Protection

Protection restricts who can see your site or parts of it, and it is a Pro plan feature. Reach for it when you want to share work in progress with a client, gate a private gallery, or publish internal documentation that should stay off the open web.

There are three levels.

Protect the whole site

Choose the level from the site settings:

  • Public, which is the default. Anyone can view the site.
  • Password protected. Every visitor must enter a password you set before any page will load, and the site’s media is covered as well.
  • Workspace protected. Only signed-in members of your workspace get in, so you never distribute a password and access follows your team.

The same setting is available through the API as protectionType, with pagesPassword for the site password. Switching to password protection requires a password in the same request unless one is already stored.

Protect a single page

On a public site, you can set a password on an individual page. Visitors see a password prompt instead of the content, and any media embedded in the page is protected along with it. The rest of the site stays public, so you can mix public and protected content freely.

Page passwords can be set in the page editor or through the API with the password field; an empty string removes the protection again.

If the whole site is workspace-protected, per-page passwords are unnecessary and unavailable, since every page is already behind sign-in.

Media follows its page

There is no separate password on an individual file. A media file is protected because the page it belongs to is protected, or because the whole site is protected. To share a protected file, protect the page that contains it.

Sharing a password

Anyone with the password can view the protected content, so treat it like a shared link: pick a password you are comfortable distributing and share it through a channel you trust. For a known team, workspace protection avoids sharing a password at all. For content that should be private to you alone, keep it as a draft instead of deploying it.