Nice approach to sharing the key! I didn't know the the part after # in a URL doesn't get send to the server. Everything makes much more sense now. :D
While that is technically true, please know that it is not true in a way that is meaningful for many threat models. The JavaScript running on the page can trivially detect, inspect, and log changes to the location hash.
More information here:
https://developer.mozilla.org/en-US/docs/Web/API/WindowEvent...
I agree with your comment. I just don’t want anyone to think that a key stored in the location hash is somehow truly protected from ever getting back to the server, which was how the comment to which I responded sounded to me.