Ross ROSS = Recommend OSS · open-source software intelligence for agents

onetimesecret/onetimesecret

Keep passwords and other sensitive information out of your chat logs and inboxes. observed · 2026-08-28

github.com/onetimesecret/onetimesecret · homepage · Ruby · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

95/100

  • Activity 99
  • Release rhythm 87
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 3.5
  • age_days: 4963
  • days_rel: 7
  • days_push: 7
  • n_releases_24m: 75

Full methodology

Adoption not part of the score

2912 stars · 451 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A self-hostable web service for sharing sensitive information like passwords via single-use, self-destructing links. Written in Ruby with Redis (and optionally PostgreSQL/RabbitMQ), it ensures only the intended recipient views the secret once before it is destroyed.

Use cases

  • share a password with a coworker without it lingering in chat logs
  • send api keys or credentials over email securely
  • self-host a one-time secret sharing service
  • give a client a temporary credential link that self-destructs
  • avoid leaving sensitive info in inboxes and messaging apps

When to choose

  • you need to transmit credentials or sensitive text one-time without leaving copies
  • you want a self-hosted alternative to hosted secret-sharing services
  • you need MFA/WebAuthn-protected secret sharing with an API

When to avoid

  • you need to share large files rather than short text secrets
  • you need recipients to access the secret multiple times
  • you want zero infrastructure and prefer a fully managed hosted tool

Facets

service · maturity active

security secrets-management self-hosted http-server security privacy self-hosted web-development self-hosted one-time-links secret-sharing self-destructing-messages ruby disposable-secrets docker web-server linux macos

2 sources

Member repositories

RepositoryRoleHealth v2
onetimesecret/onetimesecretmain95

For agents

markdown · JSON · MCP: product_card(name="onetimesecret/onetimesecret")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem