Skip to content
VaultPass

Passwords

How to share a password without sending it over WhatsApp

The VaultPass desk4 min read
Two metal keys on a table

Sharing the Wi-Fi password, the streaming login or the club's email account is something everyone does. Sharing is not the problem: the problem is that the message stays there forever, on two phones, in two cloud backups, and on any computer where that account gets opened.

There is a difference between data travelling safely and data staying safe. WhatsApp, Telegram and Signal messages travel encrypted: nobody reads them in transit. But on arrival they are stored, and that is where the trouble starts.

That password now lives:

  • In your phone’s chat history.
  • In the other person’s chat history.
  • In both of their backups, which are often kept in the cloud under different protection to the message itself.
  • On any computer or tablet where that account is signed in.
  • And on the phone that person sells in two years’ time.

Nobody had to attack anything. The message simply stayed put.

The options, best to worst

1. Share from a password manager

This is the good one, by a wide margin. Managers let you share an entry with another person who also uses the manager. The advantages:

  • The other person uses the password without ever needing to see it.
  • You can withdraw access whenever you like.
  • If you change the key, their copy updates itself.
  • There is a record of who you shared it with.

That last point is the underrated one: in a family or a small club, knowing who has access to what ends up mattering more than the password itself. How to pick one is in password managers: how to choose one.

For when the other person has no manager. Self-destructing note services let you paste the text, hand you a link, and that link stops working after one open or after a deadline.

Two details make the difference:

  • Split the channels. Send the link one way and the context (“it’s for the electricity account”) another. A bare link with no explanation is useless to whoever intercepts it.
  • Set a short expiry. Hours, not days.

3. Say it out loud

Old-fashioned and surprisingly good. A phone call or a face-to-face conversation leaves no written copy anywhere. It works well with passwords built as phrases — four random words — because they dictate unambiguously, unlike K7#mQ!2vX. That reasoning is developed in how to create a secure password.

4. Split it in two

Half the password down one channel, half down another. Better than sending the whole thing, but it still leaves two permanent copies. As an improvised patch it will do; as a system, no.

5. Send it by message and delete it afterwards

What everybody does. Deleting the message lowers the odds of someone seeing it when they borrow the phone, but it does not remove backups already taken. If the password protected something that matters, it needs changing, not just deleting.

What you rarely need to share at all

Before working out how to send it, it is worth asking whether you need to:

  • Home Wi-Fi. Modern phones share the network by QR code or by proximity, without anyone seeing the key. And nearly every router can create a separate guest network, which also keeps visitors away from your devices. More on this in your router password.
  • Streaming services. Almost all have profiles or family plans with email invitations. Sharing the main password hands over the payment details too.
  • Work accounts. These usually have user management. If you share yours and something goes wrong, it is your name on it.
  • Your bank. No nuance available here. Never.

If you do share, share properly

  1. Make it a password created for sharing, not one you use elsewhere. Recycle it and you are granting access to more than you think, by the same mechanism as credential stuffing.
  2. Turn on two-factor for the account, with the second factor staying with you.
  3. Give it a mental expiry date: when that person stops needing it, change it.
  4. Change it when the relationship changes: the contract ended, the flatmate left, the child moved out.

The short version

  • The message travels safely but is stored on two phones and in two backups.
  • Best is sharing from a manager: access without revealing the key, and revocable.
  • Without a manager, a one-time link with a short expiry, context sent separately.
  • Often nothing needs sharing at all: guest networks, profiles, invitations.
  • Only share passwords created for the purpose, and change them when they are no longer needed.

Frequently asked

The questions that keep coming up

Is it safe to send a password over WhatsApp?

The message is encrypted in transit, but it is stored permanently on both phones and in their backups, which are often not protected the same way. For something trivial it is fine; for an account that matters, it is not.

What is the safest way to share a password?

A password manager's sharing feature, because it grants access without revealing the key and lets you withdraw it later. Failing that, a one-time link that self-destructs.

What if the other person does not use a password manager?

A self-destructing note service: paste the key, get a link that only works once, and send that link. Send the link and the context through different channels.

What about passwords I have already sent by message?

Change them if they protect anything that matters, and delete the messages on both sides. Deleting without changing the password achieves nothing: the backup already exists.

Keep reading