Help

Received a link, or sending one?

Pick your side. Nothing on this page needs your link or password.

Before you open it

What is this link?

Someone sent you a secret — a password, key or code — through SoloKeySplit. It is encrypted in their browser and can be opened once. To open it you need the link and a separate access password, which the sender should give you another way: by voice, in a different app, or from another device.

Is it safe to open?

Opening the page does not reveal or consume anything; only the correct password does. The secret is decrypted in your browser, and the server never sees it or the password. If you did not expect a secret from this person, check with them through a channel you already trust before entering anything.

I don't have the password.

Ask the sender. It was deliberately not sent together with the link, so look for it in a different chat or ask them to tell you by voice. The link does not expire because you are waiting — only at the time the sender chose.

If something went wrong

The page says:

The password is incorrect, or this secret is no longer available.

This one message covers every reason on purpose: a typo in the password, a secret that was already opened, or one that has expired. First retype the password carefully — letter case, keyboard layout, similar-looking characters. A wrong attempt consumes nothing. If it still fails, ask the sender to check their status link: it shows whether the secret was opened and when, and they can send you a new one.

It won't open on my phone.

Unlocking needs a lot of memory for a few seconds — that is what makes guessing the password slow for an attacker. Browsers built into messengers sometimes cannot provide it or close in the background. Open the link in Safari or Chrome, or on a computer. A failed attempt of this kind consumes nothing.

After you open it

Nothing helped?

Ask the sender to create a new secret. It takes a minute, and the old one expires on its own.

Creating a secret

How do I send a secret?

Paste the secret, set an access password or generate one, choose when it expires, and create the link. Then send the link in one channel — a messenger, for example — and the password in another: by voice or from a different device. Two apps on the same phone count as one channel if that phone is lost.

What password should I use?

At least 12 characters. The simplest option is the generated one. You can also agree on a password by voice before sending and type it into the form — then it never travels in writing at all.

How long does a secret live?

You choose from 10 minutes to 7 days. After that it is deleted even if nobody opened it. Pick the shortest time in which the recipient will realistically open it.

What can I send?

Text up to about 128 KB: passwords, API keys, tokens, recovery codes, short notes. Files are not supported. One link is for one person — create a separate secret for each recipient.

After you send it

What does the status link show?

"Waiting" — nobody has opened it yet. "Opened" — it was revealed, and the time is shown. "Expired" — it ran out without being opened, so nobody received it. "Destroyed" — you destroyed it before anyone opened it. The number of wrong password attempts is also shown. The status is kept for the secret's lifetime plus 24 h. Keep the status link to yourself.

Can I cancel a secret I already sent?

Yes, as long as nobody has opened it. Open your status link and choose "Destroy secret now". The link stops working at once, and the recipient sees the same "unavailable" message as for an expired secret.

The status shows wrong password attempts.

Often these are just typos by the recipient. Wrong attempts never unlock or delete the secret, and their number is limited. If the recipient did not make them, someone else has the link — consider sending a new secret.

I lost the link or the password. Can I get them back?

No. The server never has the password or the key half that lives in the link, so it cannot restore either. Create a new secret. If you still have the status link, destroy the old one there; otherwise it expires on its own.

How it is protected

What the server stores, how the encryption works and what the service does not protect against.

Read about security