Password-protect a site

Updated 11 June 2026

On paid plans, any Nippy site can be put behind a password — a client gallery, a folder of documents, a draft website. Visitors who open the link see a password form and nothing else: no file names, no thumbnails, no page content is served until the right password is entered.

Setting it up takes seconds: open the site’s Settings tab, set a password, and share it alongside the link with the people who should get in. The protection covers everything on the site — pages, photos, file listings, and zip downloads alike. Changing the password immediately signs out everyone who got in with the old one, so access can be rotated when a project ends; removing the password makes the site public again.

Protected sites also stay out of search results, since search engines can’t see past the password form any more than other visitors can. For something that should be findable later, leave it public — passwords are for the things that shouldn’t be.

Step by step

  1. 1

    Set the password in Settings

    Open the site in your dashboard, go to the Settings tab, and set a password. Protection starts immediately.

  2. 2

    Share the link and the password

    Send both to the people who should get in — on the thank-you card, in the client email, wherever fits. Visitors enter it once and browse normally.

  3. 3

    Rotate or remove when you’re done

    Change the password and everyone using the old one is signed out instantly. Remove it and the site is public again.

Common questions

What do visitors see before entering the password?

A password form and nothing else. File names, thumbnails, page content and downloads are all withheld until the correct password is entered.

What happens when I change the password?

Everyone who signed in with the old password is locked out immediately — handy for rotating access between projects or after a deadline.

Can search engines index a protected site?

No — crawlers hit the same password form as everyone else, so nothing behind it can be read or indexed.

Can I protect just one folder?

Protection is per site, not per folder. If some files should be public and some private, put the private ones on their own site and protect that.

Which plans include password protection?

Any paid plan — and it can be enabled or removed at any time per site.

More guides

Still stuck?

Our team is happy to help with anything Nippy.

Get in touch