# Password-protect a status page

A password turns a status page into an **unlisted** page: it keeps its address, but visitors must enter a shared
password before they see anything. Use it for an internal team page or a page for one client. It is simple shared
access, not per-person access control.

## Settings reference

| Setting (UI label) | Where | API field | Allowed values | Default | What it does for you |
|---|---|---|---|---|---|
| **Password** / **New password** | Wizard step 2 (**Access**), Settings tab (**Access** -> **Password protection**) | not in the API (read `hasPassword`) | Any text; empty for a public page | none (public) | Visitors must enter it to view the page. |
| **Remove password protection** | Settings tab (**Access**) | - | - | - | Makes the page public again. |

## Set a password

1. Open **Status pages**, click **Edit** on the page and go to the **Settings** tab.
2. In the **Access** card, under **Password protection**, type a **New password** and click **Set** (or **Change**
   when one is already set).
3. The card now reads "Your page is unlisted - a password is required to view it." The page shows a **Private**
   badge in your list of status pages.

You can also set it while creating the page, in the wizard's **Access** section ("Leave empty for a public page").

The password is stored hashed; HostTracker cannot show it to you later. To change it, set a new one.

## What visitors experience

- Opening the page, its history, an incident page or a service page shows a password prompt first.
- After the correct password, the visitor stays unlocked for **30 days** in that browser, on both
  `status.host-tracker.com/<slug>` and `www.host-tracker.com/status/<slug>`.
- Changing the password signs every visitor out; they need the new one.

## What the password turns off

Anything that could show the page's content without the prompt is disabled while a password is set:

| Surface | With a password |
|---|---|
| `status.json`, `sla-export.json` | 404 |
| RSS and Atom feeds | 404 |
| Embed card (`/embed`) and badge (`/badge.svg`) | 404; the editor hides the embed snippets and the **Share** menu's embed section |
| Email subscribe | Only after unlocking the page |

Search engines cannot index a password-protected page.

## Remove the password

In the same **Access** card, click **Remove password protection**. The page, its feeds, `status.json`, embed and
badge become public again at once.

## Do it with the API or MCP

The password is managed in the app only. The API and MCP report whether a page has one - `hasPassword` on
`GET /statuspage/{id}` and `get_status_page` - but cannot set or remove it. In Terraform, `has_password` is
read-only.

## Limits and gotchas

- **One password for the whole page.** There is no way to make some components public and others private on the
  same page. Use two pages - one public, one protected - and add the same monitors to both.
- **Share the address and password separately** (for example the link by email, the password by chat).
- A page for a client's team works well with password protection plus **Search engines: No-index** on plans that
  include it.

## Related

- [Create a status page](/status-pages/create/)
- [Embed and export a status page](/status-pages/embeds-exports/)
- [Let visitors subscribe](/status-pages/subscribers/)
