Getting started

Credential Sharing Guidelines

Last Updated: August 24, 2026

Overview

This document provides mandatory guidelines for securely sharing credentials and sensitive information. Following these guidelines is critical to maintaining the security of our systems and protecting sensitive data.

BLUF: Use the current documented process for accessing test user accounts, and use Onceler when credentials need to be shared securely.

Critical: Why Slack is NOT Secure for Credentials

FOIA Compliance Risk

⚠️ WARNING: All Slack messages are subject to Freedom of Information Act (FOIA) requests. This means:

  • Any credentials posted in Slack can become publicly accessible

  • Sensitive test data shared in Slack may be disclosed in FOIA responses

  • Even deleted messages can be recovered and disclosed

  • Screenshots containing credentials are equally vulnerable

Security Implications

Sharing credentials in Slack exposes us to:

  • Unauthorized system access

  • Data breaches and PII exposure

  • Compliance violations

  • Failed security audits

  • Legal liability

Proper Credential Access and Sharing

For Test User Accounts

For the latest information on finding and using test accounts, including current Test User Dashboard (TUD), Test User Portal (TUP), credential, and MFA guidance, see the Test User Dashboard guide.

This guide is the source of truth for current test account access instructions.

For Sharing Credentials: Use Onceler

URL: https://onceler.app.cloud.gov/

Onceler is the approved method for sharing credentials when direct access isn't possible. It provides:

  • One-time links that expire after a single view

  • End-to-end encryption in transit and at rest

  • No permanent storage - credentials are destroyed after viewing

  • FOIA-safe - only the link is shared in Slack, never the actual credential

What NEVER to Share in Slack

Prohibited in Any Slack Channel or DM:

  • ❌ Passwords or passphrases

  • ❌ API keys or tokens

  • ❌ SSH keys or certificates

  • ❌ Database connection strings

  • ❌ Service account credentials

  • ❌ Test user credentials

  • ❌ URLs with embedded auth tokens

  • ❌ Screenshots showing credentials

  • ❌ Test user usernames, passwords, MFA secrets, or other authentication information


Help and feedback