Skip to content

Password-protect a status page

View as Markdown

A password turns a status page into an unlisted page: it keeps its address, but visitors must enter a shared password before they see anything. Use it for an internal team page or a page for one client. It is simple shared access, not per-person access control.

Setting (UI label) Where API field Allowed values Default What it does for you
Password / New password Wizard step 2 (Access), Settings tab (Access -> Password protection) not in the API (read hasPassword) Any text; empty for a public page none (public) Visitors must enter it to view the page.
Remove password protection Settings tab (Access) - - - Makes the page public again.
  1. Open Status pages, click Edit on the page and go to the Settings tab.
  2. In the Access card, under Password protection, type a New password and click Set (or Change when one is already set).
  3. The card now reads “Your page is unlisted - a password is required to view it.” The page shows a Private badge in your list of status pages.

You can also set it while creating the page, in the wizard’s Access section (“Leave empty for a public page”).

The password is stored hashed; HostTracker cannot show it to you later. To change it, set a new one.

  • Opening the page, its history, an incident page or a service page shows a password prompt first.
  • After the correct password, the visitor stays unlocked for 30 days in that browser, on both status.host-tracker.com/<slug> and www.host-tracker.com/status/<slug>.
  • Changing the password signs every visitor out; they need the new one.

Anything that could show the page’s content without the prompt is disabled while a password is set:

Surface With a password
status.json, sla-export.json 404
RSS and Atom feeds 404
Embed card (/embed) and badge (/badge.svg) 404; the editor hides the embed snippets and the Share menu’s embed section
Email subscribe Only after unlocking the page

Search engines cannot index a password-protected page.

In the same Access card, click Remove password protection. The page, its feeds, status.json, embed and badge become public again at once.

The password is managed in the app only. The API and MCP report whether a page has one - hasPassword on GET /statuspage/{id} and get_status_page - but cannot set or remove it. In Terraform, has_password is read-only.

  • One password for the whole page. There is no way to make some components public and others private on the same page. Use two pages - one public, one protected - and add the same monitors to both.
  • Share the address and password separately (for example the link by email, the password by chat).
  • A page for a client’s team works well with password protection plus Search engines: No-index on plans that include it.