How Nobins works

Nobins is a zero-knowledge pastebin. Encryption and decryption happen entirely in your browser. The server only stores ciphertext โ€” it can never read your content.

The flow

1

You write or paste content

Paste an incident note, onboarding handoff, recovery note, or any other text-only secret.

2

Browser encrypts client-side

The browser creates fresh key material and encrypts the note with XChaCha20-Poly1305 before upload.

3

Ciphertext is stored on the server

Only the encrypted blob is sent. The decryption key stays in the URL fragment, which the server never receives.

4

Recipient decrypts in browser

Opening the link reconstructs the key from the URL fragment and decrypts the content locally.

Security modes

open

X25519 + HKDF-SHA-256 + XChaCha20-Poly1305

Shorter links for everyday private notes, handoffs, and one-time instructions.

sealed

ML-KEM-1024 + X25519 + HKDF-SHA-256 + XChaCha20-Poly1305

Hybrid post-quantum envelope encryption for longer-lived recovery material.

Threat model