Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

Put a password on a folder of your website

This guide shows how to lock a folder so visitors must enter a username and password to open it.

Files and FTP2 min read15 steps

What is password protection?

When you protect a folder, the browser shows a small login box before the page opens. It is like a door with a lock. This is useful for private files, test sites or admin pages.

The lock is built with two small files. One is .htaccess, a settings file for Apache servers. The other is .htpasswd, which stores the usernames and scrambled passwords. cPanel can make both for you with a simple tool, so you do not have to type code.

Steps with the cPanel tool

  1. Log in to cPanel.
  2. In the Files or Security section, click Directory Privacy.
  3. If a box asks you to choose a starting folder, pick Web Root (public_html) and click Go.
  4. Click the folder you want to protect. Click the folder name, not its small icon, to open it.
  5. Tick Password protect this directory.
  6. Type a name for the folder in the Enter a name for the protected directory box. Visitors will see this name in the login box.
  7. Click Save.
  8. Click Go Back.
  9. Under Create User, type a username.
  10. Type a strong password and repeat it.
  11. Click Save.

Now visit the folder in your browser. A login box should appear. Enter the user details to get in.

Remove the protection

  1. Open Directory Privacy again.
  2. Select the folder.
  3. Untick Password protect this directory.
  4. Click Save.

Warning: do not protect your whole public_html folder unless you want the whole site locked. Also take a backup of your .htaccess file first. Wrong rules in it can cause a 500 error.

Tip: Passwords sent over plain http can be read by others. Use a site with an SSL certificate (https) so the login travels in a safe, scrambled form.

Troubleshooting

  • If the login box does not show, clear your browser cache and try again.
  • If you get a 500 error, restore your backup of .htaccess.
  • For more help, open a support ticket.

Quick recap

  • Use Directory Privacy in cPanel.
  • Choose the folder, tick the protect box and save.
  • Create a user with a strong password.
  • Back up .htaccess before changes.