Password Pusher is a long-standing open-source tool: free, trusted since 2011, and it does inbound requests too. Here's the honest comparison, including the places it wins.
Password Pusher's server can read every password that passes through it, and the record has no idea your ticket closed. SafeHanded seals a requested credential in the browser to your technician's key, so our server has no key to read it with, and the record destroys itself when the ticket does, that's the difference between a convenience and a control you can put in front of an auditor.
| Dimension | SafeHanded | Password Pusher |
|---|---|---|
| Encryption model | End-to-end. Secrets are HPKE-sealed to the technician's key, unlocked only by their passkey. No key on our side. | Server-side. The app holds the key, so its servers, DB, backups and operators can decrypt every payload. |
| Who can decrypt | For requests, only the named recipient(s) (plus your organisation's recovery key, if you set one). A forwarded request link lets someone submit, never read. | Whoever holds the link, plus the server. An optional passphrase gates viewing, but the server can still decrypt. |
| Ticket lifecycle | Created from the ticket, note written back, auto-purge on ticket close, plus audit. | Expiry timer / view count. No native ticket or PSA integration (webhooks and API only), so the record has no idea your ticket closed. |
| Recipient verification | Spoken out-of-band challenge code, email or SMS one-time code; passkey step-up on every reveal. | Email OTP before viewing (Authenticated Recipients), on paid plans. |
| Audit | Hash-chained, signed, exportable chain + SIEM streaming + chain-of-custody certificate. | Audit logs on every plan; webhooks on Team and above. No SIEM export documented. |
| MSP platform | Multi-tenant: per-client branding, custom domains, client scoping, PSA mapping. | Multiple workspaces per login, but no per-client MSP console; an MSP partner programme for reselling self-hosted licences. |
| Identity & enrolment | One-time passkey enrolment — the step that lets a secret be sealed to a person, not a link. | No identity setup. An email code can gate viewing, but the server can still read the secret. |
| Open-source / self-host | Managed, EU-hosted SaaS; zero-knowledge by design. No self-hosted option. | Yes, open-source (Apache 2.0), free, self-hostable — you host, secure, patch and back it up. SSO and webhooks are paid Pro features. |
| Maturity | New — built in 2026 on open standards: HPKE (RFC 9180) and WebAuthn passkeys. | Open source since 2011, battle-tested — on a server-side model from an earlier era. |
| SSO | Microsoft Entra and any OpenID Connect provider on every plan; SAML and SCIM from Team. | OIDC SSO (Entra, Google) on the Organization plan; no SAML. |
| Price anchor | £39 Team (5 technicians included, then £5 each) / £149 MSP (10 included, then £8 each) per organisation per month. The premium, security-serious option. | Free / Solo $19 / Team $29 (3 seats) / Organization $49 (5 seats) per month, cheaper billed annually; self-hosted licences from $59 per month, billed annually. The cheap-and-simple option. |
Comparison based on Password Pusher's public documentation and our own tested behaviour, as of September 2026. If anything here is out of date, tell us and we'll correct it.
If you want a free, open-source, self-hosted paste-a-link tool for low-stakes sharing and you don't need zero-knowledge, ticket-linked purge or verifiable audit, Password Pusher is genuinely good, and cheaper. We won't pretend otherwise, and we won't chase that buyer.
If you handle clients' credentials, answer to a compliance framework or a cyber-insurer, or simply can't accept that a vendor can decrypt your secrets, the architecture is the product. Encrypted to a person, destroyed with the ticket, and provable in an audit.
Detailed, equally honest comparisons with the other tools MSPs and IT teams evaluate.
Start free, connect a ticket, and watch a handover purge itself when you close it.