To send a password over Slack safely, don't paste the password into the message. Put it in a one-time, self-destructing link set to expire after one view or a short time limit, add a passcode, post only the link in Slack, and give the recipient the passcode through a different channel, such as a phone call.
Key takeaways
- A password pasted into Slack stays searchable, exportable and readable by connected apps until retention rules remove it.
- Post a one-time link instead, set to one view and a short time limit, so the Slack message holds nothing reusable.
- Send the passcode outside Slack so one compromised account is not enough to open the note.
- If a password is already in Slack, change the password first, then delete the message and check where copies went.
- For credentials a team uses every day, a shared password manager is the better tool.
Is it safe to send passwords on Slack?
Not as plain text in a message. Slack encrypts traffic and stored data, but that protects against outsiders. It does not stop people and tools inside your workspace from reading what you post.
The real problem is persistence. A message is not a phone call. Once you share a password in Slack, it becomes part of a searchable, exportable record that outlives the conversation by months or years.
Slack is fine for coordinating a password handoff. It is a poor place for the password itself.
Where a password goes after you share it in Slack
When you paste Prod-db: Tr0ub4dor&3 into a DM, it doesn't stay in that DM. Here is where it can end up.
Search
Anyone in the conversation can search for it later, along with anyone who joins a channel where it was posted. If an attacker gets into one of those accounts, typing "password" or "pw" into search is the first thing they try.
Exports and retention
Workspace owners can export message history. On certain paid plans that can include private channels and DMs. If your retention setting is "keep everything", which is common, the password sits there indefinitely and travels with every export, legal hold or compliance archive.
Integrations and apps
Bots and apps with permission to read channel history see every message in those channels. That includes archiving tools, AI summarizers and ticketing integrations, which may copy the text into their own systems where your Slack retention rules don't apply.
Notifications and devices
Slack can email unread message digests and show message previews on lock screens. Your password can land in an inbox or on a phone screen on a train before the recipient even opens Slack.
This is why secrets in chat age so badly. We cover the longer-term fallout in what goes wrong when secrets sit in chat history forever.
How to send a password over Slack the safe way
The fix is simple. Slack carries a link that works once and then dies, and the password itself never touches Slack. Here is the workflow using SecureNotes.
- Open SecureNotes and paste the password. Go to create a self-destructing note. Paste only what the recipient needs. If you can, leave the username or server address out and send it in Slack separately, so neither message is useful alone.
- Choose when it self-destructs. For a password, pick 1 view and a short time limit such as 1 hour or 24 hours. With "whichever comes first" selected, the link dies as soon as it is read or when the clock runs out, even if nobody ever opens it.
- Add a passcode. Set a short passcode the recipient must enter to open the note. This protects you if the Slack link is seen by someone else.
- Turn on the read notification (optional). SecureNotes can email you when the note is opened. If you get that email before your colleague says they've opened it, you know something is off.
- Post the link in Slack. Send it in a DM to the specific person, not a channel. Add context such as "Staging DB password, one view, expires in an hour."
- Send the passcode another way. Call them, text them or say it in person. Don't put the passcode in the same Slack thread, because that puts the lock and the key in the same place. Our guide to sending the passcode safely covers the options.
- Confirm and clean up. Once they've opened it, the link no longer works. Ask them to store the password in their password manager, and to change it if it was a temporary one you set.
If you hand out credentials often, for example when provisioning test accounts, you can generate notes from scripts with the SecureNotes REST API and post the resulting link to Slack automatically.
Slack password sharing options compared
Here's how the common ways to share a password in Slack stack up.
| Method | Stays in Slack search | Reaches exports and apps | Works for recurring access | Best for |
|---|---|---|---|---|
| Paste in a channel | Yes, for everyone in it | Yes | No | Never |
| Paste in a DM | Yes, for both people | Often | No | Never |
| Paste, then delete the message | No, after deletion | Possibly, before deletion | No | Damage control only |
| One-time link posted in Slack | Only the dead link | Only the dead link | No | One-off handoffs |
| Shared password manager vault | No | No | Yes | Team credentials used daily |
| Phone call | No | No | No | Short passwords and passcodes |
Common mistakes that still leak the password
A one-time link removes most of the risk, but a few habits undo it.
