Security
What Access Does a Web Developer Need From a Client?
A web developer typically needs the domain registrar, hosting, database, and CMS admin, plus brand assets and content. Here's the full checklist, which items to delegate rather than collect, and how to hand the rest over securely.
A web developer typically needs four kinds of access to build or migrate a site: the domain registrar and DNS, the hosting or cPanel, the database, and the CMS admin, plus SSH or SFTP for deployment. On top of access, they need your brand assets and page content. Grant whatever supports a user account, and hand the rest over through an encrypted link rather than email or chat.
The access checklist
- Domain registrar and DNS — to point the domain, set records, or transfer it.
- Hosting or cPanel — to deploy files, manage the server, and set up email or SSL.
- SSH / SFTP / FTP — for deployment and file-level work.
- Database credentials — for a CMS-driven or custom site.
- CMS admin — to build pages, install themes and plugins, and configure the site.
- Third-party services the build uses — a payment gateway, a form or booking tool, an email platform.
The assets and content checklist
- Logo files, ideally vector, and any brand guidelines.
- Fonts and colour references, or the existing style guide.
- Page copy, product descriptions, and any legal or policy text.
- Photos and video, though a large media library is better sent as its own follow-up.
Grant what you can, collect what you can't
Some of this is safer to grant than to collect. If your CMS or a SaaS tool lets you add a user, add the developer as their own user, which you can remove later. Hosting panels, registrars, and legacy CMS logins usually have no user option, so the developer needs the actual login. Those are the credentials to send through an encrypted link, and to change when the work is done.
How to hand it over safely
Don't email or DM the passwords. Ask the developer for a secure request, fill in the logins there, and upload the starter assets in the same place, so access and files arrive together instead of scattered across tools. For the full workflow, see how to collect website logins from clients securely and how clients should share hosting and domain access.
Where doconvoy fits
A developer using doconvoy sends you one request covering the logins and the starter assets. You enter the hosting and CMS details on a page in their name, encrypted on your device before it's sent, and upload the logo and copy alongside them. Nothing sensitive ends up in a chat thread.
Send your developer the logins and assets they need through one encrypted request, no account.
Hand over build access securelyRelated: How to collect website logins from clients securely · How should clients share hosting and domain access with an agency? · Client onboarding for web agencies · Reusable request templates for client intake
Common questions
What access does a web developer need to build or migrate a site?
Usually the domain registrar and DNS, the hosting or cPanel, the database, and the CMS admin, plus SSH or SFTP for deployment. On top of access, they need brand assets and page content. Grant what supports a user account, and collect the rest through an encrypted link.
Do I have to give my developer my hosting password?
Often yes, because hosting panels rarely have a user model. Send it through an encrypted link rather than email, and change it when the project ends. Where a platform does support adding a user, do that instead.
What should I never send by email or chat?
Any actual login: hosting, registrar, database, or CMS admin passwords. In plaintext they persist in inboxes and message history with no expiry. Use an encrypted request for those.