Overview
Secret Notes for Confluence lets users store sensitive content inside a Confluence page without putting plaintext secrets into the page body, version history, search index, or exports.
Use it for temporary passwords, access tokens, certificate passphrases, private keys, or similar sensitive content that needs to stay linked to a runbook, onboarding page, or operational wiki in Confluence.
Where to find it
Secret Notes is an in-page element (macro), not a separate panel. You add it to a page wherever you would add a divider, info panel, or table.
- Slash command: while editing a page, type
/Secret Noteand select it. - Macro browser: use the insert (+) menu in the editor and search for “Secret Note”.
Create a secret note
- Edit the page and insert the Secret Note element.
- Enter a clear label, such as “Production API token” or “TLS certificate passphrase”. The label is shown on the sealed card.
- Paste or type the secret content.
- Choose who can reveal the note.
- Choose an expiry policy.
- Save the configuration and publish the page.
On publish, the page stores only an opaque reference id. The label and the secret content are stored separately in Forge — the label and metadata in Forge KVS, and the secret plaintext in the Forge Secret Store.
Access modes
Default mode. Anyone who can already view the page can reveal the note. Page permissions and restrictions form the first access floor. You can optionally allow external guests who can view the page to reveal it.
Choose specific users and/or groups that may reveal the note. Everyone else who can view the page sees a sealed card they cannot open.
Only the creator can reveal the note. No one else who can view the page can open it.
External and guest collaborators are blocked by default. They can reveal a note only when the creator explicitly allows guests on a page-viewers note. Anonymous users are always blocked from reveal access.
Expiry policies
The note self-destructs after the first successful reveal. Read-once notes require confirmation before reveal. This is the default.
The note remains revealable for 1 hour, then expires.
The note remains revealable for 24 hours, then expires.
The note remains revealable for 7 days, then expires.
The note remains until revoked manually. As a defense-in-depth backstop, the secret-store payload still has a maximum platform TTL of 365 days.
Reveal a note
- Open the page and find the sealed Secret Note card.
- Click Reveal.
- For read-once notes, confirm that you understand the note will self-destruct after reveal.
- Use Hide when you no longer need the plaintext on screen.
If you copy a revealed secret, it enters your operating-system clipboard. Clear your clipboard when you are done, especially if you use clipboard history or sync tools.
Replace a secret
The creator can replace (rotate) the secret stored in an existing note from the note's configuration. Leave the secret field blank to keep the existing value; enter a new value to replace it.
Expiry can only change when you replace the secret. Replacing rotates the stored payload and records a rotated event in the audit trail.
Revoke a note
Creators can revoke their own notes at any time. A revoked note cannot be revealed again, and the secret is destroyed immediately — including when a Marketplace subscription has lapsed.
Use revoke when a secret should no longer be available, when the wrong audience was selected, or when the secret has been rotated elsewhere.
Copying and moving pages
Each secret is bound server-side to exactly one page.
- Copying a page carries the opaque reference onto the copy, but the app refuses to reveal it there because the copy is a different page. A copied reference is a dead link, not a leak.
- Moving a page keeps the same page identity, so the note stays revealable for authorized users.
- Deleting a page purges the secrets bound to that page. The 365-day secret-store backstop covers any gap.
Audit trail
Secret Notes keeps a metadata-only audit trail. Audit events do not include secret plaintext.
- created
- reveal attempted
- revealed
- rotated
- expired
- revoked
The creator can see the audit history for their own notes.
Limits
- Secret payload
- 10 KB maximum
- Note label
- 120 characters maximum
- Notes per page
- 20 active notes maximum
- Reveal attempts
- 20 per actor per note
- Restricted users/groups
- 50 users and 50 groups maximum per note
- Audit events
- 100 retained per note
- Secret Store TTL backstop
- 365 days maximum
Troubleshooting
I cannot reveal a note.
You may not be in the note's reveal audience, the note may be expired/revoked/self-destructed, or you may be viewing a copy of the page rather than the original the secret is bound to.
A read-once note says self-destructed.
The note has already been successfully revealed once. Read-once notes cannot be revealed again.
A note shows as relocated or unavailable on a copied page.
Secrets are bound to a single page. When a page is copied, the copy carries the reference but cannot reveal it. Recreate the note on the new page if you need a secret there.
A guest or external collaborator cannot reveal a note.
Guests are blocked by default. They can reveal only when the creator enables “Allow guests” on a page-viewers note. Anonymous users are always blocked.
I copied a secret. What should I do?
Paste it only where intended, then clear your clipboard if your operating system or tools keep clipboard history.
Need help?
For support, bugs, privacy questions, or Marketplace review questions, open a support ticket.