Pass API keys and tokens without leaving them in Slack
API keys and tokens end up pasted into chat, tickets and shared docs, where they linger. Send them as one-time encrypted links that self-destruct on view, with a record of who received each one.
Made for handing over secrets
A key that never lands in a channel, a ticket or a doc — and a record of exactly which developer opened it.
Out of Slack, tickets and docs
Send an API key or token as a one-time encrypted link that's destroyed on first view — not pasted into a channel or a ticket where it's searchable later.
Send the config file with it
Attach a .env, certificate or config file alongside the key — scanned for malware, encrypted at rest, and deleted on the same view-or-expiry rules.
Automate key handovers
Create secrets and requests from your own tooling via the API, and get signed webhooks when a key is viewed — so provisioning can be scripted and logged.
Know exactly who received a key
The audit trail records which developer or contractor opened each key and when — metadata only, never the key itself — for your security records.
Revoke a link, then rotate
Sent to the wrong person? Revoke the link before it's opened. Combined with rotating the key, a mistaken send is a non-event.
Expiry and one-time by default
Keys self-destruct on first view or after a deadline you set, so a token can't sit in an inbox waiting to be found.
Questions we hear
Why not just send the key over Slack?
Chat keeps the key in message history, backups and search indefinitely. A one-time link is destroyed on first view and logs who opened it, so the key isn't left lying in a channel.
Can I send a key and its config file together?
Yes. Attach the config or certificate file to the secret on the Business plan — it's malware-scanned, encrypted at rest, and hard-deleted on view or expiry, just like the key.
Can I create these links from my own scripts?
Yes. The API creates secrets and requests programmatically, and outbound HMAC-signed webhooks tell your systems when a key has been viewed or a request fulfilled.
What if I send a key to the wrong person?
Revoke the link before it's opened, then rotate the key. Because the link is one-time and audited, you can see whether it was viewed before you revoked it.
Explore more ways to use SecretWolf
Keys are one kind of secret. The same links carry the rest.
Or see them all: All use cases.
Stop pasting keys into Slack
Free to start. Attachments, webhooks and the API come with Business.
Start free