Encrypted text that deletes itself.
Your text is locked in this browser before anything is sent. The key lives after the # in the link, a part browsers never send to a server.
Link ready.
your other devices
One link opens it. Scan the code or paste the link.
Anyone who sees this whole link can read the text.
someone else
Send the link and the key on different channels, so one leaked chat isn't enough.
Decrypting…
Fetching the encrypted text and unlocking it in this browser.
Decrypted on this device.
Paste the key to read this.
This link came without its key. Paste the key you got separately. It is used only in this browser.
404: nothing here anymore.
This snippet expired or never existed. Expired snippets are deleted from the server and can't be recovered, even with the key.
what leaves your browser
Each snippet gets a fresh random key and is encrypted here with AES-256-GCM. The server keeps the encrypted bytes until the time runs out, then deletes them.
| server gets | server never gets |
|---|---|
| encrypted text size and expiry your IP and request times | your text the key |
verify this page
A page can only be as honest as the server that sends it. This one is a single HTML file, built in public by GitHub Actions and signed on every release. Check that the copy you got is the published one:
$ curl -s https://text.numeri.xyz/ -o index.html $ gh attestation verify index.html --repo hmirin/trustless-txt
Rather not trust any host? Run your own copy: one HTML file and a small Worker.