Share once, secure always

Create encrypted, one-time links that self-destruct after they’re viewed.

Credentials, API keys, or configuration. Encrypted in this browser before it is sent.

  • AES-256-GCM
  • Zero-knowledge
  • Burns on open
  • Expires 72h

Need to collect a secret from someone instead?

Create a secret request →

For agents

OAuth MCP, server-blind secrets

Connect Cursor or any MCP client. LockLink issues tokens and stores ciphertext only — decrypt keys never reach our servers.

MCP docs

How LockL.ink protects your secret

Encrypted in the browser

Your secret is encrypted with AES-256-GCM via the Web Crypto API before any request is made.

The key never reaches our servers

The decryption key lives in the URL fragment after #, which browsers never transmit.

Destroyed after one view

Retrieving a link deletes the stored record. Anything unopened expires within 72 hours.

  • AES-256-GCM
  • Zero knowledge
  • HTTPS only
  • No plaintext logs
  • 72h auto-expiry