Skip to content

Password-protect a website directory

Add a separate login prompt in front of a directory, for example a private test area.

Where Tools → Files → Directory Privacy

Before you start

  • Back up access configuration and identify the exact directory.
  • Avoid protecting paths needed by payment callbacks, public APIs or certificate validation without a plan.

Steps

  1. 1

    In the security settings, enable password protection for that directory and enter a name for the protected area.

  2. 2

    Save the protection setting, then create an authorised user in the user section using a strong password. Enabling protection without a working user can lock everyone out.

  3. 3

    Keep these credentials distinct from WordPress or cPanel login credentials. They are a separate web-server prompt.

  4. 4

    To remove protection later, reopen the same directory’s settings, disable the protection control and save; review unused users separately.

  5. 5

    Open Directory Privacy and browse to the intended folder. Clicking a directory opens it; use its Edit action to configure protection.

    Browse to the correct directory before opening its protection settings.

Check it worked

  • Open the directory URL in a private browser window and confirm it asks for credentials.
  • Test the authorised login and check public parts of the site still work.