Blog

Vanish: secrets that delete themselves

A self-destructing secret sharing tool built on free-tier Cloudflare Workers, and a build guide for reproducing it.

Vanish is live. You paste a secret, you get a link, you send the link. The recipient opens it once and the secret is destroyed.

It exists because the usual way of passing a credential to someone — chat, email, a ticket comment — leaves it sitting in a log that outlives the reason it was sent. A link that only works once turns that into a much smaller problem.

The server never sees the secret

Secrets are encrypted in the browser with AES-256-GCM before anything is sent. The decryption key travels in the URL fragment — the part after the #, which browsers never transmit to the server. What Vanish stores is ciphertext it has no way to read.

Link previews do not get to read it first

A one-time link has an obvious failure mode: something opens it before the recipient does. Slack, WhatsApp, Outlook Safe Links, and corporate mail scanners all fetch URLs to build previews, and a naive implementation hands them the secret and burns it.

So revealing a secret in Vanish requires an explicitPOST — never a GET. Preview bots issue GETs. They can fetch the page all they like; they cannot destroy a secret before the person it was sent to has read it.

The stack

Cloudflare Workers, on the free tier throughout. Astro builds the static frontend, and a single Worker serves those assets and handles the API. Each secret gets its own SQLite-backed Durable Object, which is what makes the burn atomic — two people opening the same link at the same moment cannot both be served — and gives expiry a place to live as an alarm rather than a cleanup job.

Build guide

The Vanish repository is private, but the build guide is not. It is a set of AI instructions for reproducing Vanish from scratch: the platform and scope decisions, the design language, and the implementation plan.

Read the build guide