SecretWolf
Service desk

Send temporary passwords your staff receive safely

A password reset shouldn't sit in a ticket or a chat thread. Send the temporary credential as a one-time link, optionally gated behind an emailed code, so only the right employee opens it — once.

One-time links AES-256-GCM Full audit trail Your brand & domain

Built for the service desk

A reset only the person who asked for it can open, and that stops existing the moment they've read it.

Not in the ticket, not in chat

Send the temporary password as a one-time link instead of typing it into a ticket or a chat message where it stays readable indefinitely.

Confirm it's really the employee

Require an emailed one-time code before the reset reveals, so a temporary password opens only for the person who requested it.

Generate a strong temporary password

Create a random temporary credential on the share page and send it in the same step — no predictable, reused reset passwords.

Automate from your service desk

Create reset links from your ticketing, RMM or scripts via the API, and get a signed webhook when the link is viewed so the ticket can close itself.

It self-destructs after use

The link is destroyed on first view or expiry, so a temporary password can't be reused from an old ticket or a forwarded message.

Revoke a reset in flight

If a reset was sent in error, or a request turns out to be suspicious, revoke the link before it's opened.

Questions we hear

How does this fit our ticketing system?

Create secret links programmatically via the API from your service-desk tool, and receive an HMAC-signed webhook when the credential is viewed — so the reset and its delivery are recorded against the ticket.

Does the employee need to install anything?

No. They open the link in a browser and see the temporary password once. You can gate it behind an emailed one-time code for extra assurance.

What stops someone else opening the reset link?

Recipient verification: require a one-time code sent to the employee's email before the password reveals, so a forwarded or intercepted link is useless on its own.

Can we set how long a reset link lasts?

Yes. Set an expiry so an unopened reset link dies after a short window, and revoke any link before it's viewed if something changes.

Take reset passwords out of your ticket queue

Free to start. Recipient verification and the API arrive on the paid plans.

Start free