QuarryPasswords

Some thingsaren't meantto stay.

Don’t email passwords.
Don’t send screenshots of credit cards.
Share through an encrypted link instead.
Revealed once, then [BLANK]

Encryption
In your browser
Access
One reveal
Lifetime
Your choice
Account
Not required

A private handoff.
A short history.

QuarryPasswords shares passwords and API keys through encrypted, one-time links. Share up to 7 items for free, without an account.

  1. Add what you're sharing.

    A login, an API key, or a few of each. Everything stays together in one encrypted bundle.

  2. Set its lifespan.

    Choose an expiry. Add a passphrase if you want another layer of protection.

  3. Pass it on.

    Send the link. Once they press Reveal, the link cannot be used again.

Sharing walkthroughExample only

Sender view · You

You have a password to share.

Imagine sending this made-up login to a teammate. In this example, you create a private link with no passphrase and send it to them.

Made-up details. Nothing is sent or shared.

Encrypted before sending.
Unreadable to us.

Your browser encrypts your secrets first. We add a second encryption layer before storing them. The key to the contents stays in your link and is never sent to us.

Two layers of encryption

One in your browser. Another on our servers.

  • AES-256-GCM encryption in both layers
  • Separate keys for your contents and our storage
  • Our storage key cannot unlock your secrets

Deleted on reveal

Revealed once, then removed from active storage.

  • The link stops working as soon as it is used
  • Unused links stop working at your chosen expiry
  • Opening the page alone doesn’t consume a share
How it's kept safe

Before you share

Does opening the link reveal the password?

No. The recipient must press Reveal. A successful reveal removes the encrypted contents from active storage and prevents another retrieval.

Can QuarryPasswords read my credentials?

Your device encrypts the contents before upload. The decryption key stays in the link, after the # sign, and is not sent to our servers. Anyone with the full link can reveal the share unless you add a passphrase.

Is this a password manager?

No. It is a one-time handover tool. Keep your own copy in a password manager. Shared credentials cannot be recovered after reveal or expiry, and recipients can keep copies.

Can an AI agent create a share?

Yes, through the local, guest-only MCP integration. It currently requires an authorized source checkout. Read the agent setup guide.