SecretWolf
Client onboarding

Give a new client access without emailing passwords

The first week with a client is a flurry of logins, admin invites and API keys. Send each one as a branded, one-time link that's verified, audited and destroyed once it's read — so the relationship starts with a clean security record.

One-time links AES-256-GCM Full audit trail Your brand & domain

Onboarding handovers, done properly

Week one is a stack of logins going out at speed. This is how each one arrives branded, verified and already logged.

Everything they need on day one

Send logins, admin invites, API keys and config files as one-time links through the first week — each on your brand, each destroyed the moment it's read.

Verify who's receiving access

Require an emailed one-time code before a credential reveals, so a new starter's access opens only for them — not whoever the email gets forwarded to.

Ask the client for their side too

Send a branded request form to collect the logins you need from them — their CMS, hosting or ad accounts — instead of chasing credentials over email.

A clean record from the start

Every credential sent, verified and viewed is logged as metadata, so onboarding is documented from day one and ready for a client's security review.

Generate fresh credentials inline

Setting a new password for the client? Generate a strong, random one on the share page and send it in the same step — no reused or guessable starter passwords.

Put a deadline on the handover

Give onboarding links an expiry: a credential that isn't collected in time simply expires, so nothing sensitive is left waiting in an inbox.

Questions we hear

How is this better than a shared onboarding doc?

A shared doc keeps credentials in plain text for anyone with the link, indefinitely. SecretWolf sends each credential as a one-time link that's destroyed on first view, and logs who opened it — so onboarding leaves a record, not a liability.

Can the client open links without an account?

Yes — they click the link and view it once, with no signup or install. For sensitive access you can require a one-time code sent to their email first.

Can we collect credentials from the client, not just send them?

Yes. One-off requests and standing request portals give the client a branded, encrypted form to send you a login securely, so their credentials never arrive in plain email.

Will onboarding show our brand, not SecretWolf's?

On the Team and Business plans, links, request forms and view pages carry your logo and colours — on your subdomain, or your own custom domain on Business.

Start the next client relationship with a clean record

Free to start. Branded links, requests and the audit trail when you upgrade.

Start free