Skip to content

Protected Directories

Protects a directory of your website — or the whole website — with a browser password prompt. Meant for staging pages, internal areas, or content that is not supposed to be public yet.


Setting up protection

  1. Navigate to Protected Directories
  2. Choose Add
  3. Select the website
  4. Enter the path — relative to your website's main directory
  5. Give it a realm — the text shown in the browser's login prompt
  6. Set a username and password
Field Example
Path internal protects your-domain.com/internal
Path / protects the entire website
Realm Internal area

You can add several users for the same directory.


Lifting protection temporarily

Instead of deleting the entry you can disable it. Users and passwords are kept and protection can be switched back on at any time.


Forgotten password

Passwords cannot be displayed — they are stored encrypted. Simply recreate the user with a new password.


What the protection does — and does not

It prevents access to files. Whoever knows the password sees everything below it.

For an application with its own user roles — WordPress, for instance — that application's own login remains in charge. Directory protection is an extra hurdle in front of it, not a replacement.

Whole website rather than a single folder

If a staging site should not be public at all, protect it with the path /. The prompt then also covers PHP pages, not just images and files.