How to Share a Password Securely
Before You Share a Password
Share a password only when another person truly needs temporary access and the service does not offer a safer option. For example, some accounts let you invite another user, assign a role, create a family member profile, or give an employee limited permissions. Account-specific access is preferable because each person has separate credentials, access can be removed without changing your password, and activity may be easier to identify.
Confirm the recipient’s identity before sending anything. If the request arrived unexpectedly, contact the person through a different method you already trust. Do not rely only on a display name, profile picture, or message from a new account. A criminal may impersonate a coworker, friend, relative, or support representative.
Never share a password because someone creates urgency or asks you to bypass normal procedures. Legitimate support staff generally should not need your password. If a person claims to represent a service, stop and open the service’s official website yourself. Find its Help, Support, or Contact page and use a verified channel listed there.
Choose a Secure Sharing Method
If sharing cannot be avoided, use a method designed to protect secrets. An encrypted password manager with a sharing feature is often suitable. Check that you selected the intended recipient and the correct account entry before confirming. If the tool offers limited access, an expiration date, or the ability to revoke sharing, use those controls.
A one-time secret link is another option when permitted by your organization. It should reveal the password only once or expire after a short period. Send it directly to the verified recipient, and confirm separately that the right person received it. Do not copy the revealed secret into another message afterward.
At work, follow the organization’s approved system and security policy. The approved tool may provide access controls, audit records, and a way to remove access. Do not move a company password into a personal password manager or an unfamiliar secret-sharing website merely because it seems convenient.
When deciding how to share a password securely, consider what happens after you send it. Choose a method that limits who can view the secret, how long it remains available, and whether you can withdraw access.
Avoid Unsafe Channels
Do not send passwords through plain text messages, ordinary unencrypted email, public chat rooms, or social media messages. Messages can be forwarded, displayed in notifications, included in backups, synchronized to other devices, or seen by anyone who gains access to an account or unlocked phone.
Shared documents, spreadsheets, notes, and project boards are also poor places for passwords. Their access settings can change, links can reach unintended people, and old copies may remain after the password is supposedly removed. A private-looking group chat is not a secure vault either.
Avoid taking a screenshot or photo of a password. Images may be saved automatically, uploaded to cloud storage, or displayed in a photo gallery. Do not read a password aloud where other people or recording devices may hear it.
If no approved secure method is available, pause instead of choosing an unsafe channel. Ask the account owner or organization’s security contact for an approved way to grant access.
Share Only the Required Information
Limit what the recipient receives. Share only the credential needed for the specific task, not a list of passwords or a full account profile. Never include answers to security questions, recovery codes, payment information, identification numbers, or unrelated personal details.
When appropriate, send the username and password through separate secure methods. This does not make weak channels safe, but it reduces the amount of useful information exposed in one place. Do not label a message with the service name, account purpose, username, and password together.
Use a unique temporary password if the service permits it. Do not share a password that you also use on another account. Password reuse means exposure of one credential can place several accounts at risk.
Tell the recipient exactly what access is allowed and when it ends. Ask them not to save the password in a browser, copy it into notes, forward it, or share it with anyone else. These limits are central to how to share password securely without exposing more information than necessary.
Protect the Account After Sharing
Change a temporary password as soon as the recipient finishes. Use a new, unique password rather than returning to an older one. If you granted access through a password manager or organizational system, revoke that access when it is no longer required.
Review the account’s security or device settings. Look for sections commonly labeled Active Sessions, Devices, Recent Logins, Security Activity, or Connected Apps. Sign out sessions you do not recognize and remove devices or applications that no longer need access.
Enable multi-factor authentication when the account offers it. Keep recovery codes in a protected location, and do not give them to the person receiving the password. Multi-factor authentication adds another check, but it does not make careless password sharing safe.
Check recovery email addresses, phone entries, forwarding rules, and other account settings after sensitive access has been shared. Make sure nothing was changed unexpectedly. For ongoing collaboration, replace the shared login with individual user access if that option becomes available.
What to Do If a Password Was Exposed
Act immediately if a password was sent through an unsafe channel, posted publicly, viewed by the wrong person, or entered on a suspicious page.
- Change the password from a trusted device. Create a new password that is unique to that account.
- Sign out all other sessions if the service provides that option. Then remove unknown devices and connected applications.
- Review recent account activity, login history, messages, profile changes, and recovery settings. Record anything you do not recognize.
- Change the password on any other account where the exposed password was reused. Give the most sensitive accounts priority.
- Enable multi-factor authentication and replace any recovery codes that may also have been exposed.
- Contact the service through verified channels if you cannot sign in or see suspicious activity. Open the official website yourself and locate its Help, Support, Security, or Contact section.
Do not follow contact instructions included in a suspicious message. Keep relevant alerts or screenshots for your records, but make sure they do not reveal the new password or recovery codes.