PasswordPusher Hosting

Share sensitive text through links that expire after time or a set number of views.

Order now No setup fees
  • One click deploy
  • 1 GB RAM Memory needed
  • 15 GB Disk Space Needed
  • From 2 € Price

Tech

Docker image
pglombardo/pwpush:latest
Default port
5100

How PasswordPusher works

PasswordPusher creates a unique link for a password, text note, file, or URL, with expiration based on time, view count, or both. Recipients open the link to retrieve the content, and the application records lifecycle events for review. Optional passphrases add another access step when the creator can share that passphrase through a separate channel.

The application also supports secure requests that ask another person to submit sensitive information through a temporary workflow. Requests and pushes have their own expiration and audit behaviour. Expiry removes live application data according to the configured rules, but it does not revoke information already copied by a recipient or remove the need to rotate a shared credential.

Key PasswordPusher features

PasswordPusher is designed for controlled transfer rather than permanent storage. View limits, time limits, audit events, passphrases, files, URLs, and requests help reduce how long sensitive material remains available. Administrators still need a policy for which secrets may be shared and what happens after retrieval.

The hosted service includes scheduled backups as a platform feature, while PasswordPusher expiry governs the live application record. Customers should not market expiry as certified erasure from every possible recovery layer. The hosting service does not provide recipient identity verification, malware scanning, delivery attestation, secret rotation, or a compliance determination for a particular workflow.

Who uses PasswordPusher

IT support teams send temporary setup passwords, consultants transfer access details, and organisations request confidential values without placing them in long-lived tickets. File and URL pushes support related temporary exchanges when the recipient needs more than a short password.

It is not a password manager, identity-verification service, digital-signature platform, or permanent encrypted vault. Shared credentials should be changed after use, and consequential access should be protected with independent authentication and audit controls.

Self-hosting PasswordPusher: requirements and cost

PasswordPusher is storage-driven when file pushes and requests are used. Capacity also depends on concurrent live pushes, attachment size, expiration periods, view counts, audit history, users, requests, and download traffic. PostgreSQL and MariaDB are Not required in the catalogue template, which relies on the application’s own persisted state. PasswordPusher is marked storage-driven in the plan mapping, so 50 GB on Plan 3 is a realistic starting point and 100 GB on Plan 4 provides more room for a large working set.

On AvaHost, PasswordPusher uses Plan 1 at €2. The hosted PasswordPusher package includes one-click deployment, a custom domain with automated HTTPS, automatic application updates, and scheduled backups. Recipient identity verification, malware scanning, delivery certification, secret rotation, email delivery, and compliance assessment are not included. Application email is disabled. Use short expiration, share passphrases separately, rotate credentials after retrieval, and keep only authorised files in the service.

F.A.Q

  • PasswordPusher starts at €2 on Plan 1. Text pushes are light, but file uploads and longer retention can consume storage quickly. Concurrent pushes, attachment size, expiry periods, view limits, requests, audit history, users, and download traffic determine when Plan 3 or Plan 4 is more practical.

  • PasswordPusher is marked storage-driven. Plan 3 provides 50 GB and is a realistic starting point when files are shared regularly, while Plan 4 provides 100 GB for a larger temporary workload. Estimate simultaneous live attachments and leave room for application data, updates, scheduled backups, requests, and files awaiting expiration.

  • Expiration removes the live push according to its time or view rules, but a recipient may already have copied the information. Treat the link as a transfer mechanism rather than permanent access control. Use a separate passphrase channel where appropriate, confirm the intended recipient, and rotate passwords or tokens after they have served their purpose.

  • AvaHost applies PasswordPusher updates automatically and includes scheduled backups for persistent data. After a substantial release, test text pushes, files, URLs, passphrases, view and time limits, audit events, requests, and deletion. Application email is disabled, so verify that no important workflow depends on mail delivery or account recovery.