Get your free
API key.

Connect your app to deny.sh’s hosted services with an API key, your account’s access credential.

Free. No card. 500 API calls/month.

Use this to sign in to your dashboard for usage, audit log, billing, and account settings.

Your API key will appear on screen immediately. Keep your API key and dashboard password safe. If you lose both, we cannot restore access yet.

Your API key authorises service requests. We store a hash, never the key itself. A dashboard password only unlocks account controls.

Already have a key? Sign in · API docs · Vault

What you get
🔒

Encrypt + decoy

Free hosted encrypt/decrypt API. Creating a chosen decoy through the hosted API requires a paid plan. You can try chosen decoys in the free browser tool or run the local SDK. Compare entitlements.

📦

Vault storage

Store client-side encrypted secrets in your vault. The separate encrypt tool creates real and decoy control files.

🚨

Decoy alerts

Register a decoy’s identifier for alerts when our monitored decryption service sees it. Availability depends on your plan.

💻

Code libraries in 4 languages

Free code libraries for TypeScript, Python, Go and Rust. Local encryption needs no account.

What it looks like in practice

Create an API key, then follow the encrypt/decrypt quickstart. Both passwords are required together; choose the real or decoy control file when decrypting.

Open the quickstart ↗
No tracking
No analytics
Independent audit on the roadmap
Apache 2.0
🔓

You're in

Here's your API key. You won't see it again.

⚠ Save this somewhere safe. Right now.

What would you like to do?

🔒
Encrypt something
Use the browser tool. No coding needed.
📖
Read the API docs
Integrate deny.sh into your app.
🔧
Browse all tools
Encrypted vault, browser tools, and more.
📊
Set a password and open dashboard
View usage, audit log, billing, and account settings.
Developer quickstart ▾

Try it now

Your first encrypt
curl -X POST https://deny.sh/api/encrypt \ -H "Content-Type: application/json" \ -H "x-api-key: dk_your_key" \ -d '{"message":"hello world","password1":"example-one","password2":"example-two"}'

Or install an SDK

npm install deny-sh // Local encryption: no API key required. import { encrypt, generateDeniableControl, generateControlData } from 'deny-sh'; const password1 = 'example-one'; const password2 = 'example-two'; const message = new TextEncoder().encode('my secret'); const controlData = generateControlData(message.length + 4); const record = await encrypt(message, { password1, password2, controlData }); const decoy = await generateDeniableControl(record.ciphertext, password1, password2, new TextEncoder().encode('decoy')); // Hosted API key (keep private): dk_your_key
pip install deny-sh # Local encryption: no API key required. from deny_sh import encrypt, generate_deniable_control ct, real_control = encrypt(b'my secret', 'example-one', 'example-two') decoy_control = generate_deniable_control(ct, 'example-one', 'example-two', b'decoy') # Hosted API key (keep private): dk_your_key
go get github.com/deny-sh-crypto/deny-go/v2 // In your Go program, import denysh from the module above. // Local encryption needs no API key. Handle errors in production. ct, realControl, err := denysh.Encrypt([]byte("my secret"), "example-one", "example-two", nil) decoyControl, err := denysh.GenerateDeniableControl(ct, "example-one", "example-two", []byte("decoy text")) // Hosted API key (keep private): dk_your_key
# Add to Cargo.toml: deny-sh = "2" // In your Rust program: use deny_sh::{encrypt, generate_deniable_control}; let (ct, real_control) = encrypt(b"my secret", "example-one", "example-two", None).unwrap(); let decoy_control = generate_deniable_control(&ct, "example-one", "example-two", b"decoy text").unwrap(); // Hosted API key (keep private): dk_your_key