How to share a password safely
When you absolutely must share a password with our team, here is the right (and wrong) way to do it.
- Time
- 5 minutes
- Difficulty
- Beginner
While we always prefer delegate access (inviting support@chykalophia.com as a user), some older systems or specific domain registrars force you to share a single master password.
If you must share a password with our team, never send it in plain text via email, Slack, or text message. Once a plain-text password is sent via email, it sits in your sent folder and our inbox indefinitely, creating a major security risk.
Quick summary
To share a password safely, use a self-destructing link service like Onetime Secret, or the secure sharing feature in a password manager like 1Password or Bitwarden. Send the username and the secure password link separately.
The right way to share a password
To protect your business, please follow these steps to securely transmit a password to the Chykalophia team.
Use a secure sharing tool. Go to a free service like Onetime Secret or Bitwarden Send. If you already use 1Password, open the item, choose Share, and copy the link it gives you.
Enter the password. Type or paste only the password into the box for the secret. Do not include the username or the website URL in it.
Generate the link. Click the button to create your secret link. Onetime Secret is built for exactly one view: it says that after a single view "the secret is permanently purged from all storage". Bitwarden Send and 1Password let you choose when the link expires, and Bitwarden Send can also cap how many times it may be opened — worth setting if you want the same read-once behavior.
Send us the link and login URL. Head over to your ClickUp task or your email thread with us. Provide the login URL and the username in plain text, and paste the secure link for the password.
Example of a secure message to our team:
"Here are the logins for our GoDaddy account. URL: godaddy.com Username: mybusiness@gmail.com Password: [Link to Onetime Secret]"
What happens next?
With a one-time link, the password is revealed to us the first time we open it and then deleted at the other end — Onetime Secret describes it as "no copies, no recovery, no trace". We copy the password straight into our encrypted, internal password manager. Anyone else who opens the link afterwards finds nothing there.
Common questions
I already emailed you a password in plain text. What should I do?
Don't panic, but please log in to that service immediately and change your password to something new and strong. Once changed, use the secure method above to share the new password with us.
Can I just text it to my project manager?
No. SMS text messages are not encrypted end-to-end and are not a secure way to transmit business credentials. Please use a one-time secure link.
Related guides
- Why we ask for access (and why it's safe)
- Delegate access vs. sharing a password
- How we keep your logins safe
- How to revoke our access later
- Access checklist for a new project
Need a hand?
Last updated