SSRITHONGKWAO
Privacy & Product Literacy / Knowledge Center

Passwords and one-time codes: information you should never send

Editorial illustration supporting the article: Passwords and one-time codes: information you should never send
Visual guide for Passwords and one-time codes: information you should never send. Illustration by Srithongkwao Knowledge Center.

Authentication secrets are designed to prove control of an account. Sharing them can give another person the same power.

Srithongkwao Editorial TeamPublished 20 September 2026Reviewed 21 September 2026
In this guide: Why passwords, OTPs, recovery codes and session tokens are different from ordinary support information and should remain secret.
Important context

User control: Passwords should remain private should be explained in plain language before a user is expected to make a privacy or permission choice. A permission can often be denied, limited or changed later through browser or Android settings.

Data-minimization principle: Passwords and one-time codes: information you should never send should use only the information needed for the stated purpose. Users should avoid sharing secrets or unrelated personal information simply because a form, screenshot or upload makes it technically possible.

Passwords should remain private

A support agent can diagnose many issues from logs, account identifiers and error messages without learning the password.

Never include a password in screenshots, email or chat.

Key concepts for Passwords and one-time codes: information you should never send
Key concepts from this guide.

One-time codes are still secrets

An OTP may expire quickly, but during its valid period it can authorize a sign-in or sensitive action.

Do not forward a code to someone who contacted you unexpectedly.

Key ideas from Passwords and one-time codes: information you should never send
Key ideas from this guide.

Recovery codes can be long-lived

Backup codes are often designed for use when normal authentication is unavailable.

Store them securely and do not treat them as disposable text.

Session tokens can bypass login

Developer logs or browser tools can expose tokens that represent an authenticated session.

Redact tokens from debugging evidence and revoke them if exposed.

Practical guide for Passwords and one-time codes: information you should never send
Practical points to use with this guide.

Legitimate support should use safe verification

Account support can use established recovery procedures rather than asking for live secrets.

If a message requests a code, verify the official process independently.

Common mistakes to avoid

Practical checklist for Passwords and one-time codes: information you should never send
Practical checklist and takeaways.

Practical checklist

Frequently asked questions

Is an OTP safe to share after it expires?

There is usually no reason to share it; keep authentication codes out of support messages.

What is a session token?

It is a technical credential that can represent an authenticated session.

Should support ask for my password?

Ordinary support should not need it.

Editorial note: This page is part of the Srithongkwao Knowledge Center. We separate product guidance, belief-based interpretation and safety information so readers can understand both the useful context and the limits of each topic. See our Editorial Policy and Corrections Policy.