To set up a Squarespace password protect page (a single page behind a password rather than the whole site), open the Pages panel, hover over the page, click its settings cog, scroll to Password, type a password (30 characters or fewer, case-sensitive) and save. A lock icon appears next to the page and visitors get a lock screen instead of the page. That is the whole feature, and it is fine for a client proofing page, a pricing guide for enquiries or a page you are still building. Where people get caught is what it does to Google, what happens on blog and portfolio pages, and the four-hour session limit, so those are covered before the alternatives.
How do you password-protect one page on Squarespace?
- In the Home menu, click Pages.
- Hover over the page and click the settings cog that appears.
- Under General, scroll down to Password and enter one. Squarespace’s page password guide sets the limit at 30 characters, case-sensitive, and warns never to reuse your account password.
- Click Save. A lock icon now shows beside the page title in the panel.
- Move the page to the Not Linked section so it drops out of your navigation, unless you want visitors to find the lock screen.
- Test it in a private browser window. Logged-in owners bypass the lock, so you cannot check it from your own session.
Visitors who enter the password stay in for four hours, then are asked again. There is no “log out” for them and no way to set a longer session. To change or remove the password, open the same settings and click the X in the field.
What do visitors see, and can you change it?
They see Squarespace’s grey lock screen with a password field. You can restyle it: in Design, open Lock Screen and add your logo, a background image, a headline and a short line telling them where the password came from (“Your gallery password is in your welcome email”). One lock screen design applies to every protected page and to a site-wide password, so keep the wording general.
Does a password-protected page get indexed by Google?
Not once the password is on, but timing matters. If you add the password before the page has any content, search engines never see it. If you protect a page that was already public, Google may have indexed it already; the password stops further crawling, but the old listing can sit in results for weeks with a lock screen behind it. For a page that must vanish from search quickly, add the password, then use the URL removal tool in Search Console. Files uploaded to the page before the password was set can stay indexed on their own; remove and re-upload them after the password is on.
| Method | Visitors | Best for | |
|---|---|---|---|
| Page password | Need the password | Not indexed | Client proofs, pricing guides, a page in progress |
| Site-wide password (Settings, Site Availability; Squarespace guide) | Need the password for every page | Not indexed | Sharing a whole site before launch; hiding a site while you build |
| Disable page | Page does not exist | Not indexed | Content you want to keep but nobody should see |
| Not Linked only | Anyone with the link | Indexed | Nothing private; it only hides the menu entry |
| Member Sites | Need an account | Not indexed | Paid or gated content for many people; page passwords are not available on member pages |
What happens with blog and portfolio pages?
A password on a collection page, which is what a Blog, Portfolio, Events or Store page is, protects the whole collection: every post, project or product under it. You cannot protect one blog post on its own with this feature. On version 7.0, index pages work the same way: a password on the index protects all the pages inside it. If you need one project private and the rest public, put it on its own page outside the portfolio and password that.
Photographers hit this most: a “client galleries” portfolio page with one password means every client can see every other client’s gallery. The fix is one page per client, each with its own password, or a gallery tool built for the job; Showit vs Pixieset explains why most photographers hand delivery to Pixieset or Pic-Time rather than password pages.
Can you password-protect several pages with one password?
Only by typing the same password on each page; there is no group setting. Each page still prompts separately. For a set of pages that belong together (a course, a resource library, an onboarding sequence), a single parent page with the password and links to the others is simpler, provided the others are protected too, because a link to an unprotected page is a public page.
Why is the password not working?
| Symptom | Cause | Fix |
|---|---|---|
| You cannot see the lock screen | You are logged in; owners and editors bypass it | Open the page in a private window |
| Visitors cannot get in | Passwords are case-sensitive; caps lock or a trailing space | Retype it in page settings and resend it |
| Contributor with viewer role is asked for the password | Expected; viewers do not bypass locks | Give them the password or an editor role |
| Page still shows in Google | It was indexed before the password | Request removal in Search Console and wait |
| Password field missing | The page is inside a Member Site | Use the member area settings instead |
| Password keeps changing itself | A password manager or extension is auto-filling the field | Disable it while editing page settings and type the password by hand |
| Protected posts still visible elsewhere | Summary or archive blocks can list items from a protected collection | Expected; visitors still need the password to open them |
| Analytics show no views | Views only count after the password is entered | Nothing to fix; that is how Squarespace counts them |
Page passwords are one of the small settings that decide whether a client feels looked after or exposed, which is why they sit on the launch checklist for every Squarespace site I build; the wider list is in the Squarespace tips post.
Frequently asked questions
Open Pages, hover over the page, click the settings cog, scroll to Password, enter a password of up to 30 characters and save. Move the page to Not Linked if you do not want it in the menu, and test in a private window.
No. A password on a Blog page protects the whole blog. To protect a single piece of content, put it on its own regular page and password that page.
Not if the password was set before the page had content. If the page was public first, Google may keep the old listing for a while; use the URL removal tool in Search Console to clear it.
Four hours. After that the visitor is asked for the password again. The session length cannot be changed.
Yes. In Design, open Lock Screen to add a logo, background, headline and message. One design applies to all protected pages and the site-wide password.
Because you are logged in. Site owners and editors bypass page passwords. Test the page in a private or incognito window.
