In-page macro
Insert a Secret Note element with /Secret Note or the macro browser, like a divider or info panel, and configure it inline on the page.
Keep passwords, tokens, certificates, private keys, and other sensitive content out of Confluence page bodies, version history, search, and exports.
Created → reveal attempted → revealed → revoked
Teams still paste credentials, one-time passwords, temporary tokens, certificate passphrases, and private operational notes into runbooks, onboarding pages, and infrastructure wikis because it is convenient in the moment. Once typed into a page, that plaintext spreads into version history, the search index, and PDF/Word/space exports.
Secret Notes gives that workflow a safer place inside Confluence: you insert a Secret Note element on the page, the page keeps only an opaque reference, and the plaintext is stored separately and revealed through controlled actions.
Insert a Secret Note element with /Secret Note or the macro browser, like a divider or info panel, and configure it inline on the page.
Make a note revealable by anyone who can view the page, restrict it to selected users and groups, or limit it to yourself. Guests are blocked unless you opt in.
Choose read-once self-destruction, 1-hour, 24-hour, or 7-day expiry, or no expiry. Every secret-store write also has a 365-day hard backstop.
Secrets are not displayed by default; readers see a sealed card. Read-once notes require extra confirmation before the first and only reveal.
Each secret is bound server-side to exactly one page. Copying the page carries only a dead reference, never the secret itself.
Track created, reveal attempted, revealed, rotated, expired, and revoked events without storing plaintext in audit records.
Designed to keep the sensitive workflow inside Atlassian infrastructure and avoid unnecessary vendor-side exposure.
Read full Security & Privacy details →Secret Notes reduces secret leakage in Confluence pages, but it is not a replacement for your central password manager or vault. If a user copies a revealed secret, that plaintext enters the operating-system clipboard and may be retained by clipboard managers or sync tools.
The app warns users about clipboard handling because that boundary exists outside the Forge iframe.
Secret Notes for Confluence is launching soon on the Atlassian Marketplace as a paid app, with a free trial and free use for 1–10 user instances. The docs and the full security details are already published, so you can evaluate it before the listing goes live.