Hush by Umikflow
← Back to Blog
Threat Modeling6 min read•By Umikflow•Last updated: September 26, 2026

What Is a One-Time Secret Link? How It Works and Its Limits

Understand the exact threat model of one-time secret links, how client-side encryption works, and what they cannot protect against.

What Is a One-Time Secret Link?

A one-time secret link is a securely generated URL designed to share sensitive information that is destroyed immediately after being viewed.

Unlike sending a password in an email or a chat application—where it sits in a database indefinitely—a one-time link ensures the data exists only for a brief moment in time.

How Client-Side Encryption Works

Hush uses client-side encryption to ensure we never see your secret.

  1. Your browser generates a random encryption key.
  2. The secret is encrypted on your device.
  3. The encrypted payload is sent to our servers.
  4. The decryption key is placed in the URL fragment (the part after the `#` symbol).

Browsers intentionally do not send URL fragments to servers. Therefore, we never receive the key to decrypt your data.

The Reveal Action and Consumption

Hush requires a deliberate "Reveal Secret" click. For a normal secret, this click triggers a server-enforced database transaction that returns the encrypted data exactly once, permanently erasing it from the live database in the same moment.

Passphrase Mode Differences

If you add a passphrase, the behavior changes slightly: - Incorrect passphrases can be retried. - Successful decryption by the official client triggers a best-effort finalization request to delete the secret. - This is not identical to the strict, server-enforced one-time mechanism of normal mode, as an attacker could theoretically block the finalization request.

What This Does NOT Protect Against

It is critical to understand the limitations of one-time links: - Screenshots and Copying: The intended recipient can always take a screenshot or copy the text. - Compromised Devices: Malware on the sender or receiver device can capture data before encryption or after decryption. - Interception: If someone else gains access to the link and opens it first, the intended recipient will be locked out, and the data may be compromised.

For more details, see our Security, Privacy, or How it Works pages, or read about securely sharing passwords.

Frequently Asked Questions

Does Hush know what my secret is?
No. The decryption key is held in the URL fragment, which is never sent to our servers. We only store the encrypted data.
Can someone open the link twice?
No. Normal secrets are permanently consumed and erased from the live database the moment the recipient clicks Reveal.

Need to share a secret securely?

Hush encrypts your data in the browser before sending it.

Create a Hush Secret