Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

Password Protect One File in cPanel

This guide shows how to ask for a user name and password before anyone can open a single file on your website.

Files and FTP2 min read13 steps11 screenshots

How does it work?

cPanel is the control panel of your hosting. Its Directory Privacy tool locks whole folders. To lock only one file, you add a few lines to a file named .htaccess. This is a small settings file that Apache, the web server software, reads. Passwords for it are kept in a file named .htpasswd. The dot at the start of the name makes the file hidden.

Warning: A mistake in .htaccess can break your whole site. Download a copy of the file first.

Step 1: make the password file

  1. Log in to cPanel from your client area.
  2. Open Directory Privacy in the Files section. Choose any folder, such as the one with your file, and click Edit.
  3. Tick Password protect this directory and give it a name.
  4. Click Save.
  5. Under Create User, type a user name and a strong password, then click Save.

This makes the user and the .htpasswd file. It also locks the whole folder, which we will fix in the next step.

Step 2: lock only one file

  1. Go back to cPanel and open File Manager.
    Screenshot: Go back to cPanel and open File Manager .
    Screenshot: Go back to cPanel and open File Manager .
    Screenshot: Go back to cPanel and open File Manager .
    Screenshot: Go back to cPanel and open File Manager .
    Screenshot: Go back to cPanel and open File Manager .
  2. Open the folder you chose. Click Settings at the top right and tick Show Hidden Files. Click Save.
  3. Right-click .htaccess and choose Edit.
    Screenshot: Right-click .htaccess and choose Edit .
  4. Remove the lines added by Directory Privacy, or keep them and move them as shown below.
  5. Type the lines below. Replace secret.pdf with your file name, and use the path cPanel showed for your .htpasswd file.
    Screenshot: Type the lines below. Replace secret.pdf with your file name, and use the path cPanel show
<Files "secret.pdf">
AuthType Basic
AuthName "Restricted File"
AuthUserFile /home/youruser/.htpasswds/public_html/passwd
Require valid-user
</Files>

This tells the server to ask for a password only when someone opens secret.pdf.

  1. Click Save Changes.
  2. Open the file link in a private browser window. A login box should appear.
  3. Open another file from the same folder. It should open freely.
Tip: The exact AuthUserFile path can differ. Copy it from the lines cPanel wrote in .htaccess.

Quick recap

  • Use Directory Privacy to create the user and password file.
    Screenshot: Use Directory Privacy to create the user and password file.
    Screenshot: Use Directory Privacy to create the user and password file.
    Screenshot: Use Directory Privacy to create the user and password file.
    Screenshot: Use Directory Privacy to create the user and password file.
  • Use a <Files> block in .htaccess to lock one file.
  • Back up .htaccess first.
  • Test in a private window.