How to share a password or API key securely (without leaving it in chat)
How to send passwords, API keys, and .env files to a coworker, client, or AI agent without leaving them in chat. What to avoid and a ten-second checklist.
The Evergist team · · 4 min read
Short answer: send it through an end-to-end encrypted link that works once and expires soon, and send any extra password through a different channel. Don't paste it into chat, email, or a ticket. If you and the recipient share a password manager, share it there instead.
Someone needs a password, and you have it. The fastest option is to paste it into Slack, email, or a ticket. It's also the option that leaves the password sitting in a searchable archive for years, synced to every device, and copied into every backup and export.
Here's how to do it properly, and why each step matters.
What not to do
- Don't paste it into chat or email. Messages are kept indefinitely, indexed for search, and exposed in data exports, integrations, and compromised accounts. Deleting a message later rarely deletes every copy.
- Don't put it in a ticket, doc, or pull request. These get shared far more widely than you expect, and version history keeps the old value after you edit it out.
- Don't send the password and the username or URL together in one message. If that one message leaks, the attacker has everything.
- Don't let an AI agent echo a secret into its transcript. Agent conversations are logged and often shared. Have the agent send a link instead.
What to do instead
1. If you both use a password manager, share through it
1Password, Bitwarden, and similar tools can share an item with another member of your vault, encrypted end to end. If the recipient is on your team and in your password manager, this is the best option: the secret stays in a place built to hold it.
2. Otherwise, send a self-destructing encrypted link
For everyone else (a client, a contractor, a friend, an agent in another sandbox), use a one-time secret link. The good ones encrypt the text in your browser, put the key in the link, and delete the note after it's read.
With Evergist that looks like this:
- Paste the password into the editor on the homepage.
- Leave the view limit at 1 view so the link works once.
- Pick a short expiry, like 1 hour or 1 day.
- Send the link.
Once the recipient opens it, the note is deleted from the server. If someone finds the link later in a chat log, it leads nowhere.
3. Split the secret across two channels
For anything important, add a password to the note and send it through a different channel than the link. Send the link by email and the password by text message, or say it on a call. An attacker would need access to both channels to read the note.
In Evergist, choose Generate one for me under Password. The password is mixed into the encryption key itself, so the link alone can't decrypt anything, and after 10 wrong guesses the note deletes itself.
4. Rotate after sharing, when you can
If the credential is for a shared account or a service key, change it once the person no longer needs it, or give them their own credential in the first place. Sharing securely limits exposure. Rotation ends it.
Sharing from a terminal or an AI agent
Developers and agents can do the same thing without a browser:
# Share a .env file, readable once, gone in an hour
npx -y evergist create .env --views 1 --expires 1h
For agents, add the Evergist MCP server so they can call create_gist directly:
claude mcp add evergist -- npx -y evergist mcp
The encryption runs on the machine where the command runs, so the secret never reaches Evergist's servers in readable form. The agent guide covers Codex, Cursor, and other clients.
How to tell if a sharing tool is actually private
Plenty of "secure note" sites encrypt on their server, which means the operator can read your note if they want to or are made to. Before trusting one, check:
- Is the key in the link after the
#? That part of a URL never reaches the server. If the link is just an ID, the server holds the key. - Does the site load third-party scripts? Analytics and ad scripts on a page that handles secrets are a bad sign.
- Is the design documented? A trustworthy tool explains exactly what it stores and lets you verify it.
We compared seven popular tools against these questions in Private note sharing compared.
The ten-second checklist
- Not pasted into chat, email, or a ticket
- Sent as an encrypted link, or through a shared password manager
- One view, short expiry
- Password added and sent through a different channel, for anything important
- Credential rotated when it's no longer needed