Skip to the page

Guides

Password-protect a staging site

Keep work in progress away from strangers and search engines: a password on the link, or a list of the only people who may open it.

Updated

A staging site is usually public. Anyone who has the address can open it, addresses get forwarded, and a search engine that finds it may list pages that aren't ready. For client work, you want a lock on it.

The usual ways

  • Basic auth on your server, set up in its configuration with a file of usernames and passwords. Visitors get the browser's plain sign-in box, which asks for a username too and has no way to sign out.
  • A login in the site itself. It works, but it's code you write and keep up only for staging, and it changes the site you're testing.
  • A secret address. Anyone who has it can open it, and addresses travel in forwarded emails, chat previews and browser histories.

With ouicu, the lock is on the link. Your site doesn't change, and there is no server to configure. It works the same for a dev server shared from your laptop and for a build you uploaded.

Before you start

On macOS and Linux, install the command line tool with:

curl -fsSL https://ouicu.com/install.sh | sh

On Windows, run this in PowerShell:

irm https://ouicu.com/install.ps1 | iex

Then log in. It opens ouicu.com in your browser, where you approve this computer:

ouicu login

You need a ouicu account to log in. ouicu is in a closed beta, so accounts are for people we have invited: write to [email protected] to join.

Passwords come with Hobby and Pro, and invite lists with Pro. ouicu whoami shows your plan.

A password on a share or an upload (Hobby and Pro)

ouicu share 3000 --passwordouicu deploy ./dist --password

You type the password twice, and it isn't shown. In scripts and CI, set OUICU_PASSWORD instead, and ouicu reads it from there:

OUICU_PASSWORD="$PREVIEW_PASSWORD" ouicu deploy ./dist --password

Visitors see a page from ouicu asking for the password, not the browser's sign-in box. Once they type it, that browser stays in for 7 days. Passwords are 8 to 200 characters, ouicu keeps only a hash of them, and wrong tries are slowed down so a password can't be guessed by trying many.

A share's password lasts as long as the share. An upload's lasts until its next upload, so give each upload --password, or put the password on the name.

One password for everything under a name (Hobby and Pro)

A reserved name can carry the password. On the Shares page, open “Change who can open it” by the name and set it there. Every share and upload under the name then asks for it, unless it brings its own. Change the password and everyone is asked again.

This suits a client you show work to every week: one password, which each of their browsers asks for once a week at most.

Only the people you invite (Pro)

Instead of a password everyone shares, list the people who may open the link:

ouicu share 3000 --allow [email protected],[email protected]

@acme.com lets in everyone with an address at that domain. A list holds up to 50 entries, and your own address can always open your links. What your visitor does:

  1. They open the link, and ouicu asks for their email address.
  2. If the address is on your list, ouicu emails them a link. The page says the same either way, so it tells a stranger nothing.
  3. The link in the email works for 24 hours. It opens the preview in that browser for 7 days.

They need no account and have nothing to remember. A list can sit on a reserved name too, on the Shares page. To shut someone out, take them off it there: everyone is asked for their address again, so the person you removed is out straight away.

A share or an upload takes --password or --allow, not both.

Out of search results

Every page at a ouicu.app address is sent with X-Robots-Tag: noindex, nofollow, which asks search engines not to list it or follow its links. Behind a password or an invite list, there is nothing for them to read anyway. On a custom domain of yours, ouicu leaves that to your site.

Which to choose

Who can open a staging link
Who gets inPlans
Anyone with the linkEveryone who has itAll
A passwordEveryone who has the link and the passwordHobby and Pro
Invited peopleOnly the addresses you listPro

A password is quickest for a small team who can share one. An invite list is better when you want to know who opened it, or to let people go one at a time: on Hobby and Pro, your visitor emails name the invited people who opened the link.