Skip to content

Access & security

Sharing secrets

Send an API key, password or .env file through an encrypted link that expires.

Use secret links to hand someone a password, API key or .env file without pasting it into chat or email. The content is encrypted on your machine before it is sent. The key is only in the link, so Elula can't read it.

How it works

  1. Your browser or the CLI encrypts the content with a new AES-256-GCM key.
  2. Only the encrypted content is stored in Elula.
  3. The key goes in the link after the #. Browsers don't send that part of a URL to the server.
  4. The person opening the link decrypts it on their side.

Links look like this:

https://<elula-web-address>/s/<id>#<key>
Anyone with the full link can open the secret, unless you add a password or restrict it to one email. Share the link over a channel you trust.

Send from the dashboard

Open Send a secret in the dashboard. Paste text, or upload or drag in a file such as .env, .json, .pem or .key. Choose when it expires (1 hour up to 30 days). Under Advanced options you can set:

  • Max views: delete the secret after this many views.
  • PIN protect: require a password.
  • Restrict to email: only this person can open it, after signing in.
  • Require click to reveal: hide the content until the viewer clicks.

Send from the CLI

elula send "sk_live_..."                         # text
elula send -f .env.production                    # a file
cat creds.json | elula send                      # from stdin
elula send -f .env --expires 60 --max-views 1    # one view, gone after an hour
elula send "hunter2" --password "correct horse"  # needs a password
elula send -f key.pem --to alice@company.com     # only Alice, signed in
OptionWhat it does
-f, --fileRead the content from a file.
--expiresMinutes until it is deleted. Default 1440 (1 day), maximum 43200 (30 days).
--max-viewsDelete after this many views.
--passwordRequire a password to view.
--toOnly the person signed in with this email can open it.

The CLI prints the link and the command to revoke it.

Open a secret

Open the link in a browser, or decrypt it in the terminal:

elula reveal "https://<elula-web-address>/s/<id>#<key>"
elula reveal "<link>" --password "correct horse"
elula reveal "<link>" -o .env                    # save to a file instead of printing

Quote the link so your shell doesn't cut it at the #. Binary content must be saved with -o.

Each open counts as a view. When a secret reaches its view limit or its expiry time, it is deleted.

Check and revoke what you sent

elula sends                    # list your secrets: state, views, protection, expiry
elula sends status <id>        # ID, ID prefix or the share link
elula sends revoke <id>        # delete it now; -y skips the prompt

Only the person who sent a secret can revoke it. The list shows metadata only. Nobody can get the content back from Elula, including you.

Limits

LimitValue
Encrypted content size1 MB
Longest expiry30 days
Max views setting1 to 1000
Active secrets per person100
Open attempts5 per minute