Putting the passcode in the same thread
"Link above, passcode is 4471" means anyone with access to that DM can open the note. Use a separate channel or skip the passcode, but don't pretend it adds protection when it sits next to the link.
Posting the link in a channel
A one-view link in a busy channel is a race. Whoever clicks first gets the password. Send it to one person in a DM.
Ignoring link previews
Slack fetches URLs to build previews. Depending on how a service handles those requests, a preview fetch could count against a view limit. If your recipient opens the link and finds it already gone, don't just resend. Treat the password as possibly seen and change it.
Long expiry "just in case"
A 30-day link that nobody opens is a 30-day window for someone else. Short timers cost you a resend at worst. The trade-off is explained in self-destruct vs time-based expiration.
Screenshots and copy-paste after the fact
The recipient can still screenshot the note or paste the password back into Slack to ask "is this right?". Tell them where it should live, usually their password manager.
Reusing the password
Secure delivery doesn't help if the same password protects five systems. Send unique credentials and ask for a change at first login where the system allows it.
What to do if a password was already posted in Slack
It happens. Someone pastes an AWS key into #deploys at 6pm. Work through these in order.
- Change the password or rotate the key first. Deleting the message doesn't undo anyone who already saw it, exports already made, or apps that already copied it. Rotation is the only step that makes the leaked value useless.
- Delete the message and any quotes of it. Check threads, replies and messages where someone quoted or forwarded it. Edit history can matter too, so delete rather than edit.
- Check where else it went. Think about email notifications, connected apps that read that channel, and anyone who joined the channel since. Ask your Slack admin which integrations have history access.
- Review account activity. Look at login history or access logs for the affected account between the time it was posted and the time you rotated it.
- Tell your security or IT team. If your workspace runs compliance exports or legal holds, a copy may exist that only an admin can deal with. A quick heads-up is better than an auditor finding it later.
- Send the new password properly. Use the one-time link workflow above.
If you want to find older leaks before someone else does, see what your IT audit will find in your chat logs. The OWASP Secrets Management Cheat Sheet is also a solid reference for rotation and detection practices.
When a one-time link isn't the right tool
One-time links are built for handoffs: a new hire's first login, a contractor's temporary key, a door code for a weekend. They are not a storage system.
If five people on your team need the same admin login every week, sending it again and again is friction and risk. Put it in a shared password manager vault with access controls, and remove people when they leave. We compare the two in one-time links vs password vaults.
Also skip the password entirely when you can. Single sign-on, per-user accounts and scoped API tokens mean nothing needs to be shared at all. And for a six-digit passcode or a short Wi-Fi password, a quick phone call is often simplest.
Frequently asked questions
Does Slack encrypt messages?
Slack encrypts data in transit and at rest, which protects against outside interception. It is not designed to hide messages from your own workspace. Admins can export history depending on plan, connected apps can read channels they have access to, and anyone in the conversation can search it later. Encryption at rest does not make a pasted password private.
Can Slack admins read my direct messages?
Depending on your plan and settings, workspace owners may be able to export direct messages and private channels, often for compliance or legal reasons. Some organizations also connect data loss prevention or archiving tools that scan all messages. Assume anything you type in a DM could be reviewed later, and keep passwords out of the message text.
Does deleting a Slack message remove the password completely?
Deleting removes it from the conversation and search, but not from places it already reached. Earlier exports, compliance archives, email notifications, lock-screen previews and third-party apps that copied the message may still hold it, and anyone who read it may have saved it. That is why you should change the password before deleting the message.
Is it safe to say a password out loud in a Slack huddle?
A voice huddle leaves no text in search, which is better than typing it. But huddles can be recorded or transcribed by some tools, and saying a long password aloud is error-prone. It works for short passcodes. For longer passwords, send a one-time link and use the call only for the passcode.
Is Slack Connect safe for sharing credentials with external partners?
Slack Connect channels involve two organizations, so the message can fall under both workspaces' retention, exports and integrations. That widens the audience for anything pasted there. For credentials going to a partner or contractor, send a one-time link to one named person and deliver the passcode outside Slack.