Pinzen
GuidesUse casesFAQSupportOpen Pinzen
  1. Home
  2. Guides
  3. How to Send a Password Securely (and Stop Texting Them)

Family Sharing

How to Send a Password Securely (and Stop Texting Them)

How to send a password securely to a sitter, parent, or college kid. Why texts and email are risky, how expiring encrypted links work, and what to do after.

Last updated October 4, 2026 · 7 min read
On this page
  1. Why texts, email, and chat apps are risky for passwords
  2. How encrypted secure links work, in plain English
  3. How to send a password securely, step by step
  4. Send the username and website separately
  5. When to share access instead of a password
  6. After you send it: expire, revoke, or change
  7. Frequently asked questions

The safest way to send a password is an encrypted link that expires, with the username sent separately. Texts and emails keep passwords in message history for years, where anyone who gets into either account can find them. If you've already sent one the old way, change it once the person no longer needs it.

This guide shows how to send a password securely in everyday family moments: the Wi-Fi for a babysitter, a streaming login for a grandparent, or a shared account for a college student. You don't need to be technical to do it well.

Why texts, email, and chat apps are risky for passwords

When you text or email a password, you aren't just handing it to one person. You're leaving copies in places you can't see or control.

  • Chat history. The message stays on both phones until someone deletes it, which rarely happens.
  • Backups. Phones often copy messages to the cloud automatically, so the password can outlive the conversation.
  • Searchable inboxes. Anyone who breaks into an email account can simply search for the word "password."
  • Lock-screen previews. A message preview can show the password to anyone who glances at the phone.
  • Forwarding and screenshots. The person you sent it to might pass it along, or screenshot it so they don't forget.

Encrypted chat apps like WhatsApp, Signal, and iMessage help, but they don't fix this. Their end-to-end encryption means only you and the recipient can read a message, not the app company. Once it arrives, though, the password sits in plain view on both phones.

Email has the same problem. Most email is protected on its way, but then it sits readable in your sent folder and their inbox, often for years. So if you're wondering how to send a password securely over email, the answer is to leave the password out and send a secure link instead.

How encrypted secure links work, in plain English

A secure link is a web address that opens a small page showing the password. The password isn't written in the link. It's encrypted, meaning scrambled so it can't be read without a key, and stored in that scrambled form.

Think of a locked box left at a front desk for a friend. The desk holds the box but never sees the key, because you give that to your friend yourself.

Good secure links work the same way:

  1. Your device scrambles the password before it goes anywhere.
  2. The service stores only the scrambled version.
  3. The link you send carries the key that unscrambles it.
  4. The link stops working after a set time, or sooner if you cancel it.

That last step is what people mean by an "expiring password link." A "one-time secret link" usually goes further and works for just one viewing.

Why the key after the # never reaches the server

Some web addresses end with a # followed by a jumble of letters and numbers. That part is called the fragment. When your browser asks a website for a page, it leaves the fragment out of that request, so it isn't sent to the website's server.

Well-designed secure links put the key there on purpose. The recipient's browser uses it to unscramble the password right on their screen, while the company running the service only ever holds the scrambled version.

Secure links in Pinzen+, our paid plan, work this way. They're encrypted in your browser, and the key after the # is never sent to the server. Links can expire or be revoked, so you can cancel one early if plans change or you sent it to the wrong person.

Two honest limits are worth knowing:

  • Anyone with the whole link can open it while it's active. The key travels inside the link, through whatever text or email app you use, so treat the link like a secret. Send it to one person, not a group chat.
  • Expiry can't take back what was seen. Once someone has viewed the password, they know it. If their access should end, change the password.

How to send a password securely, step by step

The exact buttons depend on your tool, but the steps are the same almost everywhere.

  1. Check who's asking. Scammers sometimes pose as a family member texting from a new number. If anything feels off, call the person on the number you already have.
  2. Open the login in your password manager. That's an app that keeps your passwords locked up in one place. Look for an option like share, send, or secure link.
  3. Choose the shortest expiry that works. If the sitter arrives tonight, a day is plenty. If your tool offers a view-once setting, use it.
  4. Send the link in a private message. A text or email works here, since the message holds a link that will expire, not the password itself.
  5. Send the username separately. More on this two-channel habit below.
  6. Ask them to confirm. A quick "Got it" tells you the link did its job. Then revoke it or let it expire.

