Introduction
When setting up integrations or troubleshooting access issues, CorePlan support may need credentials from you, such as a username and password or an API key. Sharing this information securely protects your account and prevents sensitive data from being exposed in email threads or chat messages.
This article explains the recommended methods, in order from easiest to most manual.
What counts as sensitive information
Sensitive information includes anything that grants access to a system or account, such as:
Usernames and passwords
API keys or tokens
Account PINs or access codes
If you're unsure whether something needs to be shared securely, treat it as sensitive and follow one of the methods below.
How to share credentials securely
Option 1: Use a password manager (easiest)
If your organisation already uses a password manager such as 1Password, BitWarden, or LastPass, this is the simplest option. You can share a secret directly to an email address and control how long the recipient has access.
Contact your internal IT team if you're unsure whether your organisation has a password manager.
Option 2: Use an online temporary sharing service
If you don't have a password manager, use a time-limited, self-destructing sharing service. CorePlan recommends:
These services automatically delete the secret after a single view, or after a specified time period. They are not affiliated with CorePlan and claim to keep no record of any information transferred.
To share credentials using OneTimeSecret:
Go to onetimesecret.com.
Paste the sensitive information (e.g. username and password) into the Secret value field.
Optionally, set a passphrase and expiry time for added security.
Click Create a secret link.
Copy the generated link and send it to CorePlan support via email or support chat.
Once CorePlan support views the link, it is permanently destroyed and cannot be accessed again.
Option 3: Secure shared folder
For some customers, CorePlan creates a shared folder via Microsoft OneDrive that only you and the CorePlan onboarding team can access. You can drop the credentials into this folder and CorePlan will retrieve them. The folder is destroyed afterwards to ensure no ongoing access.
Ask your CorePlan contact if this option is available to you.
Option 4: Manual sharing (last resort)
If none of the above options are available to you, use this method as a minimum:
Create a text or Word file containing the credentials.
Compress the file using Windows' built-in Send to compressed folder option, or third-party software such as 7-Zip.
Password-protect the compressed file. Use a password generator and a length of 12 or more characters.
Send the password-protected file to your CorePlan contact via email or support chat.
Send the password separately through a different channel, such as SMS or a phone call.
What not to do
Avoid sharing sensitive information through:
Unencrypted email: credentials sent this way may persist indefinitely in inboxes.
SMS or messaging apps: regular SMS and public chat platforms are not designed for credential storage.
Social media direct messages: these are not secure channels for sensitive data.
Shared documents: credentials stored in Notion, SharePoint, or similar tools can be accessed by anyone with document access.
⚠️ Important: If you have already shared credentials through one of these channels, let CorePlan support know so the credentials can be rotated and the messages removed.
Not sure what to do?
If none of the above options make sense, reach out to your internal IT team, IT provider, or software vendor for advice. CorePlan can support you with the CorePlan platform, but cannot provide support for third-party tools mentioned in this article.
