Password-protect a website directory
Add a separate login prompt in front of a directory, for example a private test area.
Where Tools → Files → Directory Privacy
Before you start
- Back up access configuration and identify the exact directory.
- Avoid protecting paths needed by payment callbacks, public APIs or certificate validation without a plan.
Steps
-
1
In the security settings, enable password protection for that directory and enter a name for the protected area.
-
2
Save the protection setting, then create an authorised user in the user section using a strong password. Enabling protection without a working user can lock everyone out.
-
3
Keep these credentials distinct from WordPress or cPanel login credentials. They are a separate web-server prompt.
-
4
To remove protection later, reopen the same directory’s settings, disable the protection control and save; review unused users separately.
-
5
Open Directory Privacy and browse to the intended folder. Clicking a directory opens it; use its Edit action to configure protection.
Browse to the correct directory before opening its protection settings.
Check it worked
- Open the directory URL in a private browser window and confirm it asks for credentials.
- Test the authorised login and check public parts of the site still work.