It's a common shortcut: a fulfilment partner or contractor needs to check something in your store, and it's faster to just send the login and a verification code over chat than to set up proper access. It feels harmless in the moment. It's also one of the easiest ways to lose visibility and control over your own store, and it's rarely necessary.
Why this happens
Usually it's not carelessness, it's speed. A quick question comes up, "can you just log in and check the tracking sync," and typing out a password feels faster than setting up a proper access method. It happens most under time pressure, exactly when people are least likely to think through the risk.
What actually goes wrong
You lose the audit trail. Once someone has your actual login, you can't see what they did, changed, or accessed versus what happened through your own account.
The credential doesn't expire when the task is done. Unless you change the password afterward, that access stays live indefinitely.
It defeats two-factor authentication. Sending the code along with the password means the second layer of protection did nothing.
It's hard to revoke cleanly. Removing one person's access means changing the password for everyone, including yourself, and re-sharing it if others still need in.
It normalizes the habit. Once it's happened once, it's easier to do again, and each repetition is another point where the credential could leak, get stored somewhere insecure, or be reused.
What proper access actually looks like
Most platforms have a real answer to this that takes about the same amount of time:
Shopify: collaborator access, generated from your own admin, scoped to specific permissions, revocable instantly without changing your password.
WooCommerce: a separate admin or staff user account with its own login, deletable independently.
Most other platforms: a staff or team-member invite system rather than sharing the owner login.
These give the other party exactly the access they need, nothing more, and you can remove it in seconds without disrupting your own access or anyone else's.
If someone asks for your password anyway
A fulfilment partner, developer, or contractor asking for your actual login and a 2FA code, instead of requesting proper scoped access, is worth a second look. It might be genuine urgency and unfamiliarity with the platform's access options rather than anything malicious, but it's still worth redirecting to a proper access method rather than just sending the credential because it's quicker in the moment.
We never ask for your store password. If we need access, we'll ask for collaborator or staff-level access through your platform's own system, scoped to what we actually need. If anyone else asks you for a full login over chat, it's worth asking why proper access isn't being used instead.
Need to check how a change affects a live product?
Send the product, destination and order context on WhatsApp (wa.link/dropship). We will help you separate confirmed facts from operational next steps.
Consult on WhatsApp →