/secret "staging DB password"

Stop pasting passwords in Slack.

Credentials in chat history are a breach waiting to be searched. Just Secrets swaps the paste for an encrypted link that works once — then burns.

# ops
/secret "staging DB password"
Just SecretsAPP
A one-time secret card in Slack: Encrypted, viewable once, with a Reveal the secret button

How it works

Three beats, zero residue

1

Type the secret

/secret "staging DB password"

Type /secret with the value, or bare /secret to open the form and set a passphrase or expiry window.

2

Just Secrets posts a burn link

Instead of the value, the channel or DM gets an encrypted, one-time card. The secret itself never touches chat history.

3

Read once, then it’s ash

The recipient reveals it once. The link refuses every later visit — and expires on its own if never opened.

Features

The product, not a mockup

Every image below is Just Secrets running in a real Slack workspace — captured, not composed.

Create

One form, three knobs

The secret, an optional passphrase the recipient must enter, and an expiry window. Defaults are safe; every knob is yours to turn.

# ops
The Share a secret form in Slack with a secret field, optional passphrase, and expiry dropdowns

Burn after reading

Opened once, then it’s ash

After the first reveal, the ciphertext is deleted and the card says so. Refreshes, forwards, and curious teammates get the burned notice — nothing else.

# ops
Just SecretsAPP
A burned secret card in Slack showing a flame icon and Opened 1 time

Encrypted at rest

Fernet encryption before the value ever hits storage. A leaked database backup yields ciphertext, not credentials.

Never in chat history

Slack stores the link, not the secret. Search the workspace all you like — the value isn’t there to find.

Minimal scopes

No message-history read, no admin rights. Secret values never appear in logs, ours or Slack’s.

Free. Unlimited. Self-hosted.

FreeEvery feature. No secret quotas.

UnlimitedShare as often as the job needs.

Self-hostedSecrets never leave your server.

Add to Slack

Privacy policy·Terms of service

FAQ

Asked and answered

Where do secrets actually live?

On your own server, encrypted at rest. Just Secrets is self-hosted — nothing transits a third-party SaaS, and nothing survives on ours because there is no ours.

What does “burned” mean?

The link works exactly once. After the first reveal the stored ciphertext is deleted, and every later visit gets the burned notice — including a refresh by the original reader.

Can I set an expiry?

Yes. Unopened secrets expire on the window you choose and return nothing afterwards. You can also destroy a secret manually before anyone opens it.

Does it read our messages?

No. Just Secrets runs on minimal Slack scopes and never reads channel history. Secret values never appear in logs.

How do I install?

Click "Add to Slack", review and grant the requested scopes, then invite the bot to the channels where you want to share secrets with /invite @Just Secrets.

Is it really free?

Yes — unlimited secrets, every feature, no per-seat pricing. Self-hosted, so there’s nothing to meter.