Burn-After-Read Link Generator (Self-Destructing URLs)

    Share a password, token, or note with one person. After they read it, it's gone — encrypted at rest, destroyed on reveal, optional passphrase. No account needed.

    0/10,000 characters

    Hashed in your browser before sending

    Burn after read is always on for anonymous secrets. The link self-destructs after one view.
    Burn after read
    Optional passphrase
    Never expires (until read)
    • One-time reveal — self-destructing URL
    • Burn after read by default
    • Encrypted at rest
    • Optional passphrase protection
    • No signup required
    • Privacy-preserving reveal logging
    • Upgrade for file attachments & audit timeline

    How it works — 3 steps

    1. 1

      Enter the secret

      Type or paste the password, token, or message you want to share once.

    2. 2

      Add a passphrase (optional)

      Require a passphrase for an extra layer of protection if the URL itself leaks.

    3. 3

      Send and forget

      Share the link. The first successful read destroys the secret atomically — even you can't recover it.

    What does 'burn-after-read' mean?

    When the recipient opens the link, we show them the secret once and then permanently destroy the encrypted payload. The same URL, opened a second time, shows a 'burned' state — even by you. There's nothing left to leak.

    Burn-after-read vs one-time secret vs expiring link

    All three remove a URL's value over time, but they answer different questions. A burn-after-read link self-destructs on the first read — it's about one viewer. A one-time secret link is the same idea applied to short text payloads like passwords. An expiring (temporary) link is about a clock — it stops working at a chosen time regardless of how many people opened it. Pick burn-after-read when only one person should see the contents. Pick an expiring link when you want a short URL that stops working on a date.

    Self-destructing URLs — when and why

    A self-destructing URL is the right primitive whenever the recipient will read it once and never again: a generated password for first login, a one-time recovery code, an internal staging URL, or a private note to a single person. LinkPilot's burn happens atomically with row-level locking so two simultaneous opens can't both succeed.

    Why this beats sending a password in chat

    Chat messages and emails persist in inboxes, backups, and search indexes long after they were useful. A burn-after-read link removes the secret the moment it's been read, so it can't be re-discovered by someone scrolling through history months later.

    LinkPilot Secret Links — the upgrade

    Sign up for LinkPilot Secret Links and unlock: file attachments with short-lived signed URLs, audit timelines showing reveal events, configurable reveal limits (one-time or many), team access controls, longer retention windows, and SSO/SAML for enterprise.

    Frequently asked questions

    Ready for the full LinkPilot?

    Create a free account to claim your links, get private analytics, revoke after sending, set passphrases, and manage everything in one workspace.

    Related free tools

    Learn more