Securely Sharing API Keys with Further

Last updated: September 1, 2026

Last updated: September 2026

Overview

To protect sensitive credentials, Further asks all clients and partners to share API keys through a secure, one-time method rather than posting them in Slack messages, support tickets, or plain email. This guide covers the recommended process.

Why this matters

Raw API keys sent through open channels (chat threads, email bodies, ticket comments) can remain visible indefinitely to anyone with access to that channel, including in message history and search. A one-time secure share removes the key from view after it's been retrieved, reducing the risk of accidental exposure.

Recommended method: One-Time Secret

Further supports sharing credentials via One-Time Secret, a free tool that generates a link containing your secret. The link can only be opened once, after which the content is permanently deleted.

Steps

  1. Go to ots.frth.ai.

  2. Paste the API key (or other credential) into the secret field.

  3. If a passphrase option is available, set one. It adds a second layer of protection on top of the one-time link.

  4. Generate the one-time link.

  5. Email the link to support@talkfurther.com, with your Further CSM cc'd. If you set a passphrase (not required), send it separately — for example in a follow-up email, Slack message, or a quick call — rather than in the same email as the link.

  6. Once retrieved, the link expires and cannot be viewed again. If it's not opened within the tool's expiration window, it also expires automatically.

Using your own secure method

If your organization has a preferred secure credential-sharing tool already in place (for example, a password manager's secure share feature or a secrets vault), you're welcome to use that instead. Just route the share the same way: to support@talkfurther.com with your CSM cc'd, so it reaches the right team.

What happens after you share a key

Once Further support receives a key through a secure share, it's stored in our internal credential vault and handled according to our internal access controls. You do not need to re-share a key unless it changes or is rotated, at which point the same process applies.

Questions

If you have questions about this process or need help setting up a secure share, reach out to your Further CSM or email support@talkfurther.com.