How to create a client document portal in WordPress Pro
A WordPress client portal needs client logins, per-client access enforced on downloads, and protected files. How to build one on your own site, step by step.
Updated September 26, 2026
A client document portal in WordPress needs three parts: a login for each client, access rules that show each client only their own files, and file protection, so a copied file URL doesn’t work for anyone else and a copied download link stops working within minutes. WordPress provides the logins; per-client file access comes from a plugin.
What should a client portal do?
Before choosing a tool, be clear about the job. A useful client portal:
- Knows who is looking. Each client signs in with their own account, so access can be granted and removed per person.
- Separates clients. Client A reaches Client A’s files and cannot learn the names of anyone else’s.
- Protects the files themselves. Pasting a file’s address into a browser doesn’t get round the rules.
- Delivers. Clients hear when something new is waiting, instead of you sending "I’ve uploaded it" emails.
- Receives. Clients can send documents back without email attachments.
- Keeps a record. You can see who downloaded what, and when.
Why can’t WordPress do this on its own?
WordPress has user accounts and roles, which covers the first point. The rest is missing.
Roles describe kinds of user, not individuals. Your clients will usually share one role, such as Subscriber, so a role cannot say "Acme sees Acme’s folder and nobody else’s". Private pages are visible to Administrators and Editors by default, not to clients. And uploaded files sit at public addresses under wp-content/uploads/, where the web server serves them to anyone with the link.
What are the options?
| Approach | Separates clients? | Protects the file? | Trade-off |
|---|---|---|---|
| A password-protected page per client | Weakly — one shared password per page | No | Many pages to maintain, and the files linked from them stay public |
| Shared cloud-storage folders (Google Drive, Dropbox) | Depends on sharing settings | Only when shared with named accounts | Access lives outside your site; "anyone with the link" is a hidden URL, not access control |
| Separate client-portal software | Usually | Usually | Another login and subscription, and clients leave your site to use it |
| A document library plugin with per-client access | Yes | Yes, when it protects the file | Runs on the WordPress site you already have |
How to build a client portal with FileDeck
FileDeck’s free version gives you the document library itself. Client areas, per-person access and file protection are part of FileDeck Pro.
FileDeck Pro — client areas, groups, single-use links and file protection are included in all Pro plans. PDF watermarking, acknowledgment tracking and transmittals are part of the AI tier. See pricing
- Create an account for each client. In WordPress, go to Users → Add User. Any role works — Subscriber is fine.
- Create one category per client. Go to Documents → Document Categories and add a category such as Acme Corp. Keep the structure flat. If you use sub-categories for projects or matters, they inherit the client’s access from their parent.
- Assign the client to their category.
Pro — edit the category and enter the client’s username or email address under Client area — assigned users (FileDeck), separated by commas. To admit everyone at a company, add an entry such as
@acme.example. To reuse a team, create it under Documents → Groups → Add group and tick it under Client area — groups (FileDeck). Named people, groups and domains combine as an OR — matching any one gets a person in. See client areas, groups and access by email domain. - Add documents to the client’s category.
Pro — when you publish a document into a client area, its assigned users are emailed automatically. Sending uses your site’s email, so add an SMTP plugin if your host can’t send mail.
- Create the portal page.
Pro — create a page called Your documents containing
[filedeck_my_documents]. Each signed-in client sees only their own areas, each as a titled section with its own library; visitors who are not signed in get a login prompt. One page serves every client. - Let clients send files back.
Pro — use
[filedeck_my_documents uploads="1"]to add a "Send us a document" form to each area, locked to that client’s category. Uploads land in your moderation queue, and a client’s upload is not published until you approve it. - Handle one-off documents.
Pro — for a single contract or letter, set the document’s Visibility to Specific people only and tick the recipients; see assign a document to specific people. For someone without an account, open the document and choose Create a single-use link. The link works for one download, stops working after 7 days if unused, and is shown once, so copy it straight away. See single-use download links.
- Keep a record.
Pro — enable Log activity under Documents → Settings → Features. The activity log under Documents → Insights → Activity log records who downloaded what and when, with CSV export. Add
[filedeck_my_downloads]to the portal page so clients can see what they have already taken.AI tier — PDF watermarking stamps each served PDF with the recipient’s email and the time, acknowledgment tracking records who confirmed reading a document, and transmittals keep a numbered register of what was sent to whom.
- Test with two client accounts. Sign in as Client A and confirm Client B’s documents do not appear at all. Then, signed out, open one of Client B’s document pages and a raw file address — both should be refused.
Restricted files move into FileDeck’s protected folder and are served through signed links that expire after 15 minutes. On nginx, add the short location block in protect files on nginx servers.
What do other clients see?
They see no trace of each other’s areas. A document in a client area does not appear in anyone else’s library — no row, no title, no padlock — because a locked row would still reveal a file’s name, such as "Acme redundancy letter".
If someone opens the address of a document they cannot access, they get the not-found page, even if you have set a custom page for refused visitors. That page is only used where a document’s existence is not secret — role-, password- or login-restricted documents, which already show as padlocked rows. Site administrators can see all client areas.
Limits to know before you start
- It is a portal, not a practice-management system. FileDeck handles sharing documents with clients. If you need matter management, e-discovery or email filing, you need a full document management system (DMS) as well. The secure client folders guide walks through this boundary for law firms.
- External links are only as private as their host. A document that points at a Google Drive or Dropbox URL is still reachable by whoever holds that URL. Upload files that must be protected.
- Domain rules trust your sign-up process. An
@acme.examplerule admits anyone whose account email is at that domain, so use it where you create or verify accounts yourself. - The person picker is built for small lists. Specific people only lists up to 200 users. For ongoing work with the same people, use a client area or a group.
FAQ
Do clients need a WordPress account?
For client areas, yes — any role, including Subscriber. To send one file to someone without an account, use a single-use download link.
Can clients upload documents to me?
Yes. Add uploads="1" to the [filedeck_my_documents] shortcode and each client area gains an upload form. Uploads arrive as pending documents for you to review, and are not published until you approve them.
Can one client see the names of another client’s files?
No. Client-area documents are left out of other visitors’ libraries rather than shown as locked rows, and their pages return a not-found response to anyone without access.
What happens to client access if my Pro licence lapses?
Client-area assignments keep being enforced, so client files do not become public. The Pro features themselves, including the portal page, stop until you renew.
Is this suitable for law firms or healthcare providers?
Many firms use a WordPress client portal for sharing documents, but suitability depends on your own obligations. Our security page describes how file protection and access rules behave; FileDeck does not by itself make a site meet any regulation. See the notes for law firms, agencies and healthcare.
Next steps
Explore the live demo to see the library layouts clients would use, then read client areas and secure client folders for the detail. If you are moving from another plugin, the switch page covers migration help, and restricting downloads by role covers staff-only and member-only sections.
Still stuck? Email support@getfiledeck.com.