Password-protect a status page
A password turns a status page into an unlisted page: it keeps its address, but visitors must enter a shared password before they see anything. Use it for an internal team page or a page for one client. It is simple shared access, not per-person access control.
Settings reference
Section titled “Settings reference”| Setting (UI label) | Where | API field | Allowed values | Default | What it does for you |
|---|---|---|---|---|---|
| Password / New password | Wizard step 2 (Access), Settings tab (Access -> Password protection) | not in the API (read hasPassword) |
Any text; empty for a public page | none (public) | Visitors must enter it to view the page. |
| Remove password protection | Settings tab (Access) | - | - | - | Makes the page public again. |
Set a password
Section titled “Set a password”- Open Status pages, click Edit on the page and go to the Settings tab.
- In the Access card, under Password protection, type a New password and click Set (or Change when one is already set).
- The card now reads “Your page is unlisted - a password is required to view it.” The page shows a Private badge in your list of status pages.
You can also set it while creating the page, in the wizard’s Access section (“Leave empty for a public page”).
The password is stored hashed; HostTracker cannot show it to you later. To change it, set a new one.
What visitors experience
Section titled “What visitors experience”- Opening the page, its history, an incident page or a service page shows a password prompt first.
- After the correct password, the visitor stays unlocked for 30 days in that browser, on both
status.host-tracker.com/<slug>andwww.host-tracker.com/status/<slug>. - Changing the password signs every visitor out; they need the new one.
What the password turns off
Section titled “What the password turns off”Anything that could show the page’s content without the prompt is disabled while a password is set:
| Surface | With a password |
|---|---|
status.json, sla-export.json |
404 |
| RSS and Atom feeds | 404 |
Embed card (/embed) and badge (/badge.svg) |
404; the editor hides the embed snippets and the Share menu’s embed section |
| Email subscribe | Only after unlocking the page |
Search engines cannot index a password-protected page.
Remove the password
Section titled “Remove the password”In the same Access card, click Remove password protection. The page, its feeds, status.json, embed and
badge become public again at once.
Do it with the API or MCP
Section titled “Do it with the API or MCP”The password is managed in the app only. The API and MCP report whether a page has one - hasPassword on
GET /statuspage/{id} and get_status_page - but cannot set or remove it. In Terraform, has_password is
read-only.
Limits and gotchas
Section titled “Limits and gotchas”- One password for the whole page. There is no way to make some components public and others private on the same page. Use two pages - one public, one protected - and add the same monitors to both.
- Share the address and password separately (for example the link by email, the password by chat).
- A page for a client’s team works well with password protection plus Search engines: No-index on plans that include it.

