Runs on Atlassian Confluence Forge Secret Store

Secret Notes for
Confluence.

Keep passwords, tokens, certificates, private keys, and other sensitive content out of Confluence page bodies, version history, search, and exports.

// launching soon on the Atlassian Marketplace · free trial · free for 1–10 user instances · no external services

Secret Notes Confluence page macro
The page stores only an opaque reference. Secret content lives in the Forge Secret Store and is revealed only after an explicit user action.
Production API token Read once · page viewers
TLS certificate passphrase 24h left · restricted to 2 users
Audit trail

Created → reveal attempted → revealed → revoked

// problem

Confluence is not a secret manager.

Teams still paste credentials, one-time passwords, temporary tokens, certificate passphrases, and private operational notes into runbooks, onboarding pages, and infrastructure wikis because it is convenient in the moment. Once typed into a page, that plaintext spreads into version history, the search index, and PDF/Word/space exports.

Secret Notes gives that workflow a safer place inside Confluence: you insert a Secret Note element on the page, the page keeps only an opaque reference, and the plaintext is stored separately and revealed through controlled actions.

// capabilities

Built for sensitive content inside Confluence pages.

In-page macro

Insert a Secret Note element with /Secret Note or the macro browser, like a divider or info panel, and configure it inline on the page.

Reveal controls

Make a note revealable by anyone who can view the page, restrict it to selected users and groups, or limit it to yourself. Guests are blocked unless you opt in.

Expiry policies

Choose read-once self-destruction, 1-hour, 24-hour, or 7-day expiry, or no expiry. Every secret-store write also has a 365-day hard backstop.

Explicit reveal

Secrets are not displayed by default; readers see a sealed card. Read-once notes require extra confirmation before the first and only reveal.

Copy-safe by design

Each secret is bound server-side to exactly one page. Copying the page carries only a dead reference, never the secret itself.

Metadata audit trail

Track created, reveal attempted, revealed, rotated, expired, and revoked events without storing plaintext in audit records.

// security posture

Forge-first, no external backend.

Designed to keep the sensitive workflow inside Atlassian infrastructure and avoid unnecessary vendor-side exposure.

Read full Security & Privacy details →
Runs on AtlassianHosted entirely on Forge. No Forge Remote, no external services, and no third-party telemetry or error-reporting SDKs.
Secret Store onlyPlaintext secret payloads are written only to the Forge Secret Store. They are not written to the page body, version history, search index, exports, normal KVS metadata, logs, or audit events.
Nothing in the pageThe page body stores only an opaque reference id. The secret and its metadata never enter the page, its version history, the search index, or exports.
Server-side authorizationReveal, revoke, visibility, and audit checks run inside Forge resolvers using Atlassian-signed identity. UI-supplied flags are not treated as a security boundary.
Copy-safe page bindingEach secret is bound server-side to exactly one page. A reference carried onto a copied page is a dead link, not a leak.
Lifecycle cleanupExpired and destroyed secrets are cleaned up best-effort, page deletion purges bound secrets, tenant data is purged on uninstall, and user references are scrubbed on Atlassian anonymization events.
// boundaries

Clear about what it does not do.

Secret Notes reduces secret leakage in Confluence pages, but it is not a replacement for your central password manager or vault. If a user copies a revealed secret, that plaintext enters the operating-system clipboard and may be retained by clipboard managers or sync tools.

The app warns users about clipboard handling because that boundary exists outside the Forge iframe.

// launching soon

Free trial, with a small-team free tier.

Secret Notes for Confluence is launching soon on the Atlassian Marketplace as a paid app, with a free trial and free use for 1–10 user instances. The docs and the full security details are already published, so you can evaluate it before the listing goes live.