Publish and grow
Password protection
Keep your published app private with one shared password, and understand what changes for visitors, search engines and link previews.
Sometimes an app isn't meant for everyone yet: a site for a client to review, a tool for your team, or a launch you're not ready to announce. With Who can visit, you can put your whole published site behind a password. Visitors see a simple page asking for it before anything else loads.
The password covers your live site on every address it uses, including custom domains. It works on every plan.
Turn on a password
Open the Publish dialog
Click Publish at the top right of your project. Who can visit sits below the safety check.
Choose who can visit
Pick Only people with the password. The other option, Everyone, means anyone with the address can open your app.
Set the password
Type a password and click Save password. It needs at least 8 characters. Use one you don't use anywhere else, and share it only with people who should see the site.
Re-publish to apply it
The password goes live with your next publish. If your app is already live, you see "Your live site doesn't have this change yet." Click Re-publish now, and your live site gets the change in about a minute. If your app isn't published yet, the password applies when you first publish.
What visitors see
When someone opens your site, they see a small page with your site's title, the message "This site is private. Enter the password to continue.", a Password box and a Continue button. Once they enter the right password, they go straight to the page they were trying to open.
- They stay unlocked for 30 days in that browser, so they don't have to type it on every visit.
- A wrong password shows "That password isn't right. Try again." After too many wrong tries in a short time, they see "Too many tries. Wait a few minutes, then try again."
What changes when a site is private
Buildliy lists these consequences next to the option, so there are no surprises:
- Search engines won't list your site. It tells search engines to stay away.
- Link previews won't appear. When you share the address in a chat or on social media, the picture and title won't show.
- The "Report" link in the Buildliy badge only shows after someone unlocks the site.
- Webhooks keep working. Services like Stripe can still send updates to your app's webhook addresses (the ones with "webhook" in the address) without the password.
Change or remove the password
- To change it, click Change password, enter the new one and click Save password. Then re-publish. A new password signs everyone out, so people who had unlocked the site need the new one.
- To remove it, choose Everyone. You see "Password removed. Re-publish so everyone can visit again." Click Re-publish now to open the live site to everyone.
Who can change it
Only the workspace owner or an admin can set, change or remove the password. Other teammates can see whether the site is protected, with the note "Only the workspace owner or an admin can change this."
Buildliy stores only a scrambled version of your password, never the password itself, so it can't be shown again. If you forget it, set a new one and re-publish.
A password or user sign-in?
A site password is one shared password for everyone. It's great for keeping a whole site private while you show it to a few people. It doesn't give each person their own account or keep their data separate.
If you want people to sign up, log in and see only their own things, ask the AI to add sign-in instead:
Add sign-up and log-in. Only signed-in people can see the dashboard, and each person only sees their own saved items.
See User sign-in.
Related
Still stuck? Read the FAQ or contact us.