1tyme Guide
← Back to app
Getting started

Welcome to 1tyme

1tyme is a secure workspace for sharing secrets, passwords, and files that self-destruct after they're read — with every project's access explicitly approved, never assumed. This quick guide walks you through the full flow, from signing in to sharing your first secret.

How it works — step by step

1

Sign in

Open the app and authenticate with your organization's single sign-on (Azure AD, SAML, or Keycloak), or local credentials if enabled. Your session is protected and times out automatically when idle, with a warning before it expires.

2

Request access to a project

New here? You won't see any project's data until an admin approves you. On your first sign-in:

  • Choose the project you need from the list.
  • Add an optional note explaining why you need access.
  • A project admin (or super admin) reviews and approves your request.
  • Once approved, your workspace unlocks automatically — no page refresh needed.
3

Explore your workspace

Everything lives in the left-hand sidebar: Share, Messages, Keys, Password Vault, Notes, and Settings. If you belong to more than one project, switch between them from your Profile — each project's data stays completely separate.

4

Share a secret

Go to the Share tab and create a one-time secure link:

  • Type the secret (password or text), or attach up to 10 files.
  • Add an optional subject so recipients know what it is.
  • Set an expiry (how long it stays valid) and a max view count.
  • Optionally restrict to users or groups — search your organization's directory by name or email.
  • Generate the link and share it. Recipients are notified by email / Teams.
5

Check your messages

Open Messages → Inbox for secrets shared with you, or Sent to track what you've shared. Hover over any row to reveal quick actions — View details in your inbox, or Copy link / Burn (destroy immediately) for sent items. Each secret can be viewed a limited number of times before it auto-destructs.

6

Use the built-in tools

Beyond sharing, 1tyme includes a password generator, SSH/API key generator, a personal vault, secure notes, and certificate tracking — all in one place.

  • Generate SSH keys, passwords, or API keys — use Download Keys for SSH private keys (copy/paste on Windows can corrupt them).
  • Click Save to Vault right after generating to back it up in one step.
  • Track Certificates so nothing expires unnoticed.

Access Governance — Project-Based Permissions

No user sees any project's data until an admin approves them.

1
Sign in

User authenticates via SSO. No project membership yet.

2
Request

Picks a project from a list. Optional note to the approver.

3
Review

Project admin or super admin sees the pending request.

4
Approve

Added as Member or Admin. Every grant is audit-logged.

Role model

Member — project access only  •  Project Admin — manage members, features & requests for their project  •  Super Admin — platform-wide oversight

How Secure Sharing Works

1
Create

Enter secret + file. Set expiry & max views. Restrict to users/groups.

2
Scan

ClamAV malware detection. Phishing URL analysis. Suspicious content check.

3
Encrypt

AES-256-GCM encryption. Stored in Redis with TTL. Metadata in PostgreSQL.

4
Deliver

Recipient gets secure link. Teams / Email notification. Auto-destroyed after use.

Security controls

AES-256-GCM  •  ClamAV Malware Scan  •  Phishing/URL Analysis  •  CSRF Protection  •  Rate Limiting  •  TLS 1.3  •  HSTS + CSP

What's inside

🔗

Share

Create one-time secure links for secrets and files with expiry & view limits.

📥

Messages

Track secrets shared with you (Inbox) and ones you've sent (Sent).

🔑

Generate

Create strong passwords, SSH keypairs, and API keys instantly.

🗄️

Password Vault

Store and organise credentials securely in folders.

📝

Notes

Keep encrypted notes and attachments private to you.

📜

Certificates

Track certificate expiry dates so renewals never sneak up on you.

⚙️

Settings

Profile, appearance (theme & text size), security, and project settings — all in one place.

🛡️

Access Governance

Every project grant is requested, reviewed, and approved by an admin — with a full audit trail.

🔒 Built secure by design

Everything is encrypted with AES-256 using a zero-knowledge approach, secrets automatically self-destruct after expiry or once their view limit is reached, and no one sees a project's data until an admin explicitly approves them.