Knowledgebase / Security & SSL
How do I password protect a folder in cPanel?
Put a login prompt in front of a folder on your site with Directory Privacy in cPanel, then add the users who are allowed through.
Password protecting a folder puts a login prompt in front of everything inside it, so a visitor needs a username and password before any of those files load. It is a quick way to shield a staging copy of a site, a client download area, or an internal folder you would rather keep out of search results. You will need your cPanel login to follow along. If you are not sure how to get in, start with the cPanel login guide in /kb.
Turn protection on for the folder
- Log in to cPanel.
- In the Files section, open Directory Privacy.
- Browse to the folder you want to protect. Click a folder name to move into it, then click Edit beside the folder itself to open its settings. Website folders normally sit under public_html.
- Check the box labelled "Password protect this directory".
- Give the directory a name. This is the text the browser shows in the login prompt, so "Staging site" reads better than a raw folder name.
- Click Save, then Go Back.
Protection covers the folder and everything beneath it, subfolders included. Two cautions: avoid protecting the folder that holds your main site unless you want every visitor to see a prompt, and avoid protecting wp-admin on a WordPress site, since the extra login layer interferes with admin-ajax.php and breaks parts of the dashboard.
Add a user who is allowed in
Turning the box on does not create any accounts, so at this point nobody can get through, including you.
- Stay on the Directory Privacy settings page for that folder and find the Create User section.
- Enter a username and a password. Use the password generator if you like, and copy the password somewhere safe before you leave the page, because it is not shown again.
- Click Save.
The account now appears in the authorized users list. Add more users the same way. To revoke access, select the user and click Delete User.
Test the prompt
- Open a private or incognito window. Your everyday browser may already have the credentials cached, which makes a working prompt look broken.
- Visit the folder's web address, for example https://yourdomain.com/staging/.
- Enter the username and password you just created.
To lift the protection later, return to Directory Privacy, open the same folder, clear the checkbox and save. The users you created stay in the list in case you want the prompt back.
If it didn't work
- The wrong folder is protected. Directory Privacy lists paths relative to your home directory, so public_html/staging is the folder that answers at yourdomain.com/staging. Read the path shown at the top of the settings page before you save.
- No user has been created yet. A protected folder with an empty user list can show a prompt that refuses every password, or return a server error. Add at least one user and try again.
- Something else is editing .htaccess. cPanel stores these rules in an .htaccess file inside the folder. Security plugins, caching plugins and hand written redirect rules can overwrite or clash with them, which is the usual reason a prompt that worked yesterday has vanished today.
Still stuck? Send us the folder path through /support and we will check the rules on the server for you.
More in Security & SSL
Stuck partway through? Support is answered by the engineers who run the servers, around the clock.