Is It Safe to Send Passwords Over Slack?

Short answer: Slack encrypts messages in transit and at rest, so a password in Slack is safe from someone sniffing the network. The problem is everything else: the message stays, it is searchable, it can be exported, it is readable by integrations, and it is one compromised account away from whoever wants it.

What happens to a password you paste into Slack

  • It is kept for as long as the workspace's retention says. Paid plans keep messages indefinitely by default, unless an admin sets a shorter retention policy. Free workspaces show the last 90 days, and since August 26, 2024 Slack deletes free-plan messages and files older than one year. Either way, that is months to years — not minutes.
  • It is searchable. Anyone who gets into your account, or the recipient's, can search for "password", "pw", or "key" and find it in seconds. That is the first thing an attacker does after taking over a chat account.
  • It can be exported. On Business+ and Enterprise Grid, workspace owners can export private channels and direct messages once Slack approves the request (for legal process, with members' consent, or where the company has the right to the data). Enterprise plans also feed legal-hold and eDiscovery tools.
  • Apps may read it. Bots and integrations added to a channel can read messages in that channel, and their vendors' logs are outside your control.
  • Editing or deleting isn't a guarantee. If a retention policy or legal hold is in effect, a deleted message may still be preserved for compliance — and notifications, previews, and other people's screenshots may already have copied it.

"It's a DM, only the two of us can see it"

A direct message limits who sees it today. It does not change how long it is kept, whether it is searchable from either account, or whether a future admin export or a compromised laptop includes it. Most leaked credentials are not stolen in transit; they are found later, sitting in a place that was convenient at the time.

Sending a password in Slack safely

  1. Create a one-time link at oncepad.com. The password is encrypted in your browser under a generated seven-word passphrase.
  2. Paste the link into Slack. It carries no key, so the message history holds nothing usable — and Slack's link preview cannot open or burn it.
  3. Send the passphrase another way: say it on a huddle or call, or text it.
  4. Once your colleague reveals it, the secret is gone from the server. If they never open it, it disappears after 24 hours.

For credentials a team uses every day, a shared vault in a password manager is the right long-term home. A one-time link is for the hand-off — and for the many people you need to send a credential to who are not in your vault.

If a password is already in Slack

Deleting the message is worth doing, but treat the password as exposed: change it, and send the new one properly. Searching your own workspace for common words like "password" is a quick way to find the others.

Sources: Slack's help articles on message history on free workspaces and exporting workspace data. Plans and policies change; check them for your workspace.