Sharing & hosting

How to password-protect a website before it's ready to launch

1 September 2026 · 2 min read

Publishing a site and making it public don't have to happen at the same time. A client review draft, a redesign you're not ready to announce, a portfolio piece you want one person to see before anyone else, all of these need to be live somewhere real, just not visible to whoever stumbles across the link. On MakeMySiteLive, password protection is available on Pro full sites.

Live and public aren't the same thing

Once a site is published it has a real URL, real HTTPS, and works exactly like a finished site would. None of that requires it to be open to anyone who finds the address. Password protection sits in front of the site itself: visitors hit a login screen first, and only get through with the password you set.

Turn it on

On a Pro full site, password protection is a toggle in the dashboard. Set a password, save it, and every visitor to that subdomain or custom domain sees a login screen before anything else, no separate setup, no code to add to your files. Microsites and Free full sites don't support this gate.

Who this is for

A client reviewing a draft before it's announced. A redesign you're testing before the old site comes down. A private portfolio piece you're sending to one recruiter, not indexing for search. A page you're still actively editing and don't want half-finished in front of the public yet.

Turning it off when you're ready

The same toggle removes it. Nothing about the site's files, its address, or its version history changes, the password is a gate in front of the site, not a property of the site itself. Flip it off the moment it's meant to go fully public.

It's a real toggle, not a URL trick

Some hosts fake privacy with an unlisted or hard-to-guess link, which still works for anyone who has it. Password protection actually checks a password before showing anything, so sharing the plain link by accident doesn't expose the site.

Key takeaways

  • Password protection is a Pro-full-site toggle, not a separate setup step or a code change.
  • A protected site is still fully live and HTTPS-secured, just gated behind a login screen first.
  • It's meant for review drafts, private portfolios, and pages you're still editing, not for content you never intend to make public.
  • Turning it off doesn't touch the site's files or version history, it just removes the gate.
  • It checks an actual password, unlike an unlisted link anyone with the URL can still open.

Frequently asked questions

Does password protection require any code changes?

No. On a Pro full site, it's a dashboard toggle and nothing is added to your uploaded files. Microsites and Free full sites don't support password protection.

Can I remove the password once the site is ready to launch?

Yes, the same toggle removes it instantly, without touching the site's files or its version history.

Is a password-protected site still indexed by search engines?

No, a login screen blocks crawlers the same way it blocks anyone else, so search engines can't see behind it.

Is this different from just using a hard-to-guess subdomain?

Yes. An unlisted link still works for anyone who has it. A password actually has to be entered before the site loads, so an accidentally shared link doesn't expose anything.

Share this article

Keep reading

More from the blog

Ready to go live?

Create a free account and publish your first site in 2 minutes.

Get started free