Get a free website with any plan

See how
ACCOUNT & SECURITY

Sharing credentials with support securely

When our support team is helping you with a transfer, a server move, or anything that needs your login to a third-party system (cPanel, WordPress, a registrar, an old web host), we sometimes need credentials. Don't paste them into the ticket message body. Use the secure share panel instead.

Why not just paste in the message

Anything you type into a support ticket sits in your account history forever. If your portal account is ever compromised, or you forward the email notification to someone else, or you take a screenshot to share with a teammate — every set of credentials you ever sent is right there, in plain text.

How to share securely

Every ticket form in the portal has a "Share credentials securely" panel below the message field. It's collapsed by default — click to expand:

  • What's this for? — a label so the agent knows what the creds are. Optional but helpful (e.g. "WordPress admin for the migration").
  • Username — optional.
  • Password / secret value — the actual sensitive bit. Pasting is fine.
  • Notes — instructions, context, special steps. Encrypted alongside the password.
  • Self-destructs after — pick how long the share stays valid. Default is 3 days. Maximum is 30.

When you submit the ticket (or reply), we encrypt the credentials at rest, generate a one-time link, and attach it as an internal staff note on your ticket. The link never appears in the ticket conversation you can see — only support staff with admin access can view it.

What the support agent sees

Your ticket message + an internal staff-only note containing the link to the encrypted credentials. When they click it, they're shown the values once, copy what they need, and continue your support session.

We log every view (timestamp, count). After the timer expires, the encrypted material is permanently destroyed — even we can't recover it.

What if I need to share more credentials later

Same panel exists in the reply form on every ticket. You can attach as many separate credential bundles as the conversation needs. Each one has its own timer.

Things to know

  • Use the secure panel even for "small" credentials. API tokens, recovery codes, IMAP passwords — anything sensitive belongs there, not in the message.
  • Clear your clipboard after pasting into the panel. Most operating systems keep clipboard history.
  • Don't email credentials. Email is even worse than the ticket body — it's stored in plain text on multiple servers and rarely encrypted at rest.
  • 30 days is the maximum lifetime. If you need long-term storage, use a password manager (1Password, Bitwarden, etc.) — secret-share isn't a vault.

What if my portal account is compromised

A compromised portal account would let an attacker view any unexpired credentials shared with us — same risk as if they read your ticket history. We strongly recommend turning on two-factor authentication so this never happens.

CAN'T FIND IT?

Real humans answer fast.

Hosting with us? Open a ticket and a real person replies - no scripts, no upsells. Still choosing a host? The same team is included with every plan, from day one.