Oncepad shares a file, password, API key or .env file through a link that works exactly once, then destroys itself. Everything is encrypted in your browser (AES-256-GCM) under a generated 7-word passphrase, the server only ever holds ciphertext, in RAM, never on disk.
The link carries no key, so it's safe to paste in email, Slack or a ticket; the passphrase travels on a second channel. No account, no cookies, no analytics, nothing to install. Unopened secrets or files expire in 24 hours.