Skip to content

Use case: secure password sharing for hosting companies

P
PassTransfer
Published April 9, 20244 min read

Hosting companies handle more credentials per customer than almost any other type of service business. From initial account provisioning through ongoing support interactions, credentials are constantly being created, reset, and delivered. This use case walk-through shows how PassTransfer fits into a hosting company's operations.

The credential delivery problem at scale

A mid-sized hosting company with 2,000 customers might handle several hundred credential-related support interactions per month: new account provisioning, password resets, FTP credential creation, database access setup, email account configuration. Each of these requires delivering credentials to a customer.

The traditional approach — emailing credentials in plain text — creates risk and inefficiency:

  • Customer inboxes accumulate old credentials that may no longer be valid but represent a historical exposure
  • Support staff must send separate emails for each credential type
  • Customers who use the same password across systems (common despite advice against it) are exposed if one credential is compromised via an email breach
  • Regulatory and compliance scrutiny is increasing on how hosting companies handle customer data

Scenario 1: New account provisioning

When a customer signs up, they need their control panel credentials, perhaps FTP access, and often a database password. The traditional flow sends all of this in a welcome email.

With PassTransfer's API, a hosting company can automate this:

  1. Account is provisioned in the backend system
  2. Provisioning script calls the PassTransfer API to create a one-time link containing the credentials
  3. Welcome email is sent to the customer containing the link (not the credentials)
  4. Customer clicks the link, receives their credentials once, saves them to their password manager
  5. Link expires — the credentials are no longer accessible via that link

The customer email now contains only an expired URL. Even if that email is later compromised, there's nothing useful in it.

Scenario 2: Support-triggered password reset

A customer contacts support: they've forgotten their FTP password. The support technician generates a new password and needs to deliver it securely.

With PassTransfer, the technician:

  1. Opens PassTransfer (or uses the API via their support tool integration)
  2. Creates a link containing the new FTP credentials
  3. Pastes the link into the support ticket or support chat
  4. The customer clicks, retrieves their new credentials, and the link becomes inactive

The support ticket is no longer a credential repository. Six months later, if someone reviews that ticket, they see a link — but the link is long expired and contains nothing.

Scenario 3: Developer/agency access for customers

Customers often ask their hosting company to share credentials with their web developer or agency. Instead of the developer requesting credentials directly — creating confusion about authorization — the process can be structured:

  1. Customer authorizes the credential share via a support request
  2. Support creates a PassTransfer link with a 48-hour expiry
  3. The link is sent directly to the developer
  4. Developer retrieves credentials, link expires

This creates a clean audit trail: the link was created, delivered to a specific email address, and accessed at a specific time. Nobody needs to worry about old credentials sitting in a developer's inbox.

Scenario 4: Branded credential delivery

A hosting company investing in brand differentiation uses PassTransfer Pro to configure a custom subdomain: credentials.hostingbrand.com. Every credential delivery goes through this URL. Customers see the hosting company's domain and logo when they receive their credentials, not a third-party service.

This is particularly effective during account provisioning — the first credential delivery a new customer experiences. It signals that the hosting company has invested in their security infrastructure.

API integration

For hosting companies with custom billing and provisioning systems, PassTransfer's API allows full automation of credential delivery without requiring manual link creation. Credentials can be generated and delivered programmatically as part of existing workflows.

The result is a hosting operation that handles credentials securely at scale, with minimal manual overhead and a significantly improved security posture compared to plain-text email delivery.

Share this article
P
PassTransfer

The team behind PassTransfer writes about secure sharing, compliance and practical security for teams and agencies.

Ready to get started?

Sharing securely takes 10 seconds

Paste your password, pick an expiry time and share the link. Free and without an account.

Share a password