Vanish: secrets that delete themselves
A self-destructing secret sharing tool built on free-tier Cloudflare Workers, and a build guide for reproducing it.
Vanish is live. You paste a secret, you get a link, you send the link. The recipient opens it once and the secret is destroyed.
It exists because the usual way of passing a credential to someone — chat, email, a ticket comment — leaves it sitting in a log that outlives the reason it was sent. A link that only works once turns that into a much smaller problem.
The server never sees the secret
Secrets are encrypted in the browser with AES-256-GCM before anything is sent. The decryption key travels in the URL fragment — the part after the #, which browsers never transmit to the server. What Vanish stores is ciphertext it has no way to read.
Link previews do not get to read it first
A one-time link has an obvious failure mode: something opens it before the recipient does. Slack, WhatsApp, Outlook Safe Links, and corporate mail scanners all fetch URLs to build previews, and a naive implementation hands them the secret and burns it.
So revealing a secret in Vanish requires an explicitPOST — never a GET. Preview bots issue GETs. They can fetch the page all they like; they cannot destroy a secret before the person it was sent to has read it.
The stack
Cloudflare Workers, on the free tier throughout. Astro builds the static frontend, and a single Worker serves those assets and handles the API. Each secret gets its own SQLite-backed Durable Object, which is what makes the burn atomic — two people opening the same link at the same moment cannot both be served — and gives expiry a place to live as an alarm rather than a cleanup job.
Build guide
The Vanish repository is private, but the build guide is not. It is a set of AI instructions for reproducing Vanish from scratch: the platform and scope decisions, the design language, and the implementation plan.