Webflow maintenance

How do I password protect a page in Webflow?

Turn on a password for one page, a folder, or the whole site, then publish so visitors hit the password page.

THE SHORT ANSWER

Open the Pages panel, open the page settings, turn Password protection on, set a unique password, save, and publish. Page and folder passwords need a Site plan. A folder password replaces passwords on pages inside it. A site-wide password replaces those until you turn it off. Visitors land on the password page. Uploaded files stay publicly reachable.

Protect one page when a draft is the wrong tool

A draft stays off the live site. A password is for a URL you do want to publish, but only for people who have the password. That fits a client preview, internal notes, or a prototype you will share with one group.

Open the Pages panel. Click the settings icon beside the page. In General, turn Password protection on, type a unique password, save, and publish. Until you publish, the live URL does not ask for the password.

Page and folder passwords need a Site plan. For example: leave the public marketing site open, and put a password only on /spring-preview so a client can review that page before launch.

If you do not need anyone to open the page yet, save it as a draft instead of inventing a password you will have to remember.

Use a folder or a Collection when many URLs share one password

Each page can have its own password. If several pages should share one, put them in a folder and set the password in the folder settings, then publish. A folder password overwrites passwords already set on pages or folders inside it. Child pages and folders inherit the parent folder password.

You can also lock every item page in a Collection. Open the Collection template in the Pages panel, turn Password protection on, set the password, save, and publish. Anyone who opens an item URL from that template sees the password page. Use this while the template is still in progress, not as a way to hide a single post. One template password covers the whole Collection.

A site-wide password replaces the others

To lock every domain while you test, go to Site settings, General, Website password. Turn Password protection on, set a password, click Set password, and publish.

That switch is available on a paid Site plan (Basic, CMS, Business, or Ecommerce). It is also available on free or paid sites in a Growth, Agency, or Enterprise Workspace. It is not available for a free, unhosted site in a free Workspace.

A site-wide password overwrites passwords on pages and folders. You cannot add a new page or folder password until you remove the site password. If the homepage and a private preview need different rules, do not turn on the site password. Protect only the preview page.

Design the page people see before they enter

A locked URL sends the visitor to the password page. Open it from Pages panel, Utility pages, Password page. You can restyle the layout and add your own elements. You cannot delete the password form or the submit button. You can edit the message shown for a wrong password: select the form, open Form settings, choose the Wrong password state, and change the text.

The password page slug is reserved as /401. You can rename the page in the panel. You cannot change that slug.

Remove the lock, then publish again

To open a page, folder, or Collection template, set Restrict access to Public, save, and publish. To open the whole site, turn Password protection off under Website password and publish.

After either change, open the live URL in a private window. A cached visit can still look locked or still look open. Also remember the file warning: a password on the page does not make an uploaded PDF or image private. If a file must stay confidential, do not upload it to the site.

Questions & answers

Why can I not turn on a password for a single page?

Page and folder passwords need a Site plan. A free unhosted site in a free Workspace also cannot use a site-wide password. A site in a Growth, Agency, or Enterprise Workspace can use a site-wide password.

Does a site password keep my page passwords?

No. A site-wide password overwrites page and folder passwords. You cannot set new page or folder passwords until you turn the site password off in Site settings and publish.

Are images on a locked page private?

No. Files uploaded to Webflow stay publicly available. The password stops people from opening the page. It does not lock the file if someone has the file address.

How do I take the password off?

For a page, folder, or Collection template, set Restrict access to Public, save, and publish. For the whole site, turn Password protection off under Site settings, General, Website password, then publish.

Sources & further reading

Need a hand with your Webflow site?

View membership