Table of Contents
collect client credentials safelyclient login sharingwebsite access credentialssecure credential collection agency

How to Collect Client Logins and Credentials Safely During a Website Project

6 min read
How to Collect Client Logins and Credentials Safely During a Website Project

The Problem with How Agencies Collect Client Credentials

Ask any web agency how they collect client passwords and you will get one of three answers: email, WhatsApp, or a spreadsheet. All three are wrong.

Client credentials are among the most sensitive data an agency handles. A hosting login, a domain registrar password, or a Google Workspace admin account gives whoever holds it significant power over a business's digital infrastructure. When these credentials are collected insecurely, the consequences -- account takeovers, data breaches, ransomware -- fall on the client, but the reputational damage falls on the agency.

This guide explains the correct way to collect client logins and platform access during a website project.


Why Email Is the Wrong Tool for Sharing Credentials

Email is not encrypted end-to-end in most implementations. A password sent over email can be:

  • Intercepted in transit if the email server is compromised
  • Accessed by anyone with access to the client's email account
  • Forwarded accidentally to the wrong person
  • Stored indefinitely in both sender and recipient inboxes
  • Exposed in a data breach at the email provider level

Despite this, the majority of web agencies still ask clients to send passwords via email. This is not just a security risk -- it is a professional liability. If a client's hosting account is compromised after they emailed you the password, the agency is in a difficult position.


The Hierarchy of Credential Collection: Safest First

Not all access methods carry the same risk. Where possible, use the most secure option available.

1. Platform Invitations (Most Secure)

Most platforms now support role-based access through invitation:

  • WordPress: Add the agency as an Administrator via Users > Add New
  • Shopify: Grant Partner access through the Shopify Partners programme
  • Google Analytics: Share view or edit access through User Management
  • Google Search Console: Add a property user
  • Cloudflare: Create a Team member invitation
  • cPanel/WHM: Create a reseller or sub-account

With platform invitations, the client never has to share their password. The agency receives access under their own credentials and the client can revoke it at any time. This is the gold standard.

2. Dedicated Credential-Sharing Tools (Secure)

When a platform does not support invitations, use a tool specifically designed for secure credential sharing:

  • 1Password for Teams -- generates one-time share links that expire
  • Bitwarden -- open-source, shareable vaults
  • NordPass Business -- business credential sharing with audit logs
  • Onboard -- built-in credential collection step within the client portal, stored encrypted and accessible only to the agency team

These tools encrypt credentials at rest and in transit, provide access logs, and allow revocation after a project ends.

3. Secure Form with Encryption (Acceptable)

A password-protected form that submits credentials over HTTPS and stores them encrypted in a database is significantly better than email. Tools like Onboard handle this natively, providing clients with a structured step in their client onboarding portal where they can submit credentials securely.

4. Phone Call (Last Resort)

If a client is non-technical and cannot use any of the above, a phone call where credentials are verbally communicated -- and immediately recorded in a password manager -- is preferable to written communication over email or messaging.


What Credentials to Collect (And When)

Not every project requires every credential. Collect only what you need, when you need it.

Domain access

  • Domain registrar login (GoDaddy, Namecheap, 123-Reg, Google Domains)
  • DNS management access
  • Needed for: pointing domains, setting up email records, SSL configuration

Hosting access

  • cPanel or hosting control panel login
  • FTP/SFTP credentials
  • Database access (MySQL, phpMyAdmin)
  • Needed for: deploying files, migrating sites, server configuration

CMS access

  • WordPress admin login
  • Shopify admin login
  • Webflow account access
  • Needed for: building, updating, or migrating website content

Email and DNS

  • Google Workspace admin
  • Microsoft 365 admin
  • Needed for: email configuration, SPF, DKIM, DMARC records

Analytics and tracking

  • Google Analytics admin access
  • Google Tag Manager access
  • Needed for: tracking setup, data migration, reporting

Third-party integrations

  • Payment gateway (Stripe, PayPal)
  • CRM (HubSpot, Salesforce)
  • Email marketing (Mailchimp, Klaviyo)
  • Needed for: connecting tools, data migration, testing

How to Ask Clients for Credentials Without Confusion

Many clients are understandably hesitant to share access to business-critical accounts. How you ask matters.

Be specific. Tell the client exactly which platform, exactly which type of access, and exactly what you will use it for. "We need your GoDaddy login to update the DNS records so your new website goes live" is better than "we need your domain access."

Explain the method. Tell the client how you will be collecting the credential. If you are using a secure portal, explain why it is safer than email.

Reassure with policy. A brief sentence about your credential handling policy builds confidence: "We store all client credentials in an encrypted password manager, access is limited to the team members working on your project, and all access is revoked on project completion."

Use a structured workflow. A client portal that presents credential collection as a named step in the client onboarding process -- alongside contract signing and brand asset upload -- normalises the process and reduces friction.


After the Project: Revoking Access

Collecting credentials is only half the process. Revoking access after a project ends is equally important.

  • Remove agency team members from platform invitations
  • Change any shared passwords once work is complete
  • Confirm in writing to the client that access has been removed
  • Document the revocation date in your records

Agencies that do not have a formal offboarding process often retain access to client accounts years after projects end -- a liability for both parties.


Frequently Asked Questions

Is it illegal for an agency to store client passwords? In the UK, storing client credentials is subject to UK GDPR. Credentials must be stored securely (encrypted), only for as long as necessary, and with appropriate access controls. Storing passwords in plaintext or in email threads likely constitutes a breach of your data processing obligations. Your service agreement should include a data processing clause that explicitly covers how client credentials are handled and stored.

What should an agency do if a client insists on sending credentials by email? Acknowledge receipt, immediately transfer the credential to a password manager, delete the email, and notify the client that you have moved it to secure storage. Document the fact that the client sent credentials via email despite your recommended process.

Can we share a single agency password manager vault with all client credentials? Yes, but use separate vaults or collections per client and restrict access to only the team members on that client's project. Mixing all client credentials into a single shared vault without access controls is a significant risk.

Should we ask clients to change passwords after project completion? Yes. After the project ends, ask clients to update any passwords they shared with you. Even if you have deleted your copy, this is good practice and demonstrates security awareness.

Share this post

Ready to fix your onboarding?

Join 500+ agencies who have replaced email threads and spreadsheets with Onboard. Start your 30-day free trial, no card needed.