tuqo
Privacy without a server

Gated access to a site: password, email code, channel subscription or payment

The site opens only for people you give access to. No server, no .htaccess, no sign-up for visitors. Every file is protected — pages, images, PDFs.

In the panel, it's the Visibility tab on the site page.

1

Choose how to gate the site

Password — one secret for everyone that you can read out over the phone. Email code — sign-in by a list of addresses. Subscribers only — the site opens for subscribers of your Telegram/MAX channel. Member sign-up — visitors sign up themselves. Paid access — entry is sold through your own acquiring. You switch modes in the Visibility tab and changes apply at once.

2

Send the link

The site address stays the same. Only what a person without a pass sees changes: instead of pages, your login screen with your logo and text.

3

Add limits if needed

An access period and a number of opens. Access closes by itself on the day you set — no need to ask a client to “stop visiting”.

Five ways to gate a site

All five gate the whole site. The difference is who you give access to: one secret for everyone, a named list, your channel's subscribers, everyone who signs up — or those who paid for entry. Each mode has its own page with the details.

Password for the whole site

Start plan or 199 ₽/mo add-on

One secret for everyone. A visitor enters it once and gets the whole site — pages, images, PDFs and any other files.

Three levels: the simple one is easy to say aloud, the strong one is copy-only
Or set your own password
The password stays visible in the panel — forgot it, look it up instead of sending a new one
Changing the password logs out everyone who signed in

When it fits. When there are only a few recipients and you talk to them directly: a client, family, a contractor.

Learn more →

Email code

Pro plan or 299 ₽/mo add-on

No shared secret. A visitor enters their address, gets a six-digit code by email and signs in. Only people on your list get in.

A list of up to 1,000 addresses: one by one or pasted in bulk
A name next to each address — the log shows a person, not a mailbox
See who signed in, when, and on how many devices
Remove an address — one person loses access, the rest don't notice

When it fits. When there are many recipients and the group changes: a course cohort, a department, a list of investors.

Learn more →

Channel subscribers only

Pro plan or 299 ₽/mo add-on

The site opens only for subscribers of your Telegram/MAX channels. A visitor taps “Check subscription”, confirms it in the bot and gets in. Your content helps the channel grow.

Up to three channels or groups — access for people subscribed to all of them
No passwords or lists: the subscription itself is the check
Channel name, description and avatar right on the login screen
The bot needs no posting rights — it only has to see members

When it fits. When the site is a bonus for your audience: an expert's handbook, a knowledge base, closed community materials.

Learn more →

Member sign-up

Pro plan or 299 ₽/mo add-on

No lists — visitors sign up themselves: email, name, consent to your documents and a code from an email. Want to filter at the door? Turn on request moderation.

Sign-up = sign-in: there are no passwords
Up to three of your own documents + consent via a button or checkboxes
Request moderation and a seat limit
Member log, bans, emails in your site's name

When it fits. When you can't collect the audience into a list upfront: an open course, a club, a community.

Learn more →

Paid access

Pro plan or 499 ₽/mo add-on

A storefront with price and perks, payment through your own acquiring — T-Kassa or YooKassa. The money goes straight to you: Tuqo takes no fee on sales.

One-time payment for lifetime access, or access for a period
Your own acquiring: 0% platform fee
Test and live terminals with a checklist
A refund closes access automatically

When it fits. When your materials are worth money: a paid course, a handbook, a private archive.

Learn more →

Which mode to choose

Password Email code Subscribers only Member sign-up Paid access
Who gets access Anyone who knows the secret A named list of addresses Subscribers of your channels Anyone who signs up People who paid
What the visitor does Enters the password Enters their email and a code from the inbox Confirms the subscription in a bot Email, consent and a code from the inbox The same, plus payment on the bank's form
How to revoke access Change the password — for everyone at once Delete a line — for one person The person unsubscribes — automatically Ban the member A refund or a ban
Plan Start or 199 ₽/mo add-on Pro or 299 ₽/mo add-on Pro or 299 ₽/mo add-on Pro or 299 ₽/mo add-on Pro or 499 ₽/mo add-on
Choose it when Few recipients and you're in touch Many people and the group changes The site is a bonus for your channel People come on their own The materials are worth money

Access period, your own login screen and stats are available in all five modes. A device limit applies to password, email code and channel subscribers; in Member sign-up and Paid access, the seat limit plays that role. You can switch modes at any time — the site's files aren't touched.

