Looking for serious maintainer(s), see issue.
Share sensitive information securely with client-side encryption and self-destructing messages.
Try it online • Quick Start • Docker Guide • Configuration
- Enter your secret on hemmelig.app or your self-hosted instance
- Set expiration time, view limits, and optional password
- Share the generated link with your recipient
- The secret is automatically deleted after being viewed or expired
Zero-knowledge architecture: All encryption happens in your browser. The server only stores encrypted data and never sees your secrets or encryption keys.
- Client-side AES-256-GCM encryption - Your data is encrypted before leaving your browser
- Self-destructing secrets - Configurable expiration and view limits
- Password protection - Optional additional security layer
- IP restrictions - Limit access to specific IP ranges
- File uploads - Share encrypted files (authenticated users)
- Rich text editor - Format your secrets with styling
- QR codes - Easy mobile sharing
- Multi-language support - Available in multiple languages
- Webhook notifications - Get notified when secrets are viewed or burned (docs)
docker run -d \
--name hemmelig \
-p 3000:3000 \
-v hemmelig-data:/app/database \
-v hemmelig-uploads:/app/uploads \
-e DATABASE_URL="file:/app/database/hemmelig.db" \
-e BETTER_AUTH_SECRET="$(openssl rand -base64 32)" \
-e BETTER_AUTH_URL="https://your-domain.com" \
hemmelig/hemmelig:v7git clone https://github.com/HemmeligOrg/Hemmelig.app.git
cd Hemmelig.app
# Edit docker-compose.yml with your settings
docker compose up -dSee Docker Guide for detailed deployment instructions.
The hemmelig CLI does all that the web app does, with the access of your account. It encrypts and decrypts on your machine.
# Download the binary for Linux on amd64. Other platforms are in docs/cli.md.
curl -L https://github.com/HemmeligOrg/Hemmelig.app/releases/download/cli-v1.1.0/hemmelig-linux-amd64 -o hemmelig
chmod +x hemmelig
# Create a secret and print the link.
./hemmelig "API key: sk-1234" -t "Production API Key" -e 7d -v 3
# Read a secret, then work with your own instance.
./hemmelig secrets get "https://hemmelig.app/s/<id>#<key>"
./hemmelig login --url https://secrets.example.com
./hemmelig admin users list --jsonThe CLI also runs a local MCP server, so AI assistants can use Hemmelig with an API key:
HEMMELIG_API_KEY=hemmelig_xxxxxxxxxxxxxxxx ./hemmelig mcp- CLI documentation: install, authentication, every command, JSON output and exit codes.
- MCP server: Claude Desktop and Claude Code setup, the tools and the security model.
- Docker Deployment - Complete Docker setup guide
- Helm Chart - Kubernetes deployment with Helm
- Environment Variables - All configuration options
- Managed Mode - Configure instance settings via environment variables
- CLI - Command-line interface for automation and CI/CD
- MCP Server - Let AI agents create and read secrets with local encryption
- API Keys - Use the API with a key, and the actions that need a session
- Encryption - How client-side encryption works
- Social Login - OAuth provider setup (GitHub, Google, etc.)
- Secret Requests - Request secrets from others securely
- Webhooks - Webhook notifications for secret events
- Health Checks - Liveness and readiness probes for container orchestration
- Prometheus Metrics - Monitor your instance with Prometheus
- API Documentation - REST API reference and OpenAPI spec
- SDK Generation - Generate client SDKs from OpenAPI spec
- E2E Testing - End-to-end testing with Playwright
- Upgrading from v6 - Migration guide for v6 to v7
npm install
npm run dev
npm run dev:apiHemmelig is proudly hosted on Hetzner Cloud. Hetzner provides reliable and scalable cloud solutions, making it an ideal choice for hosting secure applications like Hemmelig. By using our referral link, you can join Hetzner Cloud and receive €20/$20 in credits. Once you spend at least €10/$10 (excluding credits), Hemmelig will receive €10/$10 in Hetzner Cloud credits. This is a great opportunity to explore Hetzner's services while supporting Hemmelig.
O'Saasy License Agreement - Copyright © 2025, Bjarne Øverli.
This project is licensed under a modified MIT license that prohibits using the software to compete with the original licensor as a hosted SaaS product. See LICENSE for details.
