LinkPilot where you already work
Short links and one-time secret links from the browser, Slack, your automations and your editor. Every app uses your own LinkPilot account and plan; API access is on every plan, including Free.
Chrome extension
Shorten the current page or turn selected text into a one-time secret link from the toolbar. No tracking, no host access.
Installs from the same store page in Brave, Microsoft Edge, Opera, Vivaldi and other Chromium browsers.
Get it from the Chrome Web StoreSlack
/secret replies only to you with a link that opens once. /shorten gives you a short link. Send as secret link rescues a password someone already pasted.
One permission, commands. Each person connects their own API key once.
Add to SlackZapier
Create short links and secret links from any Zap, and trigger Zaps when new links or secrets appear. Secrets are encrypted inside the Zap before LinkPilot sees them.
The invite link adds the integration to your Zapier account. It is private until Zapier's review completes.
Join the private betaFirefox extension
The same extension, submitted to Firefox Add-ons.
Raycast
Create Secret Link and Shorten Link commands for Raycast on macOS and Windows. Submitted to the Raycast Store.
WordPress plugin
Short links and QR codes as blocks and a shortcode, and secret links encrypted in the editor's browser. Submitted to the WordPress plugin directory.
For developers
-
CLI
npm i -g linkpilot -
SDK
npm i @uselinkpilot/sdk -
MCP server
@uselinkpilot/mcp for Claude, Cursor and other assistants
All of them sit on the same REST API. Read the API documentation
What stays private, and where
In the web app, the Chrome extension, the WordPress editor and the CLI, a secret is encrypted on your own device before anything is sent, and LinkPilot stores ciphertext it holds no key for. In Slack and Zapier the text is encrypted by the integration's own service in memory, so it does pass through that service on the way; those pages say so plainly. For anything where the text must never leave your device, use one of the first group.
Browser-side encryption shipped on 29 September 2026. Secrets created before that date were stored as plaintext until they expired, and a file's name, size and type are still visible to us. Read the full security model.