Passwords end up in the worst places. A client’s WordPress login sits in an email thread from eight months ago. An API key is pasted into a Slack channel where thirty people can scroll back and find it. A Wi-Fi password lives in a text message that never gets deleted. None of this is anyone’s fault – email and chat were never built to hold secrets, they were built to hold conversations.
Target now includes a simple way to fix this: secret sharing. It is built into the platform you already use for marketing, so sharing a password safely takes the same amount of effort as sending a link.
What secret sharing is
Secret sharing lets you send a password, an API key, a license code or any other short piece of sensitive text as a one-time link instead of as plain text. The recipient opens the link, reads the secret once, and the link stops working. Nobody can scroll back through a chat history and find it later, because there is nothing left to find.
You can also request a secret from someone else. Instead of asking a client to “just email me the password”, you send them a request link. They fill it in, it is encrypted immediately, and only you can read the answer.
How the encryption works
The secret is encrypted in your browser with AES-256-GCM before it is sent anywhere. The encryption key travels in the part of the link after the # character, which browsers never send to a server. In practice this means Target’s own servers only ever store ciphertext – scrambled data that is useless without the key that never left the link itself.
This is sometimes called a zero-knowledge design: the service that stores the secret has no way to read it, by construction, not just by policy.
Why it matters for a small business
Client handovers
Agencies and freelancers constantly move logins between people: a client hands over a domain registrar password, a developer hands back a hosting login when a project ends. A one-time link replaces an email that would otherwise sit in an inbox indefinitely.
Team and contractor access
Shared tool logins, a Wi-Fi password for a new hire, an API key for a contractor who only needs it for a week – secret sharing gives each of these a link that expires after one view, instead of a permanent record in chat.
It also earns trust with the person you send it to
Because the sharing page is part of Target, the person opening the link sees that you hand over sensitive credentials through a proper, secure system – not pasted into an email or typed into a chat window. That is a small but real signal: you take their password or access details seriously enough to use a tool built for it, instead of whatever is closest at hand.
How to use it
Open Secrets from your Target dashboard, paste in the password or code you want to share, and set how many times it should be viewable. Target gives you a link to send through whatever channel you like – email, chat, or read aloud over a call. Once it has been opened the agreed number of times, it is gone.
Get started
Secret sharing is included with Target, alongside the strategy, brand, persona and content planning tools you already use. Start your free week to try it with your next password handover.