What is password protection?
When you protect a folder, the browser shows a small login box before the page opens. It is like a door with a lock. This is useful for private files, test sites or admin pages.
The lock is built with two small files. One is .htaccess, a settings file for Apache servers. The other is .htpasswd, which stores the usernames and scrambled passwords. cPanel can make both for you with a simple tool, so you do not have to type code.
Steps with the cPanel tool
- Log in to cPanel.
- In the Files or Security section, click Directory Privacy.
- If a box asks you to choose a starting folder, pick Web Root (public_html) and click Go.
- Click the folder you want to protect. Click the folder name, not its small icon, to open it.
- Tick Password protect this directory.
- Type a name for the folder in the Enter a name for the protected directory box. Visitors will see this name in the login box.
- Click Save.
- Click Go Back.
- Under Create User, type a username.
- Type a strong password and repeat it.
- Click Save.
Now visit the folder in your browser. A login box should appear. Enter the user details to get in.
Remove the protection
- Open Directory Privacy again.
- Select the folder.
- Untick Password protect this directory.
- Click Save.
Warning: do not protect your whole public_html folder unless you want the whole site locked. Also take a backup of your .htaccess file first. Wrong rules in it can cause a 500 error.
Troubleshooting
- If the login box does not show, clear your browser cache and try again.
- If you get a 500 error, restore your backup of .htaccess.
- For more help, open a support ticket.
Quick recap
- Use Directory Privacy in cPanel.
- Choose the folder, tick the protect box and save.
- Create a user with a strong password.
- Back up .htaccess before changes.