QR codes
Password-protect a code
Add a /u/ unlock page in front of the destination.
Add a password gate to any dynamic QR. Scanning takes the visitor to an unlock page; entering the right password redirects to the destination.
When to use it
- VIP / members-only content — a private menu, exclusive download, members link
- Event tickets — gate access to the post-event page
- Internal documents — share a doc QR but require an internal password
- Restricted previews — pre-launch content, beta access
Not a security feature — anyone with the password gets in. But adequate for "casual gating" where you trust your audience to keep the password.
How to set it
Step 1 — Open a dynamic code
From /dashboard/<brand>/qr, click into the code you want to protect. Must be dynamic — static codes can't be password-protected.
Step 2 — Toggle Password protect on
In the code's advanced settings.
Step 3 — Set a password
Pick something memorable but not trivially guessable. Avoid password, 12345, letmein. Mix letters + numbers, ~8 characters minimum.
What the visitor sees
Scan the QR → /u/<slug> unlock page with your brand colors and an "Enter password" field. Type the password → redirected to your destination URL.
Rate limiting: 5 wrong attempts per IP per hour. After that, blocked for 1 hour. Stops brute-force attempts.
Don't put the password on the same surface as the QR. Posting a printed QR with the password right next to it defeats the point — anyone walking by sees both. Distribute the password separately (in a private email, a secure chat, after the user completes an action).
Plan note
- Pro+ ($9/mo)