What you can configure

Access period: until a date or for 1, 3, 7 or 30 days, with a countdown on the login screen
Number of opens: after N devices, the link stops letting people in
Login screen: your own logo, title and description
Stats: sign-ins, screen views, wrong attempts, last sign-in
Attempts from unlisted addresses — see who tried to get past the list (Email code mode)
Subscription funnel: screen views, checks started, sign-ins — without a single visitor identifier (Subscribers only mode)
AI agents can do the same over MCP and the REST API

Which plans include it

Free Not included; per-site add-ons available
Start Site password
Pro Every mode: password, email code, subscribers, member sign-up, paid access
Business and up Every mode: password, email code, subscribers, member sign-up, paid access

On any plan, including Free, a mode can be added to one site as a monthly add-on: password 199 ₽/mo, email code 299 ₽/mo (password included), subscribers only 299 ₽/mo, members 299 ₽/mo, paid access 499 ₽/mo (members included). Prices are in rubles.

Downgraded your plan? The lock doesn't come off by itself: the site stays gated, but you can change access settings again only after paying. Removing the lock and opening the site to everyone is always free.

How people use it

A photographer delivers a shoot

The gallery is open for a week and the password goes to the client in a messenger. The open limit keeps the link within the family, not in a group chat.

A designer shows a mockup

The client views it by link; search engines can't find it. Extend the period as revisions go on, so access doesn't cut off mid-review.

A studio hands over work

The acceptance demo lives at the production address but opens only for people with the password. Once the work is signed off, remove the lock in one click.

Course materials

Access by the list of students. Someone leaves — delete the line; no need to send a new password to the whole group.

A handbook for subscribers

An expert opens a knowledge base to channel subscribers. To read, subscribe: every reader grows the audience.

Documents for a client

The contract and estimate live on a site, not in a chat thread. The log shows whether the recipient opened them.

Internal handbooks

Policies and price lists for your team: the site lives at a normal address, but search engines don't find it and outsiders can't open it.

How it works

The check runs before a file is served

The lock sits in the serving layer and covers every request, not just HTML. A stranger can't open a direct link to an image or PDF — otherwise the protection would be decorative.

One argon2 check per sign-in, then a cookie

The password is checked once; after that, the visitor browses with a signed service cookie. A gallery page with fifty files doesn't turn into fifty password checks.

A cookie for your host only

The pass is issued strictly for your site's address and doesn't travel to other sites on the platform. No analytics and no visitor profiles — it's a pass, not an account.

Brute force hits a limit

Five wrong passwords from one IP address on one site within 15 minutes, and the form shuts off. An email code is valid for ten minutes and burns after three wrong entries.

Step-by-step guides

These walkthroughs are on the Russian site for now. AI agents can set up the password, email code, subscriber and member modes over MCP and the REST API.

Gated access: frequently asked questions

Do I need a server or a backend? +

No. This is static hosting: the password check lives in Tuqo's serving layer, so you need no .htaccess, nginx or server code. The Free plan doesn't include gated access, but you can add it to one site as an add-on (a password from 199 ₽/mo); the Start plan includes the password.

Are images and PDFs protected, or only pages? +

All files. The check runs before any file is served, so a stranger can't open a direct link to an image or document. That matters: those files are usually the reason for the lock in the first place.

Will a gated site show up in search? +

No. A gated site serves search engines a separate robots.txt that blocks crawling, and the login screen is marked noindex and returns a 401 status — the password page isn't indexed.

What does a visitor without a password see? +

Your login screen: the logo, title and description you set, plus an input field. If you leave them empty, there is neutral text, and the page still looks finished rather than like a site error. The login screen's built-in labels follow the site's language, English or Russian: Tuqo detects it on each publish (Cyrillic in the title tag of index.html means Russian, otherwise the lang attribute of the html tag decides), or you fix it in the site's settings. Your own title and description can be in any language.

How secure is it? +

The password is stored as an argon2 hash; after sign-in, the visitor browses with a signed cookie for your host only. Brute force is capped: five wrong attempts from one IP address on one site within 15 minutes. An email code is valid for ten minutes and burns after three wrong entries.

Can I gate a site for a while and then open it? +

Yes, that is a normal scenario. The logo, title and description of the login screen survive removing the lock, so you don't set up the design again. The password, however, is deleted for good when you remove the lock, and the access period and open counter reset: when you gate the site again, you set a new password and send it out again.

What happens when the access period ends? +

The site stops opening, and visitors see an “access expired” screen. The files stay in place: it's the entry that closes, not the deploy. If access was granted for more than two days, you get a reminder a day before it ends — short access “for the evening” doesn't need one.

Does a gated site count toward plan limits? +

Yes, just like a regular one: the files stay where they are, only access to them is closed.

Can an AI agent set up gated access? +

Yes. Over MCP or the REST API, an agent sets a password, manages the address list, sets the access period and open limit, and designs the login screen — the same set of actions as in the panel.

A site only your people can see

Password, email code, channel subscription or payment, plus access periods and open limits — no server and no extra setup.