Password-Protected Pages

Any page can be put behind a password. Visitors see a short form instead of the page content, and once they enter the correct password they stay unlocked on that device for 30 days.

This is useful for member meeting minutes, volunteer handbooks, budget documents, and the church directory.

Adding a password

  1. Open the page in Structure → Pages
  2. Scroll to Page Password
  3. Type the password you want to share
  4. Optionally fill in Password Hint — shown on the password screen to jog people's memory
  5. Publish

To remove the protection, clear the field and publish again. Anyone still holding an unlock from the old password loses it the moment you change it.

Tip: Put the hint to work. "The password is in this week's bulletin" is far more useful than making people email the office.

What the password does

When a page has a password set, Studio automatically:

  • Shows the password form instead of the page content
  • Keeps the page out of your sitemap
  • Tells Google and other search engines not to index it
  • Hides the page's description and social share image, so the content isn't summarized in search results or link previews
  • Blocks the plain-text version of the page that AI assistants can request

The page's title is still visible on the password screen, and the page can still be linked from your navigation. That's deliberate — people need to be able to find the door.

What the password does not do

It is a shared door code, not a login. Everyone uses the same password. There are no individual accounts, no way to see who viewed the page, and no way to revoke access for one person.

Because the password gets forwarded in emails, printed in bulletins, and passed along by word of mouth, treat anything behind it as semi-public. The practical test: would you be comfortable if this ended up outside the church? If the answer is no, a page password is not strong enough protection on its own.

Changing the password is the only way to cut off access, and it cuts off everyone at once.

Changing the password

Edit the field and publish. Everyone — including people who unlocked the page months ago — will need the new password the next time they visit.

It's worth doing this on a schedule for pages holding member information: once a year, or whenever someone leaves the church on difficult terms.

Troubleshooting

"I set a password but the page still loads normally." You're probably logged into Studio with preview enabled. Editors bypass the password screen on purpose so you can check your work. Try the page in a private browsing window.

"Someone says the password doesn't work." Passwords are case-sensitive and count spaces. After 10 wrong attempts the form pauses for a few minutes.

"The page is in Google even though it's protected." Google may take a few weeks to drop a page it already indexed. If it was public before you added the password, request removal in Google Search Console rather than waiting.