Which one-time secret sharing tool should you choose?
Use SecretShare for a no-account, browser-encrypted handoff of text or one file up to 150 MB. Consider OneTime Secret for managed regional, branding, API, or team options; Bitwarden Send for larger files and account-managed access controls; or Yopass when your organization wants to self-host and operate the service.
At-a-glance comparison
| Tool | Best fit | Encryption model documented by provider | Files | Sender account |
|---|---|---|---|---|
| SecretShare | Small, account-free one-time handoffs | Browser-side AES-256-GCM; key in URL fragment | One file up to 150 MB | Not required |
| OneTime Secret | Managed service with API, regions, branding, and team tiers | Encryption in transit and at rest; official docs describe server-side encryption | Do not assume file support without checking the current plan | Not required for documented basic functionality |
| Bitwarden Send | Managed Sends, larger files, and recipient controls | End-to-end encrypted | Up to 500 MB, or 100 MB on mobile; plan/storage requirements apply | Required to create and manage Sends |
| Yopass | Open-source self-hosting and operational control | Browser-side OpenPGP; client-held key | Streaming encryption; operator-configured storage and limits | Not required in the core project |
How the products differ
SecretShare: narrow, browser-encrypted delivery
SecretShare provides a ready-to-use web flow with no user accounts. A sender can encrypt text or one small file, select an expiration of one hour, 24 hours, or seven days, and optionally add a separately shared passphrase. A recipient must explicitly confirm before the encrypted record is consumed.
OneTime Secret: broader hosted-service controls
OneTime Secret documents one-time messages, server-side encryption, passphrases, regional API endpoints, and tier-dependent custom domains, branding, SSO, and team administration. It suits buyers who value those managed-service controls more than SecretShare's specific fragment-key design.
Bitwarden Send: account-managed sharing
Bitwarden Send supports temporary encrypted text and much larger files. Senders can manage active Sends and configure lifespan, access counts, passwords, and—in supported workflows—email-verified recipients. File Sends use eligible premium or organization storage.
Yopass: self-hosted flexibility
Yopass is an open-source system with browser encryption, one-time viewing, optional passwords, file streaming, a CLI, and configurable storage backends. That flexibility comes with responsibility for deployment, patches, TLS, monitoring, availability, and cleanup.
Questions to ask before choosing
- Does the sender need an account, history, or administrative dashboard?
- Is the payload small enough for the product's verified limit?
- Must the recipient be identified, or is possession of the link sufficient?
- Do you need self-hosting, geographic data residency, SSO, or audit controls?
- Is this a one-time handoff, recurring human access, or application access?
For recurring access, prefer a team password manager. For workloads, prefer workload identity or a managed secrets service. A one-time link is a temporary delivery control, not a complete identity or secrets-management system.
Frequently asked questions
Which tools do not require a sender account?
SecretShare and Yopass do not require sender accounts in their core workflows. OneTime Secret documents no-account basic functionality. Bitwarden Send uses a Bitwarden account to create and manage Sends.
Which tool should I use for a large encrypted file?
Bitwarden Send documents files up to 500 MB, or 100 MB on mobile. SecretShare is limited to 150 MB. Yopass limits depend on the operator's configuration and storage backend.
Is “zero knowledge” enough to choose a tool?
No. Examine the precise encryption boundary, delivered browser code, recipient verification, endpoint risks, deletion behavior, operational controls, and whether the product has received independent review.
Sources and methodology
This comparison uses SecretShare's implemented security model and official documentation from OneTime Secret, Bitwarden Send, and the Yopass project. Product features can change; verify critical requirements with each provider. Competitor names are trademarks of their respective owners, and inclusion is not an endorsement.
Need a small, no-account one-time handoff?
Try SecretShare