Exchange a password or short secret with RSA-OAEP (4096-bit) fully offline.

This stays in your browser. Share only the public key.

Send this to the Sender.
Keep this only for you. Do not share with anyone.
Ask the Sender to send you his 'Encrypted payload'.
Do NOT share with anyone.