Anyone With the Link Can Still Find a Password-Protected Page. They Just Can't See What's On It.

Anyone With the Link Can Still Find a Password-Protected Page. They Just Can't See What's On It.

A photographer friend of mine used to text me screenshots of half-finished galleries before he'd send a client the real link, just to make sure nothing embarrassing was showing. That's the exact problem Cantrip's password gate solves, and it's sitting in every page's settings already. No plugin, no separate login system to bolt on.

Turn it on for a page and here's what actually happens, not the marketing-brochure version. A visitor without the password doesn't get a locked-looking page with your real content quietly sitting in the HTML underneath, hidden by some CSS overlay the way a few builders fake this. Cantrip strips the content out of the response on the server before it ever reaches a browser. Look at the page source on a gated page you don't have the password for and there's nothing there to find. Type the right password and the server checks it against a hash that never leaves our end, then remembers you for that browsing session so you're not retyping it on every click.

"That session" matters more than it sounds. It's good for a couple hours of browsing, not a permanent login. Step away and come back later and you're typing the password again. Fine for a portfolio that's still being built, or a page you only want a specific group finding. Not fine if what you actually wanted was separate logins for separate clients, each seeing their own thing. Cantrip's gate is one password, shared by whoever you hand it to. Right password gets you in. It doesn't know or care who you are beyond that. If you need real per-client accounts, that's a heavier tool than a password field, and this isn't pretending to be it.

One quiet benefit you don't have to ask for: a password-protected page never shows up in your site's sitemap.xml. You don't have to remember to pull it out yourself. What it won't do on its own is mark the page noindex. So if a search engine already picked up that URL some other way, maybe an old link, maybe a sitemap from before you turned protection on, the gated version can still technically get indexed. It just shows nothing but a password box. Want it fully gone from search too, not just polite about it? Check the noindex box in the same page settings. Two separate switches, two different jobs.

Set the password through the page editor, or hand the same job to an AI assistant through Cantrip's MCP tools or API, since it's the exact same field either way. What doesn't change no matter which path you use: the password itself never touches anything on our end except a hash.