You onboard social media clients without collecting passwords by using permission-based access, which in practice means one of two things: the client grants your business partner access inside the platform's own settings, or you send them a connection link from your scheduler and they authorize each account themselves on the platform's own login screen.
No password changes hands in either version. That matters beyond tidiness, because password collection is the part of the old agency workflow that actively breaks things: it violates Meta's terms of service, it makes your login look like an account takeover, and it leaves you holding a spreadsheet of credentials that becomes a liability the day any client relationship ends.
A disclosure before the mechanics: we sell a scheduler with a connection link, so we are one of the vendors here. The limits further down apply to us as much as anyone.
Why Collecting Passwords Fails, Even When Clients Offer
Plenty of clients will happily text you their Instagram password, which is exactly why it needs saying that you should refuse. When you sign in with a client's credentials, the platform sees a new device, in a new city, on a new IP address, entering a stored password. That is the fingerprint of an account takeover, and platforms respond the way they are built to: security checkpoints, verification codes sent to a phone you do not have, temporary locks, and on Meta sometimes a full identity review. The client experiences this as you breaking their account, which is a hard conversation to have in week one. Two-factor authentication blocks the whole workflow anyway, since the code goes to the client's phone every time.
The workaround people reach for next is worse. Creating a fresh Facebook account for work, so your personal profile stays out of it, runs straight into Meta's fake-account detection, and those accounts get banned within days. Meta expects real, aged profiles with real history, so the fix is to use your actual profile with two-factor on and keep client access flowing through the permission systems below, which makes your profile a key rather than the workspace. The ban mechanics and the recovery path are in how to stop Meta from banning your Business Suite account, and Meta's eventual answer, work-only managed accounts, is still invitation-only, covered in getting access to Meta managed accounts faster.
Maeve for Agencies
One workspace per client, a connection link for onboarding, roles for your account managers, and approvals that run by link too. The declared interest behind this article.
See the agency workflowPlan, preview, and publish in one workflow
Path One: The Platform's Own Role System
Every major platform has an official way to grant a manager access without a password, and it is free. On Meta, the client gives your Business Portfolio partner access to their Facebook Page and Instagram account, and you assign those assets to your team members from your side. LinkedIn Pages have admin roles, TikTok has Business Center, Google Business Profile has manager invites, and Pinterest business accounts can add teammates. Once granted, you work from your own login, the client keeps ownership, and either side can revoke it in the platform's settings.
This is the right answer for ads, because ad accounts only move through Meta's partner system, and it is fine at a handful of clients. The problem is what it asks of the client. Partner access on Meta means knowing what a Business Portfolio is, finding a portfolio ID or accepting a request in the right place, and clicking through screens designed for marketers rather than for a cafe owner doing this once. In practice that is a call per client, or a screenshots-by-email exchange that runs for days. At fifty clients, an access path with a call in it is not a path.
Path Two: The Connection Link
The version that scales is a connection link, and the mechanics are what make it safe. Your scheduler generates a link tied to one client's workspace. You send it by email or text. The client opens it, sees the platforms you have asked them to connect, and taps each one. Each tap bounces them to that platform's own login page, on the platform's own domain, where they sign in as themselves and approve a specific list of permissions. The platform then issues the tool a scoped token, the same mechanism behind every Sign in with Google button. The client's password goes to the platform it belongs to and nowhere else.
Run onboarding this way and the client's whole job is one link and a couple of logins they already know. They never join your team, never see your other clients, and never touch a portfolio ID. Revocation stays in their hands the entire time, from the platform's connected-apps settings, which is a better security position than any password arrangement, and the comparison is laid out in how OAuth compares to handing over a password. What separates one implementation from another: whether the link covers the platforms your clients actually use, whether each client lands in a separate workspace, and whether you can resend it when the client swears it never arrived. In Maeve the link is per workspace and covers Instagram, Facebook Pages, LinkedIn, TikTok, YouTube, X, Threads, and Pinterest, and the same pattern handles client review and approval without a client login.
The Limits No Vendor Leads With
No connection link grants ads access, ours included. Boosting posts and running campaigns needs your Business Portfolio partnered with the client's ad account through Meta's own flow, so if you run ads, you are doing partner access for that piece regardless. Google Business Profile is patchy across the whole category because Google's API access for it is restrictive, so GBP usually means a manager invite done the platform-native way.
A few Instagram features are app-only no matter whose token you hold. The publishing API only works with professional accounts, so a personal account has to convert first, and interactive Story stickers and trending audio still live in the app. Scheduled Stories publish fine, but the occasional post that needs a poll sticker or a trending sound needs a thumb on a phone, so agree with the client early who that is. What still needs the app is mapped in do you log into client accounts on your phone, or just use scheduling tools. And authorizations expire, Meta's around 60 days, with a password change on the client's side killing a token early, so reconnection is a recurring part of agency life and a scheduler should warn you before a token dies rather than after a post fails.
The Onboarding Flow, Start to Finish
This holds up whether you are onboarding your third client or your hundredth. It assumes a scheduler with per-client workspaces and a connection link, with the platform-roles path slotting into step four for ads and Google Business Profile.
So the shape of the answer is a connection link for publishing and the analytics side of the work, platform partner access for ads and Google Business Profile, your own real profile with two-factor on as the only Meta login you ever use, and a written note per client covering the gaps. Password collection is the thing to eliminate, the link flow genuinely exists, and no single link does all of it. All three are true at once. What matters at scale is that the flow asks nothing of the client beyond logins they already know, and everything after it, the first-week setup and the approval rounds, can run over links too.
Related tools
Approval Without Client Accounts
The other half of link-based client work: posts reviewed and approved by link, no client login.
Maeve for Agencies
Client workspaces, connection links, roles, and reporting for teams running many accounts.
Client Reviews
Review batches with native previews, comments, and decisions on record.
Onboard the Next Client With a Link
Maeve gives every client workspace its own connection link: the client taps it, signs in on each platform's own login screen, and their accounts land in your workspace without a password ever passing through you. Connection links are on the Standard plan, with a 3-day trial.
Start planning in Maeve