digital
How to Share a Password With Someone Safely
By Jason Su ·
Use your password manager’s own sharing feature if it has one, because it lets you revoke access later. If you have to share outside a manager, share it in person or by voice, one password at a time, and change it once the other person no longer needs it. What you should not do is text or email it — those are the two channels that are easiest to intercept and hardest to undo.
Why “just text it to me” is the worst option
Text and email are convenient, permanent, and readable by more people than you think.
- Messages stay. A texted password sits in two phones and a carrier’s records indefinitely.
- Email is the account most likely to be compromised. It is also the account that can reset everything else.
- There is no way to un-send it. Once it is in a thread, it is in that thread forever.
- It is often forwarded. People screenshot, forward, and copy into notes without thinking.
The safe ways, roughly in order
| Method | Why it is better | What it costs you |
|---|---|---|
| Your password manager’s sharing feature | Revocable, and often lets you share one item rather than the whole vault | Needs both people to use the same manager |
| A one-time or expiring share link | Self-destructs on a timer | You need a service that supports it |
| In person, spoken | Nothing is written down and nothing is transmitted | Only works face to face |
| Written on paper and handed over | No digital trace, and you control the moment | The paper can be lost or photographed |
| Split across two channels | Half by phone, half in writing — neither channel alone is enough | Fiddly, and easy to get wrong |
The common thread: every good method is one you can undo. That is the property texting does not have.
What actually makes sharing risky
Three things, and they are worth separating:
The channel. Email, text, and chat apps are all designed for convenience, not secrecy. Anything that travels through them should be assumed readable.
The permanence. Sharing a password is not a one-time event — it is a standing grant. Until someone changes it, the other person has access forever, including after the reason for sharing has gone.
The scope. Sharing one login is very different from adding someone to your vault. A single shared password is a small exposure; a shared vault is everything you own.
Most people worry about the first and ignore the second and third, which are the ones that cause trouble.
If you are sharing with a helper or a caregiver
This is the most common situation, and it has its own traps.
- Create a separate account where you can. If a service supports multiple users, add the person as a user rather than giving them your login. Most banks and many services offer this, and it gives you an audit trail.
- Use a limited account if one exists. A view-only or delegated role is better than full access.
- Set an end date in your head. Decide now when access should stop, and change the password at that point. Put a reminder in your calendar — nobody remembers otherwise.
- Do not add a helper to your vault. Share the one login they need, not the vault that holds everything.
If you are the one receiving it
Some practical habits:
- Put it in your own password manager. Not a note, not a screenshot.
- Do not forward it onward to a family member who asks. If they need it, the owner should decide that.
- Expect it to change. The person may reset it, and being locked out is not a signal of anything.
- Note whose it is. Looking at a list of logins in six months, you will not remember why one of them is there.
Using a manager without sharing the vault
If both people use the same password manager, most of them offer something better than handing over your master password:
- Item sharing — you share one login, and you can stop sharing it later
- A shared vault for household accounts, separate from your personal vault
- Family plans, which let each person have their own account under one billing arrangement
These are worth the setup time, because they are the difference between a grant you can revoke and one you cannot.
What not to do
- Do not text or email the password. If you have already done it, change the password — that is faster than trying to delete the message everywhere it went.
- Do not share your master password. Nobody needs it, including a family member helping you. Share the individual logins instead. If someone insists on the master password, that is a reason to say no.
- Do not put it in a shared note, a spreadsheet, or a document in the cloud. Those are built for collaboration, which is exactly the wrong property here.
- Do not forget to revoke it. Sharing without an end date is a permanent change you made once and never revisited.
- Do not share it with a company that called you. Nobody legitimate asks for your password, ever. If a caller asks you to read out a code, that is the entire scam.
Frequently asked
Is it safe to write a password on paper?
For a short handover, yes — paper has no remote exposure and no permanent digital copy. The risk is physical: anyone in the house can find it. Hand it over, and take it back when it is no longer needed.
What about sharing through a password manager?
That is the best option where it exists, because access is tied to the other person’s account and you can revoke it. Check whether your manager offers item-level sharing before you do anything else.
How do I share a password with someone who does not use a manager?
Then you are left with the offline methods: in person, on paper, or by voice. All three work. Text and email are still the worst options, even though they feel the easiest.
Should I share my bank login with my adult child?
Better: have your bank add them properly. Most banks allow a joint owner, a power of attorney, or a view-only arrangement. Being on the account officially is both safer and more useful, because it works when you are not there to help.
What if I need someone to have access after I am gone?
That is a different problem, and it has a better solution than sharing now. See how to leave digital passwords to family — a named emergency contact keeps them out until the moment it is needed, and lets you change your mind.
How often should I change a shared password?
Whenever the arrangement ends. There is no fixed schedule that helps, but leaving a shared password unchanged for years is the pattern that causes problems.
Next step
Check whether your password manager offers item sharing — if it does, that is your answer for almost every case, and it takes about a minute to set up.
If you are sharing because of a longer-term concern rather than a one-off errand, the better solution is an emergency contact rather than a shared login. See Bitwarden emergency access or 1Password family access depending on which you use.
This is general information, not security or legal advice. Features and best practices change over time — please confirm details with your provider’s own documentation and talk with a licensed professional about your situation.
General information only. Rules vary by state and change over time. Confirm details with the official source before acting. Read the full disclaimer.