Get a free website with any plan

See how
ACCOUNT & SECURITY

Sharing credentials with support securely

Last updated

IN SHORT

Flashcloud's secure share panel lets you send login credentials to support without pasting them into a ticket. Fill in the username, password, and notes, set a self-destruct timer (1 to 30 days), and support gets a one-time encrypted link instead of plain text in your ticket history.

When our support team is helping you with a transfer, a server move, or anything that needs your login to a third-party system (cPanel, WordPress, a registrar, an old web host), we sometimes need credentials. Don't paste them into the ticket message body. Use the secure share panel instead.

Why not just paste in the message

Anything you type into a support ticket sits in your account history forever. If your portal account is ever compromised, or you forward the email notification to someone else, or you take a screenshot to share with a teammate — every set of credentials you ever sent is right there, in plain text.

How to share securely

Every ticket form in the portal has a "Share credentials securely" panel below the message field. It's collapsed by default — click to expand:

  • What's this for? — a label so the agent knows what the creds are. Optional but helpful (e.g. "WordPress admin for the migration").
  • Username — optional.
  • Password / secret value — the actual sensitive bit. Pasting is fine.
  • Notes — instructions, context, special steps. Encrypted alongside the password.
  • Self-destructs after — pick how long the share stays valid. Pick anywhere from 1 to 30 days.

When you submit the ticket (or reply), we encrypt the credentials at rest, generate a one-time link, and attach it as an internal staff note on your ticket. The link never appears in the ticket conversation you can see — only support staff with admin access can view it.

What the support agent sees

Your ticket message + an internal staff-only note containing the link to the encrypted credentials. When they click it, they're shown the values once, copy what they need, and continue your support session.

We log every view (timestamp, count). After the timer expires, the encrypted material is permanently destroyed — even we can't recover it.

What if I need to share more credentials later

Same panel exists in the reply form on every ticket. You can attach as many separate credential bundles as the conversation needs. Each one has its own timer.

Things to know

  • Use the secure panel even for "small" credentials. API tokens, recovery codes, IMAP passwords — anything sensitive belongs there, not in the message.
  • Clear your clipboard after pasting into the panel. Most operating systems keep clipboard history.
  • Don't email credentials. Email is even worse than the ticket body — it's stored in plain text on multiple servers and rarely encrypted at rest.
  • 30 days is the maximum lifetime. If you need long-term storage, use a password manager (1Password, Bitwarden, etc.) — secret-share isn't a vault.

What if my portal account is compromised

A compromised portal account would let an attacker view any unexpired credentials shared with us — same risk as if they read your ticket history. We strongly recommend turning on two-factor authentication so this never happens.

Common questions

Why can't I just paste my password into the support ticket?

Anything typed into a ticket stays in your account history forever. If your portal account is compromised, or the notification email gets forwarded or screenshotted, every credential you ever sent is sitting there in plain text.

How long do shared credentials stay available?

You pick the self-destruct window when you submit them. Anywhere from 1 to 30 days. After the timer runs out, the encrypted material is permanently destroyed and even Flashcloud can't recover it.

Can support staff see my credentials in the ticket thread?

No. The link is attached as an internal staff-only note, not the visible conversation. Only support staff with admin access can open it, and they see the values once before continuing your support session.

What if I need to send more than one set of credentials?

Use the same panel in the reply form, on this ticket or a new one. You can attach as many separate credential bundles as the conversation needs, and each one gets its own self-destruct timer.

Is it safe to use the secure panel for small things like API tokens?

Yes, and you should. API tokens, recovery codes, and IMAP passwords are all sensitive enough to belong in the secure panel, not typed into the message body.

CAN'T FIND IT?

Real humans answer fast.

Hosting with us? Open a ticket and a real person replies - no scripts, no upsells. Still choosing a host? The same team is included with every plan, from day one.