Netlify password protection on a free plan
Netlify's shared password is a Pro feature, and new teams start private. What the free plans can do instead, and cheaper ways to put a password on a link.
By Mads Sauer, who makes ouicu, one of the tools here, so read it as a maker's comparison: each fact about another product links to that product's own page, read on . Published .
No: on Netlify, a shared password is a Pro feature. On Free and Personal, a private project opens only for you, and teams made since 28 July 2026 start private, previews included. So on a free plan a client gets a public link or nothing. To put a password on a preview without Pro, check it in your own code, or use a host that includes one.
What each plan allows
As of , from each product's own pages (listed under Sources). Prices in US dollars.
| Price | Private projects and passwords | |
|---|---|---|
| Free | $0, with 300 credits a month | “On a Free and Personal plan, private projects can only be seen by the Team Owner.” |
| Personal | $9 a month, with 1,000 credits | “On Free and Personal plans, projects are single-seat. To invite others, upgrade to Pro.” |
| Pro | $20 a month, with unlimited members | Public, private, or “password protected (only available on Pro)” |
| ouicu | Hobby, $4 a month | A password on any link; invited email addresses on Pro |
Private by default, previews included
Teams made from 28 July 2026 start private, and previews need a Netlify login. The default covers new projects however they are made, Netlify Drop included. Previews follow the same rule:
“Previews stay private unless you change the preview visibility setting.”
A client who opens a private preview meets a login, not your site: visitors without access see a Netlify page telling them to ask the owner. On Free and Personal you can't let them in, since nobody but you can be invited. Two side effects to know:
- “A private project cannot receive webhooks from services like Slack or Stripe.”
- Older teams differ: Enterprise, Open Source and legacy plans keep the older Password Protection settings.
The shared password, on Pro
On Pro, you choose the password under Project configuration > General > Visitor access > Project visibility, for production, for previews, or both. It is one password for everyone:
“Anyone can use your basic password to access a site deploy”
For a password on some paths only, or several passwords: a Basic-Auth rule in a _headers file protects chosen paths, on Pro and Enterprise.
/preview/* Basic-Auth: client:a-long-password“Basic authentication does not encrypt access credentials or provide a method for user-initiated logout.”
Pro also lets you invite the client by email instead, as a reviewer: “you must have a Pro plan or higher to invite someone with the Reviewer role to your plan.”
What to do on a free plan
Make the preview public
Anyone with the link sees it, and so can anyone they forward it to. Fine for a quick look at work that isn't secret.
Check a password in an Edge Function
Edge Functions can modify requests to authenticate users, so a function can answer with a basic auth prompt until the right password comes. It costs nothing but your time, and it is your code to keep secure.
Use a host with a free sign-in or a cheap password
- Cloudflare Pages: previews are public unless you turn on Access. Cloudflare Access sign-in, free up to 50 users.
- Vercel: Password Protection is not available on Hobby, and costs extra per project on Pro (Vercel password protection without Pro).
- ouicu: a password on any link from Hobby, $4 a month, for an uploaded build or your live dev server.
What you give up by leaving Netlify
- Previews per pull request. A production deploy costs 15 credits; Deploy Previews and branch deploys are unlimited. A ouicu upload replaces the last one under its name.
- Functions and server rendering.
ouicu deployuploads static files only (Uploading); a live share runs whatever your dev server does, while your laptop is on. - Feedback on the page. Reviewers leave visual feedback on Deploy Previews in the Netlify Drawer; ouicu has no comments.
Where Netlify is better
- A production deploy costs 15 credits; Deploy Previews and branch deploys are unlimited.
- Reviewers leave visual feedback on Deploy Previews in the Netlify Drawer.
If your team is on Pro anyway, the password costs nothing more, and reviewers can leave notes on the page itself.
Where ouicu fits better
- A password from Hobby, $4 a month, with no team or seats to set up. A browser that typed it stays in for 7 days.
- Clients invited by email with Pro: they type their address and get a link, with no account to make.
- An email when someone opens the link, with Hobby and Pro, and the last version kept up while your laptop sleeps, with Hobby and Pro.
Questions people ask
How can I password protect my Netlify site?
On Pro, set the project's visibility to password protected, or add a Basic-Auth rule to _headers. On Free and Personal, Netlify has no password option.
Is Netlify password protection free?
No. It comes with Pro, along with inviting reviewers.
Why does my Netlify preview ask for a login?
Your team is set to private projects, the default for teams made since the change above, and previews follow it. Make the previews public in the project's visibility settings, or invite the viewer on Pro.
Can a client see a private Netlify project?
On Pro, invite them as a reviewer and they log in to Netlify. On Free and Personal, only you can see it.
Try ouicu
Install it (Getting started), build the site, and upload it under a name with a password (Hobby and Pro):
npm run buildouicu deploy ./dist --name acme --passwordSources
Prices, defaults and quotes about other products, and the day each was last checked at its source.
- Project visibility, Netlify docs. Checked .
- Pricing, Netlify. Checked .
- Password Protection overview, Netlify docs. Checked .
- Basic authentication with custom HTTP headers, Netlify docs. Checked .
- Roles and permissions, Netlify docs. Checked .
- Edge Functions overview, Netlify docs. Checked .
- Preview deployments, Cloudflare docs. Checked .
- Access: pricing, Cloudflare. Checked .
- Password Protection, Vercel docs. Checked .