Password Management

Hudu's password management system lets you create, manage, and securely share client passwords. The password manager includes:

  • Password and TOTP generation tools
  • PWNED (breached-password) counts
  • An Easy-Read feature that reveals the NATO phonetic spelling of a password
  • Simple, secure password share options
  • A browser extension to find and auto-fill stored passwords

Passwords are protected with AES 256-bit encryption, are searchable alongside the assets they reside in, and can be granted to different user roles based on their security group permissions.

    Visit Groups & Restrictions, Password Folders, and External Sharing for additional information on permissions, organization, and secure sharing.

Hudu stores three types of passwords:

  1. General passwords — stored within a specific client/company space and used for anything. They can be related to relevant assets or websites and restricted via security permissions.
  2. Embedded passwords — created via a confidential text field within an asset layout. Security permissions are inherited from the immediate parent asset, and these passwords do not appear in client password lists.
  3. Personal passwords — stored by technicians in their My Vault on the Hudu Toolbar. These can be imported from .csv or created manually with the password generator.

Guides

The sections below guide you through the creation, editing, and management of passwords. Access to passwords and these functions may vary depending on your Hudu user role and the security permissions set by the admin and super admin accounts at your organization.

Creating passwords

Passwords can be created in multiple ways. Expand the section that matches the type of password you're creating.

General passwords

To create, save, and organize general passwords. (To import passwords instead, see Importing Data.)

  • Navigate to a client/company space and open the Passwords tab on the left-side menu.
  • Click the (+) that appears when hovering over the Passwords tab, or click New Password in the top right.
  • In the New Password window, complete the fields:
    • Name — an easily identifiable name (e.g. "WordPress Admin").
    • External Sharing — choose whether the password is available in the portal.
    • Username (optional) — the name or email associated with the password.
    • Password — enter a secure password, or click Generate.
    • One-time password (optional) — enter the secret key from a third-party authenticator, or upload the QR code, and Hudu generates the 6-digit code (resets every 30 seconds). The secret key must be at least 16 characters and use Base32 formatting.
    • URL (optional) — a valid URL to tie to the password.
    • Notes (optional) — any relevant notes.
    • Parent (optional) — tie the password to relevant assets or websites (see Relating passwords under Tools).
    • Folder (optional) — place the password in an existing Password Folder.
    • Color (optional) — color-code the password.
    • Labels (optional): apply one or more labels to organize and filter passwords.
  • Click Create to finish, or Create and Add Another to keep adding passwords.

The New Password creation window with its fields.

Embedded passwords

Embedded passwords are credentials stored directly within an asset card (see Assets for more information). Creating them requires access to the admin tab.

  • From the admin tab, navigate to Hudu admin → Asset Layouts.
  • Click a specific asset layout (e.g. Desktops).
  • Click New Field and choose the Confidential Text field option. Give the field a name (e.g. "Administrator password for Desktop X").
  • Ensure the asset layout is active — you cannot complete the next steps on an inactive layout.
  • Return to an individual client/company page and open the asset layout you just edited. Then either:
    • Click + New in the top right to create a brand-new asset, or
    • Open an existing asset and click the Edit icon in the top right.
  • The password field is now visible and can be filled out.
  • Click Create or Update to save — field updates will not save otherwise.

Embedded passwords can be created manually or with the password generator, and the OTP generator can be used as well. As noted above, these passwords do not appear in a client's password list.

My Vault (personal passwords)

To create personal passwords. (To import personal passwords from .csv, see Importing Data.)

  • Click My Vault on the Hudu Dashboard (a person & lock icon in older versions) to open your personal vault.
  • Click + New to create a password entry.
  • In the New Personal Password window, complete the fields: Name, Username (optional), Password (or Generate), One-time password (optional; secret key must be at least 16 characters and Base32), URL (optional), and Notes (optional).
  • Click Create to finish, or Create and Add Another to continue.

The My Vault personal password view.

Passwords in My Vault can be imported in bulk or exported using the buttons in the top right, and My Vault folders can be used to organize them.

Editing passwords

Password details are changed from within the specific password. This applies to all password types.

  • Navigate into the specific password you'd like to update.
  • Click the Edit icon at the top right. You can change the name, username, password, OTP secret key, URL, notes, parent, and password folder or tags.
  • Update the details as required.
  • Click Update at the bottom of the screen — changes will not save otherwise.

Revision histories are found at the bottom of the right-hand sidebar when you're inside a password, by clicking a user's name in the Activity Feed. History dates back to password creation and includes OTP revisions. All password changes are tracked in the Activity Logs (entity-specific and global), visible only to admins and super admins.

Managing passwords

Keeping passwords organized helps ensure information stays accurate and up to date. This section applies to general passwords only. Expand each tool below.

Bulk Actions

Inside a client's password list, select the checkbox for one or more passwords to reveal Bulk Actions above the list. From here you can:

  • Move passwords to different client spaces,
  • Archive passwords to the Museum,
  • Permanently delete passwords, or
  • Change the passwords to a new folder.
Table View

Choose exactly which columns appear in the password list within a client/company space. Click the column visibility dropdown and select or deselect the columns you want to see.

