- No credentials in your ticket history. The agent posts the link, not the password. Your PSA stays clean of anything an auditor would flag.
- No follow-up cleanup for your team. No more “go back and redact the temp password from ticket #4832” after a reset.
- One less tool your techs have to reach for. The agent generates the link automatically when it does a password reset or hands off a recovery code — your techs don’t have to remember to use OneTimeSecret manually.
One-Time Secret is configured in MSP Settings → Integrations.
Connect One-Time Secret
You’ll need a One-Time Secret account and an API key.1
Generate an API key in One-Time Secret
Go to onetimesecret.com and sign in (or sign up). The free plan supports the API; paid plans raise the rate limits and add custom branding.From the top-right menu open Account, scroll to the API section, and click Generate Key (or Reset Key if you already have one). Copy the key.
2
Paste the credentials into Rallied
In Rallied, go to MSP Settings → Integrations, find the One-Time Secret card, and click Connect. Fill in:
- Username (account email) — the email address on your One-Time Secret account.
- API Key — the key you just copied.
What happens when the agent needs to share a credential
When a workflow (or the agent’s own reasoning) calls for delivering something sensitive to a user, like a temporary password after a reset, a recovery code, or a first-login token, the agent generates a one-time link through your One-Time Secret account and puts the link in front of the user instead of the value itself. By default the link expires 24 hours after it’s created. The agent can shorten that for live-call resets or extend it up to 14 days for users who might not open it right away. If the workflow calls for extra protection on high-sensitivity credentials (domain admin, banking portals), the agent can attach a passphrase to the link and deliver the passphrase through a different channel — for example, link goes in the ticket, passphrase gets read out loud on the voice call.Where the link gets delivered
The agent uses whichever channel the ticket is already on:- PSA ticket — customer-visible reply on the ticket, so the user gets it in the same email thread they’ve been on.
- Voice agent — link is sent by SMS or email as part of the call handoff.