An end-to-end encrypted pastebin that encrypts content in the browser using XChaCha20-Poly1305 and Argon2id before upload. The decryption key stays in the URL fragment and never reaches the server, with no opt-out: every paste is always encrypted.
paaster takes the same zero-knowledge approach as PrivateBin but builds on more modern primitives: libsodium’s XChaCha20-Poly1305 secretstream with Argon2id key derivation, the same stack as VERNAM. Encryption is not a mode to enable - it is the only mode. Paste history, delete-after-view, and QR sharing are built in, and the project deliberately avoids dynamically loaded third-party scripts. It is a smaller, younger project than PrivateBin with fewer public instances; self-hosting is the most reliable path. A solid choice for anyone who wants the strongest available browser-side encryption on their pastes.
Listed in
paaster alternatives
Free to use, even commercially. Changes must be published under the same license, and running a modified version as a network service counts as distributing it.
Permits
- Commercial use
- Modification
- Distribution
- Patent use
- Private use
Requires
- Disclose source
- Network use is distribution
- Same license
- State changes
- License and copyright notice
Does not provide
- Liability cover
- Warranty
Why it matters: The network clause is the point. Anyone who runs a modified version as a hosted service has to publish those changes, so the code handling your data stays inspectable. This is why privacy-first projects reach for AGPL.
Plain-language summary of the project's license, not legal advice. Read the full text for the exact terms.