Password-protect a Vercel preview without Pro
Vercel's Password Protection needs Pro and costs extra for each project. The free ways to keep a preview private, cheaper options, and what you give up.
By Mads Sauer, who makes ouicu, one of the tools here, so read it as a maker's comparison: each fact about another product links to that product's own page, read on . Published .
Vercel's Password Protection isn't on Hobby, and on Pro it costs extra for each project you protect, on top of the plan. If all you need is a password a client can type, there are cheaper ways: a Vercel login for the client, a Shareable Link, a few lines of middleware, or a host that includes passwords. Each gives something up, and this page says what.
The options, side by side
As of , from each product's own pages (listed under Sources). Prices in US dollars.
| Who gets in | What it costs | |
|---|---|---|
| Password Protection | Anyone with the password | $20 per month per protected project, on Pro. Not available on Hobby. |
| Vercel Authentication | Vercel users you let in | Vercel Authentication: on every plan, at no charge |
| A Shareable Link | Anyone with the link | Shareable Links: on every plan, but one link per account on Hobby |
| Your own middleware | Anyone with the password | No charge; it is your code to keep up |
| ouicu | Anyone with the password; invited emails on Pro | Hobby, $4 a month |
What Password Protection costs
Vercel's docs: “Password Protection is available on Enterprise and Pro plans”. It is not available on Hobby, and on Pro it is $20 per month per protected project, on top of the plan itself: a $20 monthly platform fee, with one deploying seat and $20 of usage credit. The pricing page adds: “Each protected project is charged separately.”
That is new. The per-project price arrived on 9 September 2026, and before it:
“Previously, Password Protection was available only through a $150-per-month team-level add-on that covered every project.”
For client work, Hobby was never the answer anyway: its docs say “the Hobby plan restricts users to non-commercial, personal use only”. So the real cost of a password is Pro, plus the charge for each client's project.
Every new preview asks again
Every deployment, preview or production, gets a URL of its own. The password is remembered per address:
“JWT tokens set as cookies are valid only for the URL they were set for and can't be reused for different URLs, even if those URLs point to the same deployment”
So a client types the password again for each preview link you send. With ouicu, the password belongs to a name, like acme.ouicu.app: a browser that typed it stays in for 7 days, while the name shows your latest upload or your live dev server.
Free ways in, and their catch
Vercel Authentication
It is free on every plan. The catch is on the client's side:
“Users attempting to access the deployment will encounter a Vercel login redirect.”
A Vercel user without access can ask for it, and you approve or decline. Hobby has a limit of its own: “Those on the Hobby plan can only have one external user per account.” A client without a Vercel account has to make one, just for your preview.
A Shareable Link
A Shareable Link lets anyone in through a query string parameter. Each link is made from one deployment's Share button, and it works for anyone who has it, forwarded emails included. On Hobby you get one.
A password in your own middleware
Vercel publishes an example that does it with basic auth: “Password protect pages in your application using Edge Middleware.” It costs nothing and keeps every Vercel feature. You maintain it, the browser's basic auth box is all the client sees, and Hobby's non-commercial terms still apply.
Another host
On Cloudflare Pages, previews are public unless you turn on Access, which signs visitors in with an emailed code: Cloudflare Access sign-in, free up to 50 users. Netlify keeps its shared password for Pro too (Netlify password protection on a free plan). ouicu puts a password on any link from Hobby, $4 a month.
What you give up by leaving Vercel
- Server rendering.
ouicu deployuploads static files: no functions, route handlers or rendering on request. A Next.js app needs a static export (Uploading). Shared live withouicu share, your dev server renders as usual, while your laptop is on. - A preview per commit. Vercel keeps each deployment at its own address. A ouicu upload replaces the last one under the same name, with no history.
- Comments and Git. People with access can comment on previews, and Vercel deploys on every push. ouicu has no comments, and you run
ouicu deployyourself or from your CI.
Where Vercel is better
- Every deployment, preview or production, gets a URL of its own.
- People with access can comment on previews.
- Vercel Authentication: on every plan, at no charge.
If the project already lives on Vercel and you bill the client for it, Pro with Password Protection keeps everything in one place.
Where ouicu fits better
- A password on every link from Hobby, $4 a month, with no charge per project.
- One name per client for the build, the live dev server and the last version, so the link and the password stay the same.
- Invited email addresses instead of a password, with Pro, and an email when someone opens the link, with Hobby and Pro.
- The last version stays up while your laptop sleeps, with Hobby and Pro.
Questions people ask
Is Vercel password protection free?
No. It isn't on Hobby, and on Pro each protected project costs a monthly fee on top of the plan, as the table shows.
How do I password-protect a Vercel preview on Hobby?
Not with Password Protection. Use Vercel Authentication, which asks for a Vercel login, or check a password in your own middleware.
How do I make a Vercel preview public?
Turn Vercel Authentication off in the project's Deployment Protection settings; “Disabling Vercel Authentication renders all existing deployments unprotected.” Or send a Shareable Link for one deployment.
Why does my Vercel preview ask me to log in?
Vercel Authentication protects previews, so visitors must log in to Vercel with an account that has access.
Try ouicu
Install it (Getting started), build the site, and upload it under a name with a password (Hobby and Pro):
npm run buildouicu deploy ./out --name acme --passwordSources
Prices, defaults and quotes about other products, and the day each was last checked at its source.
- Deployment Protection on Vercel, Vercel docs. Checked .
- Password Protection, Vercel docs. Checked .
- Usage & Pricing for Deployment Protection, Vercel docs. Checked .
- Vercel Pro Plan, Vercel docs. Checked .
- Password Protection is now available per project on Pro, Vercel changelog. Checked .
- Vercel Hobby Plan, Vercel docs. Checked .
- Accessing Deployments through Generated URLs, Vercel docs. Checked .
- Restrict access to deployments with Vercel Authentication, Vercel docs. Checked .
- Sharable Links, Vercel docs. Checked .
- Basic Auth Password Protection, Vercel on GitHub. Checked .
- Preview deployments, Cloudflare docs. Checked .
- Access: pricing, Cloudflare. Checked .