OneTimeSecret is the trusted classic: open-source, self-hostable, dead simple, and every plan includes an "Incoming Secrets" drop form. The gap is architectural: it's server-side encrypted, and its inbound form is a generic drop-box rather than a ticket-linked request.
OneTimeSecret's server handles the plaintext and its incoming form is an anonymous drop-box with no ticket behind it. SafeHanded encrypts to a technician's passkey so our server can't read it, turns the inbound flow into a ticket-linked request that purges on close, and gives you a verifiable, hash-chained audit chain.
| Dimension | SafeHanded | OneTimeSecret |
|---|---|---|
| Encryption model | End-to-end. HPKE-sealed in the browser to the technician's key; no key on our side. | Server-side. Encryption happens on the server, which sees the plaintext when a secret is created. With the optional passphrase, only a hash is stored, so it can't decrypt the stored secret later. |
| Who can decrypt | For requests, only the named recipient(s) (plus your organisation's recovery key, if you set one). | Whoever holds the link (and the passphrase, if set); the server handles the plaintext on the way in. |
| Inbound model | A per-request flow: justification, named subject, verification block, tied to a ticket. | "Incoming Secrets", on every plan: an anonymous drop form to a pre-configured list of recipients. |
| Ticket lifecycle | Created from the ticket, note written back, auto-purge on ticket close. | Expiry / one-time view. No ticket link. |
| Recipient verification | Spoken out-of-band challenge code, email or SMS one-time code, passkey step-up on reveal. | Basic; the drop form is anonymous by design. |
| Audit | Hash-chained, signed, exportable chain + SIEM streaming + chain-of-custody certificate. | A security audit trail (beta) on Team Plus only; no customer webhooks yet. |
| MSP platform | Multi-tenant: per-client branding, custom domains, client scoping, PSA mapping. | Organisations, RBAC and OIDC-based SSO (Google, GitHub, Entra) on Team Plus; custom domains and branding on paid plans. Not a per-client MSP console. |
| Identity & enrolment | One-time passkey enrolment — the step that lets a secret be sealed to a person, not a link. | No identity setup, and so no way to bind a secret to a specific person. |
| Open-source / self-host | Managed, EU-hosted SaaS; zero-knowledge by design. No self-hosted option. | Yes, open-source and self-hostable — you host, secure and patch it. |
| Maturity | New — built in 2026 on open standards: HPKE (RFC 9180) and WebAuthn passkeys. | Running since 2011, widely trusted — on a server-side model. |
| Price anchor | £39 Team (5 technicians included) / £149 MSP (10 included) per month. | Basic (free) / Identity Plus €35 / Team Plus €125 per month. |
Comparison based on OneTimeSecret's public changelog, docs and pricing and our own tested behaviour, as of September 2026. If anything here is out of date, tell us and we'll correct it.
If you want a free, open-source, self-hostable one-time-secret tool that everyone already trusts for low-stakes sharing, OneTimeSecret is excellent and hard to beat on simplicity and price. If you don't need zero-knowledge, a ticket lifecycle or a verifiable audit trail, you don't need us.
When you handle other people's credentials and have to prove it, an anonymous drop-box isn't enough. SafeHanded's server can't read the secret, the request is bound to your ticket and purges with it, and the whole chain is tamper-evident and exportable for an auditor.
Detailed, equally honest comparisons with the other tools MSPs and IT teams evaluate.
Start free, connect a ticket, and watch a handover purge itself when you close it.