How to Password-Protect a QR Code
For the full picture alongside expiry, see the expiring & password-protected codes overview. This is a dedicated walkthrough for the password setting specifically, since it's easy to skip the "what this actually protects against" part when you're just trying to get it working.
Setting it up
- Open the dynamic link's edit settings and find the password field (labeled for public access when left empty — that's the default, no password required).
- Enter the password you want to require. Anyone who scans the code from that point on sees a password prompt first, and only reaches the real destination after entering it correctly.
- Share the password separately from the code itself — by text, verbally, on a handout — the same way you'd share a shared WiFi password. The QR code and the password are two separate pieces of information on purpose.
- Test it yourself before handing it out, confirming both that the wrong password is rejected and the right one gets through.
What this is actually good for — and what it isn't
Worth repeating plainly, because it's the one thing worth getting right before you rely on this: this is a practical gate against casual, unintended access — someone glancing at a code left on a desk, or a code that ends up somewhere more public than you meant it to. It is genuinely useful for that.
It is not designed as a substitute for real authentication on anything genuinely sensitive. Treat the password the way you'd treat a shared office WiFi password, not a login credential meant to withstand a determined attempt to get in. If what you actually need is real access control — verified identity, an audit trail, protection against a motivated attacker — this isn't that tool, and no QR code password gate from any vendor should be treated as one.
Combining it with expiry
Password and expiry are independent settings on the same link — using one doesn't require the other. A common pairing: a password for content meant for a specific group, plus an expiration date so access closes on its own once the group no longer needs it, rather than relying on remembering to remove the password later.