Security
How Should Clients Share Hosting and Domain Access With an Agency?
Add the agency as a user where you can, and for hosting, registrar, and database logins that have no user model, send them through an end-to-end encrypted link, never by email or chat. Here's how to decide, access by access.
Add the agency as a user wherever the platform allows it, so access is revocable and no password changes hands. For hosting, registrar, and database logins that have no user model, send those through an end-to-end encrypted link the agency provides, not by email or chat. Then remove access or rotate the shared logins when the work is done.
Why the channel matters as much as the access
Handing an agency access is normal. Handing it over in a way you can't take back is the problem. A hosting password pasted into email or a chat thread stays there, in plaintext, in backups neither side controls, long after the project ends. The goal is access the agency can use now and you can cleanly withdraw later.
Delegate where you can
For anything with a user or invite model, add the agency rather than sharing your login:
- Your CMS (WordPress and most others): create a user for them.
- Analytics and Search Console: add their email.
- Most SaaS tools: invite them to a seat.
You keep ownership, and removing them later is one click, with nothing to reset.
Share securely what you can't delegate
Some logins have no per-user option, so the agency needs the actual credential:
- Hosting or cPanel
- Domain registrar and DNS
- Database credentials
- Older or custom CMS admin logins
These should travel through an encrypted link, not a message, and get rotated when the engagement ends.
How the options compare
| Method | Revocable without a reset? | Lives in inboxes / chat you don't control? | Safe for hosting & registrar logins? |
|---|---|---|---|
| Add the agency as a user | Yes | No | Not applicable (no login shared) |
| Encrypted upload link | Yes (rotate after) | No | Yes |
| Email or Slack the password | No | Yes | No |
| Shared Google Doc | No | Yes | No |
A simple rule of thumb
If the platform can add a user, add the user. If it can't, send the login through an encrypted link and change it when the work is done. Nothing sensitive should end up in email, chat, or a shared doc.
Where doconvoy fits
When an agency uses doconvoy, the non-delegatable logins come to you through an encrypted request instead of a chat message. You open a page in the agency's name, enter the hosting or registrar login, and it's encrypted on your device before it's sent. For the agency's side of this, see how to collect website logins from clients securely.
Send hosting, registrar, and database logins through an encrypted link, not email or chat.
Share website access safelyRelated: How to collect website logins from clients securely · What access does a web developer need from a client? · Client onboarding for web agencies · How to revoke access after you shared it
Common questions
What's the safest way to give a web agency access to my site?
Add them as a user wherever the platform allows it, so you can remove them later without changing anything. For hosting, registrar, or database logins that have no user option, send those through an end-to-end encrypted link the agency provides, not by email or chat.
Is it safe to email my hosting or cPanel password to an agency?
No. An emailed password sits in both inboxes and their backups with no expiry, and you can't tell who else saw or forwarded it. Use an encrypted link, and change the password when the project ends.
Should I give the agency my domain registrar login?
Only if they need DNS or transfer control, and only through a secure channel. Where the registrar supports delegated or sub-account access, use that instead of the main login, and reclaim it when the work is done.