Secure credential handover between agency and client
The moment every project ends with a risk
At the end of a web project, there is an inevitable handover: hosting credentials, CMS logins, API keys, DNS access, social media accounts. Agencies go through this routine dozens of times a year. And most of the time, credentials travel via email, Slack, or a Google Doc — none of which are secure channels.
This is the window where data gets exposed. An email with a password sits in two inboxes, possibly on mobile devices, in sent folders, and in email provider archives. If either party's account is compromised later, those credentials are still there to be found.
What a secure handover looks like
A professional credential handover has a few properties:
- One-way delivery — the credentials are shared once, retrieved once, then gone
- No persistent copies — nothing lingers in inboxes or chat logs
- Verification — the client confirms they received access before the link expires
- Audit trail — the agency knows when the link was opened
A one-time encrypted link covers all of these. You create a link containing the credentials, set an expiry window (24 or 48 hours is typical for handovers), send it over email or a project management tool, and once the client opens it the data is gone.
Structuring the handover
For large projects with many credentials, avoid cramming everything into one link. Instead, group credentials logically:
- Hosting panel — one link for server/hosting access
- CMS login — a separate link for the admin account
- Domain / DNS — registrar credentials sent independently
- Third-party services — social, analytics, payment gateways each in their own link
This makes it easier for the client to confirm receipt of each category and for you to resend if a link expires before being opened.
Practical tips for agencies
Set a short expiry. 24 hours is enough for a scheduled handover. It limits exposure if the email is delayed or the client accidentally ignores it.
Use a subject line that prompts action. "Your project credentials — link expires in 24 hours" gets opened faster than "Handover documents."
Document what was shared, not the credentials themselves. Keep an internal record of which systems were handed over and when, without storing the actual passwords.
Change agency-side access after handover. Once the client has their own credentials, revoke any shared accounts the agency used during the project.
Why this matters beyond security
Clients notice how you handle their data. An agency that sends credentials via a professional, encrypted one-time link signals competence and care. It is a small detail that contributes to trust — and trust is what earns referrals and repeat business.
Agencies subject to GDPR or working with clients in regulated industries also reduce their own liability. A documented, secure handover process is far easier to defend in an audit than "we sent it by email."
Getting started
PassTransfer makes this straightforward. Create a link, paste in the credentials, set an expiry, and send. The client opens it once, and the data is gone. No account required for the recipient, no software to install. For a closer look at the full workflow, see PassTransfer for agencies and web teams.