\n

Hosting & Website Access

How can I securely provide login details?

Practical ways to provide the access needed for a website project while reducing unnecessary exposure of your main account credentials.

The safest method is usually to avoid sharing your main password at all. Use a separate user or delegated-access feature when the provider supports one.

Preferred access options

  1. Separate or delegated user. Give the new user only the permissions required for the website task.
  2. Temporary credentials. If the provider does not support another user, create a temporary password where practical and change it after the work.
  3. Secure password-sharing method. If a password genuinely has to be shared, use a secure method agreed for the project rather than ordinary email, SMS, chat, a public Help Centre form or a URL.

Share only what is needed

Do not send unrelated passwords or access to services that are not part of the work. Where permissions can be limited, use the smallest set of permissions that allows the requested task to be completed.

Revoke access when it is no longer needed

Temporary passwords can be changed and separate users can be removed or disabled when the work requiring that access is complete.

If you are unsure whether your host supports additional users, see Can I create a separate hosting login for Toolbelt Websites?.

Independent security guidance

The UK National Cyber Security Centre recommends password managers and notes that delegated privileges or alternative authentication are preferable to sharing passwords where those options are available.

View NCSC password-manager guidance ↗

Last updated: 8 September 2026