Generate secrets and UUIDs. Share sensitive info safely.
Use the in-browser generator for passwords, passphrases, and UUIDs (offline-capable after your first visit), or encrypted sharing: you encrypt keys, tokens, or notes before anything reaches our servers.
Sign in for team invites, agent API keys, and share management—built on the open DotEnvUp standard.
Secrets and UUIDs are created only in your tab. When you generate, nothing uploads—we never see the generated text.
Open /generate once while online: a small service worker caches the tool. Later visits can load from disk and keep working offline until you pull an update.
Encrypted shares are created in /app (needs network to deliver the ciphertext link).
Privacy. GDPR-centered processing with EEA & UK rights and a US state notice (draft). OAuth sign-in may use GitHub, Google, or Apple as described in our Privacy Policy.
Possible thanks to Cloudflare.
Pages for this site and Workers for the API give fast global delivery and tight request isolation, so what you generate in the browser still never leaves your tab and encrypted shares leave only as ciphertext.
Cloudflare publishes certifications and reports such as ISO 27001 and SOC 2 in their Trust Hub.
Generator, encrypted shares, team invites, and agent API keys are free today. Audit UI and paid seat billing are not live yet.
For engineering leads
Plaintext stays in the browser for generation; ciphertext only for shares.
Today: zero-knowledge encrypted links, burn-after-read, optional GitHub recipient lock, team invites, and agent keys for automation. Revoke shares from the dashboard. Full audit trail UI and org-wide .env.up workflows are still in development.
Local generator & encrypted shares
Create passwords, passphrases, and UUIDs locally in your browser. Send sensitive text as an encrypted link with expiry, burn-after-read, or (when you choose) a recipient tied to a GitHub login—we only ever store ciphertext.
Team invites & agent keys
Sign in to invite teammates, manage shares, and create agent API keys for MCP or CI. GitHub SSH public key lookup helps prepare identity-based encryption. Audit UI and full .env.up org workflows are still in development—see the DotEnvUp format for the open standard.
Zero-knowledge by design
Generation does not upload your output; sharing encrypts in your tab before upload. Aligned with the same cryptographic direction as the open-source DotEnvUp standard (e.g. modern AEAD and sealed formats where used).
Team workflows will align with the open DotEnvUp v1 Encrypted .env Standard—hybrid public-key encryption, multi-recipient, CI/CD-ready. Today’s web app focuses on standalone generation and encrypted link sharing.