Short answer: in transit, yes. At rest, not really.

WhatsApp messages are end-to-end encrypted. Nobody between the two phones — not WhatsApp, not your mobile operator, not the café Wi-Fi — can read them. If your worry is interception, WhatsApp is a perfectly good way to send a password.

Interception is rarely how passwords leak. They leak because they are still there long after they were needed.

Features described as of September 2026; check the app’s settings for the current options.

Where the password actually lives after you press send

  1. In the chat, on both phones, indefinitely. Anyone who picks up either unlocked phone can scroll back or use search — “password” is an excellent search term.
  2. On every linked device. WhatsApp Web, the desktop app, a tablet. Each is a full copy of the conversation on a machine with its own security.
  3. In the backup. Chat backups to iCloud or Google Drive are not end-to-end encrypted unless the user has switched that option on. You can enable it on your side. You cannot check it on theirs.
  4. On the lock screen. A message preview shows the first line to anyone standing nearby — and a password is usually the first line.
  5. Wherever it is forwarded. Once it is a message, it is one long-press from another chat.
  6. On the other person’s next phone. Chat history moves to the new device; the old one may be sold, recycled or handed to a child.

None of this is a flaw in WhatsApp. It is what a chat history is for. The problem is using a permanent record to deliver something that should be temporary.

Making it less bad

If WhatsApp is what you have, these help, in order of value:

  • Split it. Send the password on WhatsApp and the username and site somewhere else. Half a credential is much less useful.
  • Turn on disappearing messages for that chat before you send (24 hours is the shortest setting). It clears both phones and future backups — not backups already made, and not screenshots.
  • Delete for everyone once they confirm they have it. It works for a limited time after sending and only removes the message, not a copy they have made.
  • Turn on end-to-end encrypted backup on your own phone, and turn off message previews on the lock screen.
  • Change the password after first use wherever that is possible. A first-login password that stops working an hour later is not worth stealing.

Note that View Once does not apply to text — only to photos, videos and voice messages. Typing a password into an image and sending it as View Once works, awkwardly, and nothing stops a second phone photographing the screen.

Better tools for the job

  • Share access, not the password. A shared vault in a password manager, or an invitation to their own account, leaves nothing to clean up.
  • A one-time link. Bitwarden Send, a password manager’s item link, or a one-time secret service: the link opens once and dies. Beware link previews spending the single view — see How to Send a Password Securely and our comparison of One-Time Secret alternatives.
  • Signal, if you both have it: disappearing messages there can be set in seconds and start counting when the message is read.

When it is your job, not a favour

For an organisation, “just be careful” does not scale. People send credentials to colleagues, contractors and clients every day, in whatever app the other person happens to use — very often WhatsApp or WeChat — and nobody can take any of it back.

That is the case WaxSeal is built for. The sender puts the secret into WaxSeal, picks a photo and chooses who may read it. The secret is encrypted on the sender’s device for the recipients’ devices and held as ciphertext in the organisation’s vault, which cannot read it; the photo carries only an invisible reference that survives WhatsApp’s compression. So you still send it over WhatsApp — but what lands in the chat history, the backup, the linked laptop and the forwarded message is a picture of a sunset.

The recipient opens the photo in WaxSeal with Face ID. The sender decides the rest: open once, expire on Friday, require a PIN told by phone, or revoke it — after which the photo is only a photo. A burn or a revocation ends further authorised opening; it cannot un-show what someone already read, so you still rotate a credential you no longer trust. Sending to other people happens inside a team workspace; recipients are free.

The one-line version

WhatsApp protects the password on the way. It does nothing about the five copies that exist afterwards. For a Netflix login, split it across two channels and move on. For anything that opens a door, a bank or a server, use something that expires — and, if you are an organisation, something you can take back.

Frequently asked questions

Can WhatsApp or anyone else read a password I send in a chat?
Not in transit. WhatsApp chats are end-to-end encrypted, so the company and network operators cannot read them. The password is readable on both phones and on every linked device, and in chat backups unless end-to-end encrypted backup has been turned on.
Are WhatsApp backups encrypted?
Chat backups to iCloud or Google Drive are not end-to-end encrypted by default. WhatsApp offers an end-to-end encrypted backup option that you must switch on yourself, protected by a password or a 64-digit key. You cannot see or control whether the other person has done so.
Does View Once work for text messages?
No. View Once is for photos, videos and voice messages. For text, the closest feature is disappearing messages, which delete the chat’s messages after 24 hours, 7 days or 90 days — a timer, not a read-once.
What is the safest way to send a password to someone?
Share access instead of the password if you can (a password manager’s shared vault or an invitation to their own account). Otherwise use something that opens once and expires, put any passphrase or PIN on a different channel, and change first-login passwords after first use.

StegoSafe hides AES-256-encrypted secrets inside ordinary photos — in a deniable format with no header or marker — and can split them across several photos with Shamir Secret Sharing. Runs fully offline on iPhone, iPad and Mac; one universal purchase. For organisations that must send a secret and control it afterwards, see WaxSeal

Get StegoSafe →