Skip to main content

What's New 🤾

Releases, service updates, and announcements from Onetime Secret.

20 updates shipped Latest:
Operations

50% off for nonprofits, charities, and schools

Eligible nonprofits, charities, and educational institutions get 50% off Identity and Team plans.

  • 50% off Identity and Team plans
  • For eligible nonprofits, charities, and educational institutions
  • Verify your organization's domain to apply
Release

SAML SSO for self-hosted instances

Use your organization's SAML identity provider to sign in to self-hosted Onetime Secret instances and custom domains. Support for regional hosted sites is coming soon.

  • Connect your self-hosted instance to a SAML identity provider with three environment variables
  • Set up a separate identity provider for each custom domain in its SSO settings
  • Copy the registration details you need directly from the custom domain SSO form
  • Built-in checks prevent login responses from being reused and keep identities separate across providers
  • Support for our EU, UK, CA, NZ and US regional sites is coming soon
→ View the release details
Operations

Homepage forms unavailable for about three hours

Homepage forms and controls were unresponsive for about three hours after the 8 September deploy.

  • The incident lasted about three hours, starting at 21:47 UTC on 8 September.
  • Only the main homepage was affected; regional apps and customer data were unaffected.
  • We learned deployments could use untested dependencies when build tooling fell out of sync.
  • We tightened deployment safeguards and expanded browser testing to catch similar failures before release.
News

Interactive SSO demos

SSOWhat? provides interactive walkthroughs of OAuth, OIDC, SAML, and SCIM flows.

  • Step-by-step OAuth 2.0, OpenID Connect, SAML, and SCIM walkthroughs
  • User-facing screens are shown alongside the HTTP exchanges behind them
→ Visit ssowhat.dev
Operations

DNSSEC validation failures during our move off Cloudflare

Our DNS migration caused intermittent DNSSEC validation failures for onetimesecret.com; custom domains on onetime.co were unaffected.

  • Some DNSSEC-validating resolvers could not resolve onetimesecret.com and its subdomains intermittently from about 19–26 August
  • Custom domains route through onetime.co, which never used Cloudflare, and were unaffected
  • Mitigation is in place: Bunny's ZSK was added to Cloudflare's DNSKEY set, stale Hetzner records were removed, and the Cloudflare zone was deleted
  • Cloudflare nameserver and DS removal from the parent delegation remains pending; recovery will be verified from independent validating resolvers
  • A temporary DNS probe now monitors DNSSEC validation and hostname resolution while we work on a more robust solution
→ Why Cloudflare was added in 2024
Release

All new Admin UI

A rebuilt Colonel operating console — every admin capability written once, served as an op call, the CLI, and the UI.

  • Write-once operations: extract Operations::* so the CLI and admin API become thin adapters over the same shared verbs
  • New admin UI kit (DataTable, StatCard, FilterBar, DetailDrawer, ConfirmDialog, JsonViewer) on its own Rolldown-Vite entry, out of the customer bundle
  • AdminAuditEvent: every mutating operation records actor/verb/target/result
  • Support without SSH: filterable Customers list + detail page, plus Secrets, Domains, Organizations, System, BannedIPs, and Usage screens
→ PR #3679
Release

Better branding and private-label in v0.26

A cohesive branding experience across the app, emails, and every recipient touchpoint.

  • Neutral-by-default: self-hosted instances no longer ship with OTS orange or OTS branding
  • BrandSettings expanded from 15 to 22 fields (product name, domain, support email, footer, logos, favicon)
  • 12 email templates ported to brand helpers, replacing hardcoded colors/logos
→ PR #3054
News

Invites now live in EU

The invites system is now enabled in EU, completing the rollout across all five regions.

  • European Union (EU)
Release

Organizations, SSO, and incoming secrets in v0.25

Organizations and team members, site-wide and per-domain SSO, incoming secrets, and per-domain email sender configuration.

  • Organizations with role-based membership and branded invitations
  • SSO authentication site-wide and per-domain (OIDC, Google, GitHub, Entra, and more IdP providers to come)
  • Incoming Secrets, site-wide and per-custom-domain with recipient management UI
  • Email sender configuration per custom domain with per-record DKIM verification
→ GitHub release notes
News

UK region launched

Fifth region (uk.onetimesecret.com) launched on UpCloud, following the share-nothing regional architecture.

  • Brings the total to five regions: UK, NZ, CA, US, EU
  • v0.24 rollout order followed launch order: UK → NZ → CA → US → EU