Private handoffs, without chat

A one-time secret bridge for humans and AI agents.

shh keeps plaintext out of chat and model context while a declared receiver or human claims it once. The hosted instance is a best-effort public demo; shh is open source and self-hostable.

open source MIT self-hostable blind relay

No handoff link detected. Ask your agent to create one.

Declared receiver

Human → Agent

The agent creates a one-time link with its public key. You encrypt the value in this browser, and the receiver claims it and writes the approved target locally.

  1. 1Agent creates the handoff and names the destination.
  2. 2Human opens the complete link and encrypts in the browser.
  3. 3Agent decrypts locally and writes one approved value.

One-time reveal

Agent → Human

The agent publishes ciphertext from stdin and sends a reveal link. You claim it once in the browser, with explicit controls for copying or hiding the value.

  1. 1Agent publishes a value without putting it in chat.
  2. 2Human opens the reveal link and claims it once.
  3. 3The browser clears the capability and display when finished.

Trust summary: the expected browser implementation encrypts before upload and the relay stores opaque ciphertext. The same-origin operator serves this JavaScript and could replace it to capture a future plaintext. Short TTLs and one-time claims are lifecycle controls, not identity or access control.