Guides / Any website
How do I give a developer access to my website safely without sharing my password?
By the WebFixed team. Last updated 21 September 2026.
The short answer
Every major website platform lets you give a developer their own separate login, so you never need to share your own password. On Shopify the developer sends a collaborator request that you approve, on WordPress you add a new user or approve an application password, and on Wix, Squarespace and Webflow you invite them by email with a chosen role. Give the lowest level of access that lets them do the job, and remove the account when the work is finished.
Why a separate login is safer than sharing yours
- You can remove the developer’s access in a few clicks without changing your own password.
- Your owner account, which controls billing and ownership of the site, stays private.
- Activity logs show which account made a change, which helps if something goes wrong later.
- You can limit what the developer can see, for example by hiding customer data or financial reports.
Shopify: collaborator request or staff account
Developers and agencies normally use a collaborator account. The developer sends the request from their Shopify Partner account and you approve it. Collaborator accounts do not count towards your plan’s staff limit.
- In your Shopify admin, go to Settings, then Users, then Security.
- Find the Collaborators section and copy the collaborator request code. This short code is safe to send to the developer, because on its own it only lets them submit a request.
- Send the developer the code and your store address ending in .myshopify.com.
- When the request arrives, you will get an email and see it under Settings, then Users. Open it and review the permissions they have asked for.
- Untick anything that is not needed for the job, then accept the request.
The alternative is to add the developer as a staff member from Settings, then Users, choosing their permissions. This uses one of your plan’s staff places.
WordPress: a separate user or an application password
- Log in to your WordPress dashboard and go to Users, then Add New User.
- Enter the developer’s email address and a username that makes clear who they are.
- Choose a role. Most repair work needs the Administrator role. Content-only work can be done with the Editor role.
- Leave the option to send the new user an email ticked. They will receive a link to set their own password, so you never see it.
- Select Add New User.
Some tools and services connect using an application password instead. This is a separate credential that WordPress creates for one connection. It cannot be used on the normal login screen and can be revoked at any time. You will find these under Users, then Profile, in the Application Passwords section. If a service sends you to an approval screen inside your own dashboard, check that the address in the browser is your own site before you approve.
A developer may also need access to your hosting for some faults. Most hosts let you add an extra user or create a separate SFTP account, which is a login for file access only. Ask your host how to do this, and avoid handing over the main hosting login.
Wix, Squarespace and Webflow: invite by email
Wix. From your site dashboard, go to Settings, then Roles and Permissions, and choose the option to invite a collaborator. Enter the developer’s email address and pick a role.
Squarespace. Open Settings, then the permissions panel, and invite a contributor by email. Choose the permission level they need. Administrator gives full access apart from ownership, and there are narrower levels such as website editing only.
Webflow. Access is managed through your Workspace. From the Workspace settings you can invite someone as a member, or give a freelancer or agency guest access, and choose the role they have.
On all three, the developer accepts the invitation using their own account and password. You remain the owner throughout.
Removing access when the work is done
- Shopify: go to Settings, then Users, open the collaborator or staff account and remove it.
- WordPress: go to Users, then All Users, hover over the account and choose Delete. WordPress will ask what to do with content owned by that user. Choose to attribute it to your own account so that nothing is deleted with them.
- WordPress application passwords: go to Users, then Profile, and revoke the entry in the Application Passwords section.
- Wix: go to Settings, then Roles and Permissions, and remove the collaborator.
- Squarespace: open the permissions panel in Settings, select the contributor and remove them.
- Webflow: remove the member or guest from the Workspace settings.
Review the full list of users on your site once or twice a year. Accounts belonging to previous developers, agencies and former staff are a common way for sites to be compromised.
When to get help
If you are not the owner of the account, or you cannot find the users area described above, the site may be set up under somebody else’s login, and that is worth sorting out before any repair work begins. Ask for help if a developer insists on having your own password, because that is not necessary on any of these platforms. WebFixed fixes website problems for a fixed price agreed up front, with one-off fixes from £39 including VAT and nothing charged until you accept the quote, and it uses collaborator requests, application passwords and contributor invitations so no passwords are shared.
Related questions
- Is it safe to give a developer admin access to my website?
- It is a normal part of getting a site repaired, provided the developer has their own account and you remove it afterwards. Take a backup first where your platform allows it, and limit permissions to what the job requires.
- What is a Shopify collaborator request code?
- It is a short code shown in the Security area of your Shopify user settings. A developer needs it to send a collaborator request to your store, and you still have to approve the request before they get any access.
- Can a developer see my customers’ payment card details?
- No. Card numbers are handled by the payment provider and are not visible in Shopify, WooCommerce, Wix or Squarespace admin areas. A developer with broad permissions may be able to see customer names, addresses and orders, so limit those permissions if the job does not need them.