Match the control to the risk
Why it matters: Unlisted limits discovery, a password adds a check, and browser encryption changes what storage can read.
Discovery controls, access controls, encryption, and expiration solve different problems. These guides explain each boundary plainly so you can choose a setting based on the content and its recipients - Not a reassuring label.
Classify the data first, remove secrets, then choose separate controls for discovery, access, storage, and retention.
Why it matters: Unlisted limits discovery, a password adds a check, and browser encryption changes what storage can read.
Why it matters: Redact tokens, personal data, signed links, internal hosts, and live credentials even when access is limited.
Why it matters: Expiration and burn-after-read stop later access to the source link, but they cannot erase a recipient’s copy.
Encryption, secret scanning, expiration, access control, and safer handling of sensitive text in pastebin workflows.
Compare public, unlisted, passworded, owner-only, and browser-encrypted pastes by discovery, application access, storage readability, and recovery.
Read guide →Add a second access check to a paste, share the password safely, and understand when browser encryption is the stronger choice.
Read guide →Choose paste retention from ten minutes through permanent availability, match it to the review window, and understand why expiration cannot recall copies.
Read guide →One successful retrieval can trigger deletion, but delivery systems still require careful threat modeling.
Read guide →Use a repeatable pre-publish review for tokens, credentials, private keys, cookies, connection strings, personal data, and contextual secrets.
Read guide →Automate paste workflows without putting permanent credentials in scripts, logs, or source repositories.
Read guide →Compare public, unlisted, owner-only, password-protected, and encrypted pastes by discovery, authentication, server readability, sharing, and retention.
Read guide →Find and replace credentials, personal data, session identifiers, internal hosts, and signed URLs while preserving the diagnostic relationships a reviewer needs.
Read guide →Turn a real .env file into a synthetic example by removing credentials, rotating exposed values, documenting required variables, and sharing only safe placeholders.
Read guide →No. It limits discovery but does not encrypt content or stop a recipient from forwarding the URL. Read the complete explanation.
It keeps readable content out of the normal storage request; it cannot protect a compromised browser, exposed complete link, or recipient copy. Read the complete explanation.
Revoke or rotate the credential at its issuing system first, then remove the paste and inspect logs for unauthorized use. Read the complete explanation.
Begin with the privacy comparison, select a control for the actual threat, and verify it using non-sensitive text. Use a secret manager when the material is a live credential.
Try the paste editor →