No secure link tool? Tell them in person, or read it out on a phone call you started yourself. Never give a password to someone who contacts you first claiming to be your bank, a tech company, or customer support, because real companies don't ask for it.

Send the username and website separately

A password on its own is hard to misuse. A password plus the username plus the website is often all someone needs to sign in, so don't put all three in one message.

Here's a simple two-channel habit:

  • Channel one: send the secure link by text or email.
  • Channel two: share the username and which account it's for another way, such as in person, on a call, or in a different app.

If someone sees only one message, they're missing a piece. Usernames are often just an email address, so this won't stop a determined snoop. Still, it takes ten seconds and makes an intercepted message far less useful.

A good rule: share the least access, for the shortest time, and never all in one message.

For home Wi-Fi, a guest network is often simpler than handing out your main password. It's a separate Wi-Fi name just for visitors, usually kept apart from your own devices. Our guide to sharing your Wi-Fi password with guests covers that case.

When to share access instead of a password

Sending a password works well for a one-time need. But if someone needs a login again and again, the best way to share a password securely is to stop sending it at all.

First, check whether the service has its own way to add people. Many streaming, smart-lock, and email services offer family plans, guest codes, or helper access, so each person gets their own way in and you can remove them later. For bank accounts, ask the bank how to add a trusted helper instead of sharing your login.

For logins the whole household uses, like streaming, utilities, and school portals, a shared family vault beats a stream of texts. A vault is a locked folder inside a password manager, and a shared one lets each family member open the same logins. Our guide on how to share passwords with family walks through the options.

With Pinzen+, you can create up to 5 family vaults with up to 6 people each, and anyone on the free plan can join one someone else created. Each vault has its own key, and removing someone changes that key and re-encrypts the shared items. They may still remember passwords they saw, though, so change the important ones.

Be choosy, even with people you trust. A college student needs the streaming login, not the banking one.

After you send it: expire, revoke, or change

Sending it is only half the job. Here's the other half.

  • Let the link expire. If you set a short expiry, you're done once it passes.
  • Revoke it if plans change. If the sitter cancels or you sent the link to the wrong person, cancel it right away.
  • Change the password when their access should end. This matters most if you sent the password itself by text or email, and for anything tied to money or your email.
  • Change door codes and PINs after short-term visitors. Our guide on how often to change your door code explains when it's worth it.
  • Clean up old messages. Search your texts and sent email for "password," delete what you find, and change any important logins that turn up. Backups may keep copies, so changing the password is the real fix.

A password manager makes all of this easier. It can suggest a strong new password whenever you need one and keeps every login in one place, so you never dig through old texts again.

You can create a free Pinzen vault for your logins and add Pinzen+ when you want secure links. For the technical details, see how our encryption works.

Frequently asked questions

What is the safest way to send a password to someone?

If they're with you, tell them in person. Otherwise, send an encrypted link that expires and share the username another way, like a phone call, then change the password once their access should end. For logins they'll need again and again, a shared password manager vault beats sending them over and over.

Is it safe to send a password by text message?

It's risky, because texts stay in the message history on both phones, often get copied into cloud backups, and can pop up in lock-screen previews. Encrypted apps protect the message on its way, but the password still sits readable in the chat. If a text is your only option, delete it afterward and change the password when it's no longer needed.

Is it safe to email a password?

Not really. Email usually sits in your sent folder and their inbox for years, and anyone who gets into either account can search for the word "password." To send a password securely over email, put an expiring encrypted link in the message instead of the password itself, and share the username another way.

What happens when a secure link expires?

It stops working. The page no longer shows the password, and you'd need to send a fresh link if they still need it. Expiry can't undo what someone already saw, though: if they opened it in time, they know the password, so change it when their access should end.

Keep your family's passwords in one safe place

Pinzen is free to start. Sign up with Face ID, save your Recovery Kit, and share only what you choose.

Create a free vault

Keep reading

Family SharingChange Passwords After Divorce or a Breakup: A Checklist8 min readFamily SharingHow to Share Passwords Between iPhone and Android Users7 min readFamily SharingHow to Share Passwords With Your Spouse (and What Not to Share)7 min read
Pinzen

A private place for the passwords your household depends on.

ProductFeaturesFamily use casesGuidesPlatformsPricing
ResourcesFAQSecurityHelp & supportShare your story
LegalPrivacy policyTerms of use© 2026 Pinzen