tuqo
Gated access · Password mode

One password for the whole site — no server, no .htaccess

One shared secret for everyone: a visitor enters the password once and gets the whole site — pages, images, PDFs and any other files. No server, no .htaccess, no sign-up. You turn it on in the Visibility tab and it works right away.

Get started Pricing → Start plan or 199 ₽/mo add-on

In the panel, it's the Visibility tab on the site page.

How to turn it on

1

Turn on Password mode

The Visibility tab on the site page. Included from the Start plan, or as a 199 ₽/mo add-on for one site.

2

Pick a password

Three strength levels: the simple one is easy to say out loud, the strong one is meant to be copied. Or set your own.

3

Send the link and the password

The site address stays the same. The password is always visible in the panel: forgot it — look it up instead of sending out a new one.

4

Add limits if needed

An access period and a limit on opens. Access closes by itself on the day you set.

When it fits. When there are only a few recipients and you talk to them directly: a client, family, a contractor. You can read a password out over the phone — that is its main advantage over any list.

What the visitor sees

The site address doesn't change — only what a person without a pass sees does.

Opens the link

Instead of pages, they see your login screen: logo, title, description and a password field.

Enters the password once

Then browses freely: the pass lasts up to a week, so there is no password prompt on every page.

Sees everything you published

Gallery, documents, price list — any files. A direct link to an image won't open without the password.

What's included

Every file is protected: the check runs before any file is served, not just on HTML pages
Three password strength levels, or your own password
The password stays visible in the panel: stored as an argon2 hash, with an encrypted recoverable copy alongside
Changing the password logs out everyone who already signed in
Brute force is capped: five wrong attempts per IP address in 15 minutes
After sign-in, the pass lasts up to 7 days and works only on your site
Access period: until a date or for 1, 3, 7 or 30 days, with a countdown on the login screen
Open limit: after N devices, the link stops letting people in
Your own login screen: logo, title, description
Stats: sign-ins, screen views, wrong attempts, last sign-in
A gated site isn't indexed: noindex, a 401 status and a robots.txt that blocks crawling
AI agents can do all of this over MCP and the REST API

How people use it

A photographer delivers a shoot

The gallery is open for a week and the password goes to the client in a messenger. The open limit keeps the link within the family, not in a group chat.

A designer shows a mockup

The client views it by link; search engines can't find it. Extend the period as revisions go on, so access doesn't cut off mid-review.

A studio hands over work

The acceptance demo lives at the production address but opens only for people with the password. Once the work is signed off, remove the lock in one click.

Documents for a client

The contract and estimate live on a site, not in a chat thread. Stats show whether the recipient opened them.

Other modes and guides

Site password: frequently asked questions

How is this different from .htaccess and htpasswd? +

You don't need a server. The classic setup needs Apache, config files and somewhere to run it all. Here the password is checked by Tuqo's own serving layer: you turn the mode on in the panel and the rest already works.

Does the password protect images and PDFs, or only pages? +

All files. The check runs before any file is served, so a stranger can't open a direct link to an image or document.

I forgot my site's password. What now? +

Look it up in the panel: the owner can always see the password. No need to send out a new one just because you forgot it.

How do I log out everyone who already signed in? +

Change the password. Every pass issued so far stops working at once, and the site asks everyone for the password again.

How long does a sign-in last? +

Up to 7 days on one device; then the site asks for the password again. The pass is tied to your site's address and doesn't work on other sites on the platform.

How secure is it? +

The password is stored as an argon2 hash; after sign-in, the visitor browses with a signed cookie. Brute force is capped: five wrong attempts from one IP address on one site within 15 minutes, and the form shuts off.

Which plan do I need? +

The Start plan or higher. On the Free plan, add password protection to one site as a 199 ₽/mo add-on.

Will a password-protected site show up in search? +

No. A gated site tells search engines not to crawl it, and the login screen is marked noindex and returns a 401 status.

A site only your people can see

Site password: Start plan or 199 ₽/mo add-on. Your own login screen, every file protected, no server to run.