Repo of the Day
trikko/neverstored: Hand a secret to someone while you are both there. Nothing is ever stored.
Published: Sep 17, 2026
Open repository ↗Hand a secret to someone while you are both there. Nothing is ever stored. - trikko/neverstored
Summary
neverstored is a self-hostable, ephemeral secret-sharing service where readable secrets never persist on a server. Two browsers perform an ECDH key exchange, each displays four symbols for manual verification, and only then does an AES-GCM-encrypted payload cross the server once before the room is destroyed.
What it is useful for
This is useful when an engineer needs to hand a password, API key, or PEM file to a colleague without that data lingering in chat history, email backups, or a typical one-time-secret database. The 8 KB payload cap is documented as fitting a password, a key, a PEM, or a short config — anything larger is refused by the page, the client, and the server. Engineers can share credentials with a co-worker on a call, send a vendor an "ask" link, or scan a QR code in person so both parties compare symbols side by side. The README also describes a terminal client, which avoids browser-extension risk because it only links against libcrypto and libcurl.
How engineers can use it
In the browser, type the secret, get a link (the link carries no secret, only an address), and share it however you like. When the recipient opens it, both sides exchange ECDH public keys, show four symbols with words underneath, and only after manual confirmation does the encrypted payload traverse the server.
Self-hosting from source, as documented:
git clone https://github.com/trikko/neverstored && cd neverstored
dub build --build=release
NEVERSTORED_PORT=8080 NEVERSTORED_NO_PROXY=1 ./neverstored
For production, the README recommends a TLS reverse proxy in front; Caddy and nginx examples ship in deploy/. A Dockerfile and compose.yml build a scratch-based image with operator details from static/operator.ini compiled in, running as uid 65534 on a read-only filesystem.
The CLI usage shown in the README:
./neverstored send --file api-key.txt
./neverstored open <link>
./neverstored ask > key.txt
Secrets are read from file, stdin, or typed without echo — never from arguments, to avoid process-list exposure. It defaults to https://neverstored.com but can target a self-hosted instance via NEVERSTORED_URL or --url.
Documented limitations worth knowing: TLS is required outside localhost (browsers deny crypto.subtle on plain HTTP, so an HTTP-only instance does not work); a compromised server could still serve modified JavaScript; browser extensions with page access can read the secret; recipients can screenshot or paste it elsewhere; rooms expire on timers (10 minutes unopened, 5 after one party arrives, 2 after both confirm); and the 8 KB cap means files are explicitly out of scope.