
sup3rS3cretMes5age
Self-destructing one-time message service backed by HashiCorp Vault
568 stars 82 forks last commit first released MIT
Actively maintained
Last commit 25 Jul 2026.
sup3rS3cretMes5age is a small web service for sharing secrets via single-use, self-destructing messages. It uses HashiCorp Vault as the storage backend so messages are handled as secrets rather than being persisted in an app database.
Key Features
- One-time secret messages that self-destruct after being read
- HashiCorp Vault backend for storing and managing secrets
- Lightweight web UI built with vanilla JavaScript and self-hosted assets (no external CDNs)
- Supports HTTPS operation, including optional automatic certificate provisioning
- Container-friendly deployment with Docker and docker-compose
- CLI-oriented usage patterns for easy scripting and automation
Use Cases
- Sharing passwords, tokens, or recovery codes securely with teammates
- Sending short-lived secrets during incident response or support workflows
- Providing single-use credentials or links in automated scripts
Limitations and Considerations
- Requires operating and securing a HashiCorp Vault instance and providing appropriate tokens/policies
- If deployed without TLS end-to-end, secrets can be exposed in transit
sup3rS3cretMes5age is a practical tool for teams that need a simple, auditable way to share secrets once and avoid leaving sensitive data sitting in chat logs or email threads. It fits well in environments that already use Vault for secrets management.
Categories:
Tags:
Tech Stack:
Similar to sup3rS3cretMes5age

Hemmelig
Encrypted secret sharing with client-side encryption and self-destructing links
Share sensitive text or files securely using client-side encryption, expiring links, view limits, and optional password protection.


Bitwarden
Open-source password manager with zero-knowledge security and self-hosting.
Bitwarden is an open-source password manager that stores, shares, and autofills credentials with zero-knowledge encryption; supports cloud or self-hosted deployments.


Onetime Secret
Self-destructing service for sharing single-use encrypted secrets
Open-source web and API service to create encrypted, single-view links for sharing secrets with configurable expiry and optional passphrase protection.

OpenBao
Open source secrets management for keys, certificates, and tokens
OpenBao is an open source secrets management platform to securely store, generate, lease, and revoke secrets, certificates, and encryption keys with auditing and access control.

OTS
One-time secret sharing with client-side AES-256 encryption
Self-hosted one-time secret sharing service that encrypts secrets in the browser with AES-256 and deletes them after the first read.

Mybucks.online
Password-only, self-custodial browser cryptocurrency wallet
Browser-based self-custodial crypto wallet that derives a private key from a password and passcode using scrypt and keccak256; no registration or seed phrases.


