Share once, secure always
Create encrypted, one-time links that self-destruct after they’re viewed.
Need to collect a secret from someone instead?
Create a secret request →For agents
OAuth MCP, server-blind secrets
Connect Cursor or any MCP client. LockLink issues tokens and stores ciphertext only — decrypt keys never reach our servers.
How LockL.ink protects your secret
Encrypted in the browser
Your secret is encrypted with AES-256-GCM via the Web Crypto API before any request is made.
The key never reaches our servers
The decryption key lives in the URL fragment after #, which browsers never transmit.
Destroyed after one view
Retrieving a link deletes the stored record. Anything unopened expires within 72 hours.
- AES-256-GCM
- Zero knowledge
- HTTPS only
- No plaintext logs
- 72h auto-expiry