Security

How Should Clients Share Hosting and Domain Access With an Agency?

Add the agency as a user where you can, and for hosting, registrar, and database logins that have no user model, send them through an end-to-end encrypted link, never by email or chat. Here's how to decide, access by access.

Add the agency as a user wherever the platform allows it, so access is revocable and no password changes hands. For hosting, registrar, and database logins that have no user model, send those through an end-to-end encrypted link the agency provides, not by email or chat. Then remove access or rotate the shared logins when the work is done.

Why the channel matters as much as the access

Handing an agency access is normal. Handing it over in a way you can't take back is the problem. A hosting password pasted into email or a chat thread stays there, in plaintext, in backups neither side controls, long after the project ends. The goal is access the agency can use now and you can cleanly withdraw later.

Delegate where you can

For anything with a user or invite model, add the agency rather than sharing your login:

  • Your CMS (WordPress and most others): create a user for them.
  • Analytics and Search Console: add their email.
  • Most SaaS tools: invite them to a seat.

You keep ownership, and removing them later is one click, with nothing to reset.

Share securely what you can't delegate

Some logins have no per-user option, so the agency needs the actual credential:

  • Hosting or cPanel
  • Domain registrar and DNS
  • Database credentials
  • Older or custom CMS admin logins

These should travel through an encrypted link, not a message, and get rotated when the engagement ends.

How the options compare

MethodRevocable without a reset?Lives in inboxes / chat you don't control?Safe for hosting & registrar logins?
Add the agency as a userYesNoNot applicable (no login shared)
Encrypted upload linkYes (rotate after)NoYes
Email or Slack the passwordNoYesNo
Shared Google DocNoYesNo

A simple rule of thumb

If the platform can add a user, add the user. If it can't, send the login through an encrypted link and change it when the work is done. Nothing sensitive should end up in email, chat, or a shared doc.

Where doconvoy fits

When an agency uses doconvoy, the non-delegatable logins come to you through an encrypted request instead of a chat message. You open a page in the agency's name, enter the hosting or registrar login, and it's encrypted on your device before it's sent. For the agency's side of this, see how to collect website logins from clients securely.

Send hosting, registrar, and database logins through an encrypted link, not email or chat.

Share website access safely

Related: How to collect website logins from clients securely · What access does a web developer need from a client? · Client onboarding for web agencies · How to revoke access after you shared it

Common questions

What's the safest way to give a web agency access to my site?

Add them as a user wherever the platform allows it, so you can remove them later without changing anything. For hosting, registrar, or database logins that have no user option, send those through an end-to-end encrypted link the agency provides, not by email or chat.

Is it safe to email my hosting or cPanel password to an agency?

No. An emailed password sits in both inboxes and their backups with no expiry, and you can't tell who else saw or forwarded it. Use an encrypted link, and change the password when the project ends.

Should I give the agency my domain registrar login?

Only if they need DNS or transfer control, and only through a secure channel. Where the registrar supports delegated or sub-account access, use that instead of the main login, and reclaim it when the work is done.