How do I deliver login credentials to a trader securely?

Quick answer

Send credentials only to the email the trader used to buy, avoid posting them in public channels, keep the password separate from the account number where possible, and rotate the password immediately if it is exposed. A prefilled login link is convenient, but it carries the password and should be treated as a credential.

Detailed answer

Good practice:

  • Verified destination: the buyer's email, not a chat handle.
  • No screenshots in public communities.
  • Rotation: if a password leaks, rotate it; this should end any session using it.
  • Links as secrets: a link containing the password is a password.

On PropExecutor, a firm can open a prefilled login link (/login?account=&password=&server=) from the admin panel's account drawer. The terminal removes the values from the address bar on load, but the link itself, as sent, is a credential. Rotating an account's password in the admin panel ends every live session for it at once.

A safer pattern

Send the Account Number and Server in the welcome email, and the password in a separate message to the same registered address. It adds little friction and means a single forwarded email does not expose everything.

When a trader shares credentials

If you see the same account used from very different places, rotate the password and contact the registered trader before restoring access.

PropExecutor team · Updated

All 20 questions in Trader operations and support · Every category