Is a prefilled login link safe to share?

Quick answer

Only with the account's trader. A prefilled link contains the account's password, so anyone who has the link can log in. The terminal removes the values from the address bar once it opens, but the link as sent is still a credential. Rotate the password if it reaches anyone else.

Detailed answer

Convenience and security pull in different directions here, so be deliberate.

What the terminal protects

  • Address bar and history: values are removed from the URL when the page opens.
  • Analytics: the values are removed before analytics tools load.
  • Recordings: the password field is masked from session recording tools.

What it cannot protect

  • The email or message the link was sent in.
  • Anyone the trader forwards it to.
  • Server logs of services the link passes through.

Safer alternatives

  • Send a link with only the server prefilled, and the password separately.
  • Send credentials in the body of an email to the trader's registered address.

Rotate the account's password in the admin panel or over the API. Rotation generates a new password and revokes every live session for the account, so the leaked link stops working. Then send the trader the new password through their registered email.

PropExecutor team · Updated

All 26 questions in The PropExecutor trading terminal · Every category