keep the data folder private. Your license covers it: press Check for updates on the Updates page, or download it from your order page.
- Own It 4.0.2 — the installer opens on every host. For Secreta, 4.0.2 fixes a fresh install on an Apache host: the one-page setup at /install/ looped back to itself and never opened, and now it opens. Your license covers it: press Check for updates on the Updates page, or download it from your order page.
Release notes in full
- Own It 4.1: client installations and your other tools. For Secreta, 4.1 makes two changes that every app gets. An Extended license bought from October 4, 2026 covers up to ten client installations, one per client project: hand each one over to the client or host it for them, with the client's logo and colors from the app's branding settings. The API reference now shows how to connect Secreta to Zapier, Make or n8n, using its own webhooks and API key. Your license covers the update: press Check for updates on the Updates page, or download it from your order page.
- Own It 4.0: it updates and backs itself up. For Secreta, 4.0 means updates from inside the app: the Updates page checks for a new release with your license key, verifies Ownware's signature, takes a backup and puts the previous version back by itself if the update is interrupted or the database step or start-up check of the new version fails. A new install can start with a sample business and remove it in one click; backups run by themselves, with an optional offsite copy and a weekly check that the latest one reads back; and the Health page says whether the install is looking after itself.
- Own It 3.3: one link per person. 3.3 lets the same secret go to several people, each with their own link and its own key, so you can see whose has been opened. The names stay your note: the person opening a link never sees them.
- Own It 3.2: secrets that travel both ways. 3.2 let secrets travel both ways: send a client a request link, and what they type is encrypted in their browser to a key only you hold. It also brought a file with the secret (off until you switch it on), sharing from the terminal with secreta-send, and templates for the requests you send again and again.
- Own It 3.1: team management in the app. Secreta 3.1 moved team management into the app: invite, deactivate and reactivate members, with yourself and the last admin protected, plus a change-password route that cannot reach anyone else's account. It still sends no email: invitations are one-time links you hand over.
- Own It 3.0: works for your AI, not just for you. Sharing gets ceilings, not suggestions: the longest life any secret may have, the most views it may allow, optionally a passphrase above a view count — applied identically to the form, the REST API and the MCP endpoint, because all three mint through one function. A request for never-expires is clamped, not excused.
- Own It 2.0: API, 2FA, backups, dark mode. The owner layer every Ownware app carries. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase.
Browse self-hosted: Compliance software · Accountancy & bookkeeping software · IT support & managed-service software