Device Passwords and Access

Store customer device passwords and PINs encrypted on the repair job, control who can reveal them, and let ReturnMate wipe them when the job is done.

7 min read
Last updated 14 September 2026

Many repairs need the device unlocked. The usual answer is a sticky note on the laptop lid or a PIN typed into the job notes. Both are seen by anyone who walks past, and both outlive the repair.

ReturnMate gives device passwords their own place on the repair job. They are encrypted, shown only to the people working on the job, logged every time someone looks, and wiped automatically when the job is finished.

Choose an access arrangement

When the technician needs to get into a device, agree one of three arrangements with the customer at the counter:

  • Customer unlocks in person when needed: nothing is stored. You call the customer in when the technician needs access.
  • Customer removed the lock before leaving: the customer turns off the password or PIN before handing the device over. Nothing is stored.
  • Customer provided the login details (stored encrypted): you record the password in Device credentials.

The first two are always the safest. Store a password only when the repair genuinely needs it and the customer cannot remove the lock.

The Device access consent explains to the customer how their credentials are handled. You can edit its wording in Settings → Industry modules.

Add credentials at the counter

Access fields appear at intake when Data work consents is switched on for your module. It is on by default for Computer Repairs and off for Walk-in Repairs.

Say a login is needed

On step 2 of the intake, tick Need to log in to the device.

Choose the arrangement

On step 3, set Access arrangement to Customer provided the login details (stored encrypted).

Add each credential

In Device credentials, choose Add credential. Pick a Type (Login password, PIN, Unlock pattern, BIOS / firmware, Encryption / recovery key or Other), give it a Label such as "Windows login", and enter the Password / PIN. Username / account is optional.

Check it in

Use Show to check what you typed with the customer, then finish the intake. The credential is saved encrypted with the job.

You can add up to 10 credentials per job. The Before the customer leaves checklist shows Device login captured once a password is entered.

Add credentials on the job

You can also add a credential after check-in. This is how Walk-in Repairs stores record one, and how you add a login the customer phones through later.

  1. Open the repair job and find Device credentials.
  2. Choose Add credential and fill in the same fields.
  3. Choose Store encrypted.

Adding a credential on the job sets the job's access arrangement to credentials held. You cannot add credentials to a completed or cancelled job.

Who can reveal a password

A stored password can be revealed by:

  • The technician assigned to the job.
  • Store owners and admins.
  • Staff who have the Can reveal device credentials on any repair job permission.

Nobody else can see it. That includes the person who typed it in at the counter, unless they fall into one of the groups above. Staff who cannot reveal a credential see Assign yourself to view next to it.

Give a staff member reveal access

  1. Go to Settings → Users and edit the user.
  2. Under Permissions, tick Can reveal device credentials on any repair job.
  3. Choose Save.

The permission is shown for roles other than Admin and Owner, because admins and owners can already reveal. Without it, staff only see credentials on jobs assigned to them. See User Roles & Permissions.

Reveal a password

When a job is checked in with a stored login, the job page shows Device access provided at the counter and a Reveal credential button. You can also open Device credentials directly.

  1. Choose Reveal next to the credential.
  2. The password appears with Copy and Hide buttons.
  3. It hides again by itself after 60 seconds.

Reveal it when you are ready to use it, not at the start of the day.

Every reveal is recorded

Each time someone reveals a credential, ReturnMate records:

  • An entry in your audit log with who revealed it, when, and from which IP address and browser.
  • An internal note on the job's timeline, such as "Device credential viewed: Windows login". The note never contains the password.

The credential itself shows how many times it has been viewed and when it was last viewed.

These timeline notes are internal. They are not emailed to the customer and are never sent to a connected helpdesk.

Remove a credential

Choose Remove next to a credential to wipe it straight away. Anyone who can reveal it can remove it. The person who stored it can also remove it, so a typo at the counter can be fixed.

A removed credential stays in the list as wiped, with the date, so the job history is complete.

Automatic wiping

You do not need to remember to delete passwords. ReturnMate wipes every stored credential on a job:

  • When the item is collected. The handover screen reminds you how many credentials will be wiped when the handover is recorded.
  • When the job is cancelled.
  • When the retention period ends, even if the job is still open.

Set the retention period in Settings → Industry modules under Keep device credentials for (days). The default is 30 days, and you can choose from 1 to 90. The period starts when the credential is stored, and the auto-wipe date is shown on each credential.

Once wiped, the password cannot be recovered. If the technician still needs it, ask the customer again and add a new credential.

Long repairs

If a job may run longer than your retention period, the password will be wiped before the work is done. Either raise the retention period or ask the customer to unlock the device in person.

Where a password never appears

The password is only ever shown in the reveal on the job page. It is never included in:

  • Printed or emailed documents, such as the intake receipt, work order, completion report or collection record
  • Emails to the customer
  • The customer portal
  • Exports
  • Timeline notes or anything synced to a helpdesk

Customers are never asked for passwords when they book online. Passwords are always handled with your staff at check-in.

Keep passwords out of notes

Passwords, PINs and unlock codes typed into notes are refused. This covers the fault description, damage notes, the access note and notes elsewhere on repairs and returns. For example, "PIN: 1234" is refused, but "PIN pad is broken" is accepted.

If a note is refused, remove the password and store it in Device credentials instead.

Technician app

Device credentials are not available in the ReturnMate Tech app yet. Technicians who need a password reveal it from the job page in the ReturnMate admin. See ReturnMate Tech (Technician App).

Was this helpful?
Contact Support