Hemmelig logo

Hemmelig

Website

Encrypted secret sharing with client-side encryption and self-destructing links

1.2k stars 106 forks last commit first released

Actively maintained

Last commit 15 May 2026.

Hemmelig screenshot

Hemmelig is an encrypted secret-sharing service designed to keep sensitive information out of chat logs and email threads. It uses a zero-knowledge approach where encryption happens in the browser, and the server only stores encrypted data.

Key Features

  • Client-side AES-256-GCM encryption (zero-knowledge storage)
  • Self-destructing secrets with configurable expiration and view limits
  • Optional password protection for an additional security layer
  • IP restrictions to limit access to specific IP ranges
  • Encrypted file uploads for authenticated users
  • Rich text editor for formatting secrets
  • QR codes for easier sharing on mobile devices
  • Webhook notifications for secret viewed/burned events
  • REST API with OpenAPI specification, plus CLI for automation

Use Cases

  • Securely sharing one-time credentials, API keys, and recovery codes
  • Exchanging sensitive notes or documents with expiring access
  • Automating secret creation and sharing in CI/CD pipelines via CLI/API

Limitations and Considerations

  • The license is a modified MIT-style license that restricts offering the software as a competing hosted SaaS

Hemmelig is a practical alternative to sending secrets through persistent channels, combining strong client-side cryptography with expiration controls. It fits well for teams and individuals who need simple, auditable secret handoff workflows with optional automation.

Categories:

Tags:

Tech Stack:

Share:

Similar to Hemmelig

Onetime Secret logo

Onetime Secret

Self-destructing service for sharing single-use encrypted secrets

2.9k
451
Last commit

Open-source web and API service to create encrypted, single-view links for sharing secrets with configurable expiry and optional passphrase protection.

MITActively maintained
Alternative to:
Onetime Secret logo
Onetime Secret
+6
sup3rS3cretMes5age logo

sup3rS3cretMes5age

Self-destructing one-time message service backed by HashiCorp Vault

568
82
Last commit

Self-hosted one-time, self-destructing message service that stores secrets in HashiCorp Vault, with a lightweight web UI and optional TLS automation.

MITActively maintained
Alternative to:
Onetime Secret logo
Onetime Secret
+1

Yopass

Secure one-time secret sharing with client-side encryption

3.1k
438
Last commit

Open-source tool for sharing secrets and files via client-side OpenPGP encryption and one-time expiring links.

Apache-2.0Actively maintained
Alternative to:
Onetime Secret logo
Onetime Secret
+3
Bitwarden logo

Bitwarden

Open-source password manager with zero-knowledge security and self-hosting.

19.9k
1.7k
Last commit

Bitwarden is an open-source password manager that stores, shares, and autofills credentials with zero-knowledge encryption; supports cloud or self-hosted deployments.

Actively maintained
Alternative to:
1Password logo
1Password
+9
Send logo

Send

Encrypted file sharing with expiring links

Self-hostable encrypted file sharing service with expiring links, download limits, and optional password protection for secure, temporary transfers.

Activity unknown
Alternative to:
WeTransfer logo
WeTransfer
+8
OnionShare logo

OnionShare

Secure, anonymous file sharing and hosting over the Tor network

7.1k
711
Last commit

Open-source tool to share files, host websites, and chat privately over the Tor network; available as desktop GUI, CLI, and mobile apps.

Actively maintained
Alternative to:
Send Anywhere logo
Send Anywhere
+8