OneTimeSecretLink

Please follow this procedure for using a one-time link to send a secret in a secure way.
This could be a password, passphrase, access token, API key etc.

  1. Open a conversation with your correspondent so you know the right person is available and they know what to expect.

  2. Generate a new secret with the relevant application, but do not activate it.

  3.     
  4. Copy the unique link created above or the boiler-plate text and paste it into a message to your correspondent.
    Ensure the messaging application does not alter the link with a spell-checker etc. then send it.

  5. Wait for your correspondent to confirm if they have succesfully saved the secret.

  6. If they say the link was already used, then follow the REVOKE process for the relevant application, and repeat the process.

  7. When the secret has been succesfully received, activate the secret in the relevant application.

  8. Let your correspondent know that the secret is now ready for them to use with the relevant application.