The column visibility dropdown for the password list.

Individually manage

Within an individual password, click More Options at the top right to manage that password. You can Favorite, Archive, Delete, or move it to a new client/company space, and (with permission) Change Permissions and View Who Has Access.

Global Password View

To view passwords across all companies, open the Global section of the toolbar (only groups with Global access see this option), then select Passwords from the left-hand sidebar. Users in a security group only see passwords their permissions allow. Passwords in the Global view can be filtered by client/company using Filters, next to the search bar.

The Global passwords view listing passwords across companies.

Tools

The sections below introduce tools for password creation, organization, and management. Expand each for an overview.

Password Folders

Password folders are the primary tool for organizing passwords. Folders group a client's passwords and can be created at a global or client-specific level. Only admin and super admin users can create and edit folders, and a folder a user isn't permitted to access won't appear for them.

    Visit Password Folders for additional information.

Labels

Labels are color-coded markers you define once and apply across record types to organize and filter your data. Labels replace the previous password tags feature.

If your instance used password tags before, those tags were automatically migrated to labels. Each tag became a label scoped to Passwords and All companies with a default black color. You can review or update these under Admin > Labels.

To apply a label to a password:

  1. Open the password.
  2. In the right-hand sidebar, locate the Labels section.
  3. Click + Add and select one or more labels. Only labels scoped to passwords and that company will appear.

The Labels section appears only when at least one label exists that is scoped to passwords and that company.

To filter passwords by label, select Filters next to the search bar and choose one or more values under the Label filter. This works on both global and company password tables.

    Visit Labels for additional information on creating, scoping, and managing labels.

Flag

Flags can be added to any password — click the Flag icon in the top right.

    Visit Flag Types for additional information on creating different flags.

Password Generator

Use the password generator to create:

  • Unique, long, and complex passwords, or
  • Passwords that are easier to say, read, and remember.
TOTP Generator

The built-in TOTP generator supports traditional OTP code viewing, team collaboration, and secure external sharing. The secret key must be at least 16 characters and use Base32 formatting. If the vendor doesn't provide the secret key, extract it from the OTP URL or use a tool such as webqr.com.

    Visit Using the OTP Generator for additional information.

Sharing

For team or client access, use the quick share feature or portal sharing.

Quick share links can be created inside an individual password (if permitted by an admin/super admin). You can:

  • Set an expiration (30 minutes to 30 days),
  • Choose whether to include OTPs, and
  • Choose whether the link expires after the first view.

With the external share portal, you can give end-users branded, secure access to selected passwords. To share via the portal, click Add to Portal in the individual password view, or configure in bulk via the client's external sharing tab. The portal must be activated before sharing and can be turned on or off at any time.

    Visit External Sharing for setup instructions.

Reveal options

Within a password entry, you can copy and reveal the password or OTP. All reveals are logged and viewable by admins. OTP reveals include a countdown timer showing when the code expires. Once revealed, the Easy-Read function becomes available, using the NATO phonetic alphabet to simplify complex characters.

Relating passwords

Passwords can be related to client entities such as other passwords, KB articles, and websites. Passwords can also be created within an asset using the sidebar's password section; passwords created within assets are automatically added to the client's password section.

    Visit Relationships for additional information.

Additional Abilities

The sections below introduce additional features associated with passwords. Unless noted otherwise, these can be found at the bottom of the right-hand action menu when viewing an individual password.

Revision history

Revision histories provide a breadcrumb trail of when edits were made to a password, and by whom. To open it, click the name of the user who last performed an action. To view an older version, move down the timeline or select the Older Version button.

Activity logs

Activity logs provide detailed information on the actions performed on a specific password. Any action is recorded in the password-specific log and in the Hudu admin Global → Activity Logs. Logs can be filtered by client name, action performed, user who performed the action, or the IP address the action was performed from.

    Visit Activity Logs for additional information.

View who has access

This lets admins and super admins see who has access to a specific password (access can be denied via security groups).

  • Users with access are marked by a green check mark.
  • Restricted users are marked by a red X.
PWNED password monitoring

Hudu's password manager includes built-in dark-web monitoring for passwords via HaveIBeenPwned.

A PWNED count shown on a password.

View PDF

If a physical copy of a password is needed, click the Print icon in the top right to open a new tab with a printable version.

FAQ

How does dark-web monitoring with HaveIBeenPwned work?

Your password is never sent in plaintext. Only a short prefix of the password's hash (the first five characters) is sent and matched against known breached hashes using a k-anonymity model, so the full password is never exposed.

Troubleshooting

My password field is prefilling with the last password I created.

This is usually caused by an autofill feature — either the browser's or a third-party extension's. To stop it, disable the autofill/password feature in that password manager or browser.

My OTP won't work with Microsoft (or another Push 2FA product).

If the product supports Push 2FA, you must use its non-Push mode. The OTP will not work if you choose Push 2FA from Microsoft accounts or similar products.

    Visit Using the OTP Generator for additional information.

Was this article helpful?
1 out of 1 found this helpful