Decide which links actually need protection
Password protection makes the most sense for content meant for a specific, known audience — a client proof, an internal document, a pre-launch preview — rather than anything you eventually want broadly discoverable. If you're on the fence, ask whether you'd be comfortable with the link being forwarded once; if not, it's a good candidate for a password.
Create or edit the link and enable password protection
When creating a new short link (or editing an existing one) in your dashboard, turn on password protection and set the password itself. This applies at the link level, so the same destination can have a public link and a separate password-protected one if you need both versions to exist.
Choose a password that's memorable but not guessable
Since you'll likely be sharing this password verbally or in a separate message, favor something a legitimate recipient can type correctly without needing to copy-paste, while still avoiding anything trivially guessable like "password" or your company name. A short phrase or a memorable word-and-number combination usually strikes the right balance.
Share the password through a separate channel than the link
The entire point of password protection is defeated if you send the link and the password in the same message — anyone who intercepts or forwards that message gets both. Send the link by email and the password by text, or mention it verbally on a call, so the two pieces stay separated.
Test the protected link yourself before sending it
Open the link in a private/incognito browser window (so you're not accidentally already authenticated from creating it) and confirm the password prompt appears and that your password actually unlocks the destination. Catching a typo in the password field now saves an awkward back-and-forth with whoever you're sharing it with.
Set an expiration date alongside the password, if relevant
For time-sensitive content — a client proof under review, a limited preview window — pairing password protection with a link expiration date means the content becomes fully inaccessible after a set point, rather than just password-gated indefinitely. This is worth doing whenever the content genuinely shouldn't be reachable forever.
Know what visitors see when they enter the wrong password
A visitor who mistypes the password, or doesn't have it at all, sees a password prompt rather than the destination content — they aren't shown any preview of what's behind it. This is worth confirming yourself so you can accurately tell recipients what to expect if they hit that screen.
Update or remove the password later without breaking the link
If the audience for a piece of content changes, or you decide it's ready to go public, you can change or remove the password entirely from the same link — the URL itself doesn't change, so anyone who already has it will simply stop being prompted (or start being prompted with a new password, if you've changed it rather than removed it).
Combine password protection with other link controls
Password protection works alongside expiration dates, click tracking, and custom domains — none of these controls interfere with each other. A branded, password-protected, time-limited link is a genuinely useful combination for anything client-facing that needs to look professional and stay controlled at the same time.
Common mistakes to avoid
The most frequent misstep is sending the password in the same message as the link, defeating the point entirely. The second is forgetting the password was set at all and being confused later why a link "isn't working" — keeping a simple record of which links are protected and why avoids that confusion down the line.
Use it for internal sharing too, not just external clients
Password protection is just as useful inside a company as it is for external clients — an internal document, a not-yet-announced project page, or draft materials shared with a small review group all benefit from the same control, without needing to set up a separate internal login system just for occasional, low-stakes sharing.
Rotate the password if it's been shared more broadly than intended
If a password-protected link ends up being forwarded further than you meant it to — a common enough occurrence — changing the password immediately cuts off anyone who received it secondhand, while the link itself stays the same for people you want to keep giving access to. This is meaningfully faster than creating a whole new link and redistributing it to everyone who's supposed to retain access.
Decide whether the destination itself also needs its own protection
Password protection on the short link controls who reaches the destination through that specific link, but it doesn't protect the underlying page if someone finds it another way — through a search engine, a shared file link, or a direct URL. For genuinely sensitive material, check whether the destination page itself also needs its own access control, rather than relying on the short link alone as the only barrier.