Password-protect documents and categories Pro
Set a password on a FileDeck category — or on a single document via the editor's Visibility control. Visitors enter it once and stay unlocked.
Updated August 1, 2026
FileDeck Pro can require a password before a category of documents can be seen or downloaded. You set the password in the Password protect (FileDeck) field on the category edit screen, and visitors enter it once and stay unlocked for 24 hours, so they are not asked again on every download. It is the right choice for semi-public material where visitors do not have site accounts.
FileDeck Pro — this feature is included in all Pro plans. See pricing
Set or change the password
- Go to Documents → Document Categories and edit the category.
- In the Password protect (FileDeck) field, enter a password. To change an existing password, enter a new one; to keep the current password, leave the field blank when you save.
- Save the category. Every document in the category is now covered by the same password.
FileDeck stores the password securely (hashed), so it is never kept or displayed in plain text — keep your own record of what you set.
Password-protect a single document
A single document doesn’t need its own category: use WordPress’s own password. Edit the document and, under the editor’s Status & visibility panel, set Visibility → Password protected and choose a password.
FileDeck honours that password everywhere it matters:
- The download route refuses the file until the password has been entered — the document page shows WordPress’s standard password form, and a correct entry unlocks both the page and its downloads.
- In library listings the document shows with a padlock (or is hidden entirely with the Hide restricted documents setting), and its excerpt, filename and thumbnail are withheld until unlocked.
- The document counts as restricted, so with file protection its file is moved into the protected vault — the raw uploads URL stops resolving, and there is no ungated second door past the password.
- Signed share links still work: a link you minted for a named recipient is its own authorisation, so you can hand the document to someone without handing them the password.
What visitors experience
When a visitor reaches password-protected content, FileDeck asks for the password. After a correct entry, the documents unlock — they download normally — and FileDeck sets a cookie that keeps them unlocked for 24 hours, even if they close the browser. After that they are asked again. Until they unlock, the documents show with a padlock in listings by default; the Hide restricted documents entirely toggle under Documents → Settings → Features removes them from listings instead.
Typical uses: board packs for committee members, member newsletters, event materials shared with attendees.
Know the limits of a shared password
Everyone uses the same password, so you cannot tell who accessed a document, and anyone the password is forwarded to gets in. If you need real per-person control, use role restriction instead. For protection of the file’s direct URL, pair passwords with file protection, which serves protected files only through signed links that expire after 15 minutes.
FAQ
How long does the unlock last?
24 hours. Once they enter the password correctly, FileDeck sets a cookie for that category and they are not asked again for a day — closing the browser does not clear it. To take access away sooner, change or remove the category password, which invalidates every existing unlock immediately.
How do I change or keep the password?
Edit the category and type a new password into the Password protect (FileDeck) field to change it; leave the field blank to keep the current one. Visitors need the new password the next time they are prompted.
Can I see who used the password?
No. Password access is anonymous by design. Use role restriction if you need access tied to individual user accounts.
Does the password also block the file’s direct URL?
The password controls the library and the download endpoint. Direct URLs are handled by file protection, which moves protected files out of the public uploads folder — see how signed download links work.
Still stuck? Email support@getfiledeck.com.