Access & security
Sharing secrets
Send an API key, password or .env file through an encrypted link that expires.
Use secret links to hand someone a password, API key or .env file without pasting it into chat or email. The content is encrypted on your machine before it is sent. The key is only in the link, so Elula can't read it.
How it works
- Your browser or the CLI encrypts the content with a new AES-256-GCM key.
- Only the encrypted content is stored in Elula.
- The key goes in the link after the
#. Browsers don't send that part of a URL to the server. - The person opening the link decrypts it on their side.
Links look like this:
https://<elula-web-address>/s/<id>#<key>
Send from the dashboard
Open Send a secret in the dashboard. Paste text, or upload or drag in a file such as .env, .json, .pem or .key. Choose when it expires (1 hour up to 30 days). Under Advanced options you can set:
- Max views: delete the secret after this many views.
- PIN protect: require a password.
- Restrict to email: only this person can open it, after signing in.
- Require click to reveal: hide the content until the viewer clicks.
Send from the CLI
elula send "sk_live_..." # text elula send -f .env.production # a file cat creds.json | elula send # from stdin elula send -f .env --expires 60 --max-views 1 # one view, gone after an hour elula send "hunter2" --password "correct horse" # needs a password elula send -f key.pem --to alice@company.com # only Alice, signed in
| Option | What it does |
|---|---|
-f, --file | Read the content from a file. |
--expires | Minutes until it is deleted. Default 1440 (1 day), maximum 43200 (30 days). |
--max-views | Delete after this many views. |
--password | Require a password to view. |
--to | Only the person signed in with this email can open it. |
The CLI prints the link and the command to revoke it.
Open a secret
Open the link in a browser, or decrypt it in the terminal:
elula reveal "https://<elula-web-address>/s/<id>#<key>" elula reveal "<link>" --password "correct horse" elula reveal "<link>" -o .env # save to a file instead of printing
Quote the link so your shell doesn't cut it at the #. Binary content must be saved with -o.
Each open counts as a view. When a secret reaches its view limit or its expiry time, it is deleted.
Check and revoke what you sent
elula sends # list your secrets: state, views, protection, expiry elula sends status <id> # ID, ID prefix or the share link elula sends revoke <id> # delete it now; -y skips the prompt
Only the person who sent a secret can revoke it. The list shows metadata only. Nobody can get the content back from Elula, including you.
Limits
| Limit | Value |
|---|---|
| Encrypted content size | 1 MB |
| Longest expiry | 30 days |
| Max views setting | 1 to 1000 |
| Active secrets per person | 100 |
| Open attempts | 5 per minute |