Want to keep part of your website private - a client preview, a staging copy or a folder of documents? cPanel's Directory Privacy tool lets you password-protect a folder so visitors must enter a username and password before they can see anything in it. This guide shows you how to set it up on your Instant Access Internet Services account, add users and remove the protection later.
How folder password protection works
- When someone visits the protected folder in a browser, they get a login pop-up. Without the right username and password, they see an "Unauthorized" error.
- Protection covers the folder and every folder inside it.
- The usernames you create are only for this folder. They're separate from your cPanel, email and WordPress logins.
- It only protects web access. Anyone with FTP or cPanel access can still see the files.
- Always use
https://for protected pages so the password is encrypted in transit. See How to Force HTTPS on Your Website.
Step 1: Turn on protection for the folder
- In cPanel, go to Files > Directory Privacy.
- You'll see a list of folders in your account. Click a folder's name to open it and see the folders inside (your website is in
public_html). - When you've found the folder you want to protect, click Edit in the Actions column next to it.
- Tick Password protect this directory.
- In Enter a name for the protected directory, type a label such as
Client Preview. This is just a label - it doesn't rename the folder. - Click Save, then click Go Back.
Step 2: Create a user who can log in
Protection doesn't let anyone in until you add at least one user.
- On the same page, under Create User, enter a Username.
- Enter the password twice, or click Password Generator for a strong one. The strength meter must reach the required level.
- Click Save, then Go Back.
Add as many users as you need - for example one per person, so you can remove someone later without changing everyone's password.
Step 3: Test it
Open a private/incognito browser window and visit the folder, for example https://example.com/preview/. You should get a login prompt. Enter the username and password you created. A private window matters because browsers remember these logins until they're closed.
Change a password, remove a user or turn protection off
- Change a user's password: under Create User, enter the existing username with the new password and click Save.
- Remove a user: select them in the Authorized Users list and click Delete User.
- Turn protection off: untick Password protect this directory and click Save.
In the folder list, a lock icon shows which folders have Directory Privacy settings.
Troubleshooting
The login box keeps coming back even with the right password
Check for typos and extra spaces - usernames and passwords are case-sensitive. If you just changed the password, close every browser window (or use a private window) so the browser stops sending the old one. Reset the password as described above if you're not sure.
My whole website is asking for a password
You probably protected public_html instead of a folder inside it. Open Directory Privacy, click Edit next to public_html, untick Password protect this directory and click Save.
Can I protect my WordPress admin (wp-admin)?
You can, but it often breaks things: many WordPress features and plugins call wp-admin/admin-ajax.php from public pages, and those calls will fail behind a password. For WordPress, use WP Toolkit's security hardening and two-factor login instead - see How to Secure WordPress with WP Toolkit Security Hardening. To keep a whole WordPress site private while you build it, you can protect its folder, or use maintenance mode (see How to Put WordPress in Maintenance Mode).
I get a "500 Internal Server Error" after turning on protection
Directory Privacy writes rules into the folder's .htaccess file. If that file already contained a mistake, the site can error. Check the .htaccess file in that folder (see How to Show Hidden Files (.htaccess) in cPanel File Manager and How to Edit a File in cPanel File Manager), or open a ticket and we'll take a look.
I can't create a user
Check the password meets the strength requirement. If it still fails, open a support ticket and tell us which folder you're protecting.
Related guides
- How to Use cPanel File Manager to Manage Your Website Files
- How to Turn Directory Listings On or Off in cPanel (Indexes)
- How to Secure WordPress with WP Toolkit Security Hardening
- How to Force HTTPS on Your Website
Still stuck? Open a support ticket and the Instant Access Internet Services team will help.
