secret handoffs for people, tools, and agents
Move secrets without turning agents, logs, or transcripts into vaults.
Shhhs gives humans, scripts, and MCP-compatible agents a controlled handoff layer for passwords, API keys, files, and private requests. Supported content is encrypted client-side, expires by policy, and keeps external recipients outside your internal workspace.
One workflow for people, scripts, and agents
Give development, IT, support, operations, and agentic workflows a controlled way to exchange temporary credentials while clients, vendors, contractors, and partners participate without joining your workspace.
- Inside your company
- Outside your company
- Through tools and agents
Four handoff workflows
Send, Request, Private Rooms, and Automation cover the directions a secret moves between people, teams, scripts, and approved agent tools.
- Send passwords, files, or API keys
- Request credentials from someone else
- Clarify in short-lived Private Rooms
- Automate through API, CLI, and MCP-compatible workflows
Keep credentials out of prompts and transcripts
A credential pasted into a message or agent prompt can remain in notifications, backups, search indexes, exports, logs, and AI transcripts. Shhhs replaces that permanent exposure with a controlled encrypted handoff.
- Define where plaintext may appear
- Decide when access ends
- Limit how many times a secret may be opened
- Add a separate access code when policy requires it
- Delete the secret early when the task is complete
How Shhhs works
Create the secret, encrypt supported content on the client, share the link, and let the encrypted object become unavailable when its time, view, or deletion rule is reached.
- Create
- Encrypt
- Share
- Expire
Pro workspaces for operational work
Internal workspace owners, admins, and members need Pro. External recipients, submitters, and invited one-time room participants do not consume seats or receive workspace-console access.
- Pro for internal workspace members
- External participants stay outside the console
- Automation identities for scripts and agents
Security you can inspect
Shhhs documents where encryption happens, what service records exist, when objects expire, and which risks remain outside the product's control. We avoid absolute claims and publish only capabilities that can be verified.
- Client-side encrypted
- Expiring links
- Secret content is not sent to AI systems
FAQ
Does every recipient need an account?
No. A person may open a secret or submit through a request link without using your inbox or joining your internal console, unless the sender's policy requires identity verification.
Who needs Pro in a workspace?
Internal owners, admins, and members need Pro. External recipients and request submitters stay outside the workspace console.
Is Shhhs a password manager?
No. Shhhs is for temporary secret sharing. Use a password manager or secrets vault for long-term storage.
Can Shhhs work with scripts and AI-agent tools?
Supported plans can use API, CLI, and MCP-compatible workflows. Exact capabilities depend on the active plan and deployed integration version.