Skip to content

binthere

Burn-after-read encrypted notes, with the key kept in the link fragment and a CLI for terminal output

binthere compose screen in the dark theme with a note field, a Password button and a Create link button

binthere encrypts each note in the browser with AES-256-GCM, so the server stores only ciphertext. The first reader gets the note, later requests get 410 Gone, and unread notes expire after 24 hours. It runs as one Cloudflare Worker with Static Assets, KV and a Durable Object.

binthere is a clean-room rebuild of PrivateBin's zero-knowledge model that uses Web Crypto and a strict content security policy. The browser generates a random 256-bit key before any network request, and the share link carries the note ID with the key after the #, a part of the URL browsers never send to a server. An optional password is mixed into the key derivation, so neither the link nor the password alone decrypts the note. A Durable Object makes the single read atomic, so if two people open the link at the same moment, only one gets the content. The viewer applies auto-detected syntax highlighting and renders a sanitized Markdown subset. The site has no accounts or analytics. For the terminal, the binthere npm CLI speaks the same protocol and works in pipelines such as git diff | npx binthere. Workers Static Assets serves the vanilla JavaScript frontend. A KV namespace stores normal pastes with native TTL expiry, a SQLite-backed Durable Object holds burn-after-read pastes, and a rate limiting binding throttles paste creation. SPEC.md freezes the protocol with test vectors, and SECURITY.md documents the threat model. The Deploy to Cloudflare button provisions the KV namespace, the Durable Object and the rate limiter.

Built for: Developers and small teams who share credentials or sensitive snippets and want a self-hosted, zero-knowledge one-time link service

What you can use it for

  • Send a credential or API key to a teammate as a link that works once
  • Share a private message or code snippet without either side signing up
  • Pipe terminal output into a one-time encrypted link
  • Host your own one-time secret-sharing service on your Cloudflare account

Deploy

  • One-click · main path

    Branch main

  • CLI

    Paste the KV namespace id and preview_id that kv:create prints into wrangler.toml before you deploy.

    npm install
    npm run kv:create
    npm run deploy

The button deploy asks for no secrets. Afterward, point the hardcoded canonical URLs, Open Graph image and security.txt at your own domain.

What it needs to run

  • Durable ObjectsBurnPaste
  • KV namespacesPASTES

Good to know

The server still sees IP addresses, timing and ciphertext sizes. Decryption runs in JavaScript served by the deployment, so a compromised host could leak keys. Lost links cannot be recovered. The UI fixes expiry at 24 hours and one-time view. The interface is English only. Passwords use PBKDF2-SHA256, and someone holding the link can test passwords offline.

Cost on Cloudflare

Likely fits the free plan

The README states that a complete instance fits within the free tier. The Workers Free plan includes SQLite-backed Durable Objects (100,000 requests per day) and KV (100,000 reads and 1,000 writes per day). Notes created in the web UI are burn-after-read notes held in the Durable Object.

Source

The estimate is based on Cloudflare’s documented limits and the app’s configuration. What you pay depends on your usage and plan.

Where this comes from

An alternative to Onetime Secret, Password Pusher, Privnote, scrt.link.

Listing history

  • Oct 2, 2026 · binthere listed

Similar apps

All Security apps
  • NodeWarden homepage header with a feature summary and Start Here, Online Demo and Contributors buttons

    Bitwarden-compatible password vault server that runs on Workers, D1 and R2 in your own Cloudflare account

    Deploy
    Manual
    License
    LGPL-3.0
    GitHub stars
    3.9k stars
    Last commit
  • 2FA desktop view in Chinese with a search bar above a four-column grid of account cards, each showing its current code

    Self-hosted TOTP and HOTP code manager with imports from other authenticators, cloud backups and browser extensions

    Deploy
    One-click
    License
    MIT
    GitHub stars
    449 stars
    Last commit
  • 2FAuth Worker sign-in screen on the public demo, offering several login providers and passkey sign-in

    Self-hosted TOTP vault with AES-encrypted secrets in D1, whitelist OAuth login and an offline-capable PWA

    Deploy
    Manual
    License
    AGPL-3.0
    GitHub stars
    62 stars
    Last commit