API keys in chat threads. Passwords in email. Files containing PII or financial data in e-mails. Each one sits there forever — forwarded, screenshotted, leaked. Konfidant replaces them with encrypted, one-time links that self-destruct after the first view — from the dashboard, or straight from your code with our REST API and SDKs.
File selected
Q4-Financial-Report.pdf
One-time encrypted download link — expires in 24h
https://download.konfidant.app/#t=hvs.CAESIOk…&k=…
The problem your team has right now: API keys sitting in Slack. Database credentials in email threads. PII in Jira tickets. Financial reports in e-mails. None of it expires. All of it can be forwarded, screenshotted, or exfiltrated. Every plaintext secret in a chat thread is a compliance incident — and the breach that triggers it won't warn you first.
How it works
Paste text or upload a file. It is encrypted with AES-256-GCM on your device — in the browser or in our SDKs — before upload. Plaintext never touches our servers.
Get a one-time access link. Send it over Slack, Microsoft Teams, email, or any channel. The link carries no readable data — only a single-use token and the decryption key, kept in the URL fragment that browsers never send to our servers.
The recipient opens it once. The token is consumed, the ciphertext is deleted, and the link is burned. No copies on our servers. No history. No exposure.
Developer API
Everything you can share in the dashboard, you can share over a REST API. Encrypt a secret or a file in your backend, CI pipeline, or internal tools and get back a one-time link in a single call. Official SDKs for Node.js, Python, Go, and Ruby encrypt locally — Konfidant only ever receives ciphertext.
curl -X POST https://www.konfidant.app/api/v1/texts \
-H "Authorization: Bearer $KONFIDANT_API_KEY" \
-H "Content-Type: application/json" \
-d '{"ciphertext": "<base64 KNF1 ciphertext>", "ttl_hours": 24}'// SDKs append &k=<key> locally to build the share link
{
"download_url": "https://download.konfidant.app/#t=hvs.CAES...",
"text_id": "9140b841-2c7e-4f0a-9d1b-6a3e8f2c4d10",
"expires_at": "2026-10-03T12:00:00Z",
"verified_burn": true
}Endpoints
Share client-encrypted text, get a one-time link
Get an upload URL for an encrypted file
Finish the upload, get a one-time link
List your organization’s shares
Premium and Enterprise include API access for scripts and CI/CD. Integrating Konfidant into your product? Add an API plan from $29/month.
Hand deploy credentials to an on-call engineer as a link that burns after one view, instead of printing them in build logs.
Send new hires their first passwords and VPN configs from your provisioning scripts. Nothing stays in their inbox.
Deliver API keys, recovery codes, or signed contracts to your own customers. Serve the links from your own domain.
Features
Whether you're in legal, infosec, DevOps, or HR — Konfidant gives you the controls to share securely without changing your workflow.
Content is permanently deleted after the first view. The access token is single-use — subsequent requests return 410 Gone.
A random 256-bit key is generated on your device for every share. It travels only in the link's URL fragment — Konfidant never receives it.
Set expiry from 1 hour up to 30 days, depending on your plan. Even if the link is never opened, the share expires and the data is deleted.
Our application, database and text storage run in Germany. On paid plans, choose EU or US storage for your files; the Free plan stores files in the US.
Serve share links from your own domain — share.yourcompany.com — with automatic SSL via Cloudflare.
For compliance-critical teams: audit logs record who on your team shared what and when. Verified burn records when each share was opened and confirms it was destroyed.
Security architecture
Konfidant is architected so that we never hold your plaintext data or your keys. Encryption happens on your device before upload, and the key lives only in the link's URL fragment. Decryption happens in the recipient's browser — and only once. Not even Konfidant can read what you shared.
File selected
Key generated on device
Encrypted on your device
random 256-bit key + AES-256-GCM
Ciphertext uploaded
ciphertext only
Token issued
single-use, expiring
Link ready
#t=token&k=key
Pricing
Start free. Scale with your team.
Compare plans
All plans include AES-256-GCM encryption and burn-on-read.
Core Security
File & Message Sharing
Access Control
Infrastructure
Team & Compliance
Developer API & Support
Set up in 60 seconds. No credit card required. Your next credential goes through Konfidant — not chat.
Create your free accountBuilding an integration? Read the API docs