Thanks. HTTPS is now live. :)
one of the comments of the question here: http://stackoverflow.com/questions/499591/are-https-urls-enc...
says: "It's probably a bad idea to put confidential data in the URL anyway. It will be displayed in the browser's address bad too, remember? People don't like it if their password is visible to anyone who happens to glance at the screen"
you can just display a form with an input field for the secret key, which will be HTTP POSTed and only THEN you should display the account's data (while the url doesn't disclose the secret key)