The request arrives in a chat, usually politely: send us your VFS login and password and we will take it from here. Sometimes it comes with a form that asks for the password alongside your passport number.
Do not. Not with us, not with anyone. And the useful part of this article is not the warning — it is the reason the job does not require it.
What changed in 2026
VFS tightened the booking flow. Two changes matter here.
A one-time code at confirmation. At the point an appointment is confirmed, the system sends a code to the applicant. Someone has to read that code back into the form within a few minutes or the booking does not complete.
The application reference bound to the booking. The appointment is tied to a specific application, not held as a generic slot that can be filled in later.
Both were introduced to stop appointments being captured and resold. Their side effect is the thing worth knowing: the applicant now has to be present for a few seconds at the end. That is not a limitation to work around. It is the part that makes a password unnecessary.
What the work actually requires
Watching a calendar and taking an appointment the second it appears is a technical problem. It needs to be done in your account, in your name, through the official system — and it needs you at the confirmation step, for the code.
So the shape of a legitimate arrangement is: you keep the credentials, you are reachable at the moment it matters, and the confirmation goes through with you in the loop. A few seconds of your attention, once, in exchange for not handing your identity to a stranger.
If a service tells you the password is unavoidable, one of two things is true. Either they are working in a way that does not survive the confirmation step, or they want the account for something other than your appointment.
What a real service will and will not ask for
Reasonable, at the right moment:
- The route, the visa category, how many applicants, roughly when you need to travel. That is enough to quote and to start.
- Later, in conversation, the details a booking form genuinely requires.
- Your availability around the confirmation step.
Never, and especially not on a public form:
- Your VFS account password.
- The one-time code from your email or phone. Not “in advance”, not “to save time” — a code handed over before it is needed is a code being used by someone else.
- Passport scans uploaded to a web form you reached from a search result.
- Payment before there is anything to pay for.
Our own request form asks five things and none of them are documents. That is deliberate, and it is the reason the page says so out loud.
The fear underneath this, and whether it is justified
The worry people actually have is not really about the password. It is: if I hand this over, can they take my money and disappear, or get my account banned, or ruin my application?
Worth separating.
Money. The exposure is entirely about when you pay. A service charging monthly for alerts has your money whether or not anything ever opens. A service charging after an appointment is booked does not. Ours is the second kind, and we would argue for it even if it were not — it is the only structure where our incentive and yours point the same direction.
Your account. Accounts get restricted for hammering the booking page and for duplicate registrations, not for using help. The codes that show up — 429202, 429001, 403201 and the rest — are rate limits, and the fastest way to trigger one is a person refreshing in a loop at three in the morning.
Your application. The consulate decides. Nobody can promise you a visa, and a service that does is telling you something it cannot know. What the appointment does is start the clock; the decision was never in anyone’s gift.
What makes it worse
- Reusing a password. If you have already given a VFS password to anyone, change it, and change it anywhere else you used the same one.
- Sending documents over a channel you did not choose. A link that arrives unprompted and asks you to upload a passport is the single most common shape of visa fraud, and official warnings say so.
- Believing a screenshot. Confirmed bookings, five-star reviews and busy dashboards are trivially fabricated. Reviews on a platform that verifies them, and a service that will say plainly what it cannot do, are worth more.
- Paying to “hold” a slot. Appointments are not held. That is the practice the tightening in 2026 was aimed at.
How we handle it
We never ask for your password, and the code stays with you. We will tell you before you commit what we have actually measured on your route, and we will tell you when the answer is that we have measured nothing. You pay after the appointment is confirmed.
If you want to see the shape of it first, how it works sets out the whole sequence, including the part where you read out a code.