How do I deliver login credentials to a trader securely?
Quick answer
Send credentials only to the email the trader used to buy, avoid posting them in public channels, keep the password separate from the account number where possible, and rotate the password immediately if it is exposed. A prefilled login link is convenient, but it carries the password and should be treated as a credential.
Detailed answer
Good practice:
- Verified destination: the buyer's email, not a chat handle.
- No screenshots in public communities.
- Rotation: if a password leaks, rotate it; this should end any session using it.
- Links as secrets: a link containing the password is a password.
On PropExecutor, a firm can open a prefilled login link (/login?account=&password=&server=) from the admin panel's account drawer. The terminal removes the values from the address bar on load, but the link itself, as sent, is a credential. Rotating an account's password in the admin panel ends every live session for it at once.
A safer pattern
Send the Account Number and Server in the welcome email, and the password in a separate message to the same registered address. It adds little friction and means a single forwarded email does not expose everything.
When a trader shares credentials
If you see the same account used from very different places, rotate the password and contact the registered trader before restoring access.
PropExecutor team · Updated
Related questions
- The PropExecutor trading terminalIs a prefilled login link safe to share?
- What should a trader's welcome email include?
- Managing accounts and tradersHow do I reassign an account to a different trader?
- How do I handle a trader who has forgotten their password?
- The PropExecutor trading terminalCan I send a trader a prefilled login link?
All 20 questions in Trader operations and support · Every category