Password-Protected Links for Secure Sharing
Control who accesses your content by adding password protection to short links. Perfect for confidential documents, client deliverables, and exclusive content.
When to Use Password Protection
- Client Deliverables: Share design mockups, reports, or proposals with clients
- Internal Documents: Distribute company policies, financial reports, or HR materials
- Exclusive Content: Provide early access to courses, webinars, or premium resources
- Temporary Sharing: Share sensitive files with contractors or partners
- Beta Access: Control access to unreleased products or features
Quick Start: Create Protected Link
Using the Dashboard
- Go to Dashboard โ Create Link
- Enter your destination URL
- Toggle "Password Protection" ON
- Enter a strong password (min. 8 characters)
- Click "Create Link"
Using the API
curl -X POST https://api.sniplink.co/v1/workspaces/{workspaceId}/links \
-H "X-API-Key: snip_live_your_api_key_here" \
-H "Content-Type: application/json" \
-d '{
"url": "https://example.com/confidential-report.pdf",
"slug": "q4-report",
"password": "SecurePass2026!",
"title": "Q4 Financial Report"
}'User Experience Flow
Here's what happens when someone clicks a password-protected link:
- 1User clicks short link (e.g.,
r.sniplink.co/q4-report) - 2SnipLink shows password entry page with your link title
- 3User enters password and clicks "Access"
- 4If correct: User is redirected to destination
If wrong: Error message, can try again
Password Best Practices
1. Password Strength
password123Too common, easily guessed
ClientReport2026Still predictable, lacks symbols
j8Kp#mQ2$vL9nXRandom, 14+ characters, mixed case, numbers, symbols
2. Password Distribution
Never send passwords in the same message as the link! Use different channels:
- Link via email โ Password via Slack/SMS
- Link via social media โ Password via direct message
- Link via document โ Password verbally or separate email
3. Password Rotation
Change passwords regularly for long-lived links:
# Update password via API
curl -X PATCH https://api.sniplink.co/v1/workspaces/{workspaceId}/links/{linkId} \
-H "X-API-Key: snip_live_your_api_key_here" \
-H "Content-Type: application/json" \
-d '{
"password": "NewPassword2026!"
}'Real-World Use Cases
1. Client Project Delivery
// Automate client deliverable sharing
async function shareClientDeliverable(
clientEmail: string,
fileUrl: string,
projectName: string
) {
// Generate random password
const password = generateSecurePassword(16);
// Create protected link
const { data } = await fetch(
`https://api.sniplink.co/v1/workspaces/${WORKSPACE_ID}/links`,
{
method: 039;POST039;,
headers: {
039;X-API-Key039;: API_KEY,
039;Content-Type039;: 039;application/json039;,
},
body: JSON.stringify({
url: fileUrl,
password,
title: `${projectName} - Client Deliverable`,
tags: [039;client-delivery039;, clientEmail],
expiresAt: new Date(Date.now() + 30 * 24 * 60 * 60 * 1000).toISOString(), // 30 days
}),
}
).then((r) => r.json());
// Send link via email
await sendEmail({
to: clientEmail,
subject: `Your ${projectName} files are ready`,
body: `
Hi there,
Your project deliverables are ready to download:
${data.link.shortUrl}
The password will be sent separately via SMS for security.
This link expires in 30 days.
`,
});
// Send password via SMS (separate channel!)
await sendSMS({
to: getClientPhone(clientEmail),
message: `Password for ${projectName} files: ${password}`,
});
return data.link;
}
function generateSecurePassword(length: number): string {
const chars = 039;abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789!@#$%^&*039;;
return Array.from({ length }, () =>
chars.charAt(Math.floor(Math.random() * chars.length))
).join(039;039;);
}2. Exclusive Course Access
// Create unique password for each student
async function provideStudentAccess(studentEmail: string, courseId: string) {
const studentPassword = `${courseId}-${studentEmail.split('@')[0]}-2026`;
const { data } = await createProtectedLink({
url: `https://courses.example.com/${courseId}`,
password: studentPassword,
title: `Course: ${courseId}`,
tags: [039;course-access039;, courseId, studentEmail],
});
// Email with embedded password (single-use scenario)
await sendEmail({
to: studentEmail,
subject: 039;Your course access is ready039;,
body: `
Welcome to the course!
Access link: ${data.shortUrl}
Password: ${studentPassword}
Keep this email safe - you'll need it to access the course.
`,
});
}3. Temporary Partner Access
// Share confidential data with time-limited access
async function shareWithPartner(partnerName: string, documentUrl: string) {
const { data } = await createProtectedLink({
url: documentUrl,
password: 039;Partner2026Access!039;,
title: `Confidential: ${partnerName} Agreement`,
expiresAt: new Date(Date.now() + 7 * 24 * 60 * 60 * 1000).toISOString(), // 7 days
maxClicks: 10, // Limit access attempts
});
return data.link;
}Monitor Access & Security
Track Failed Password Attempts
// Get analytics including failed password attempts
const analytics = await fetch(
`https://api.sniplink.co/v1/workspaces/${WORKSPACE_ID}/links/${linkId}/analytics?days=30`,
{
headers: { 039;X-API-Key039;: API_KEY },
}
).then((r) => r.json());
// Check for suspicious activity
if (analytics.data.failedPasswordAttempts > 20) {
await sendAlert({
message: `High failed password attempts on link ${linkId}`,
severity: 039;warning039;,
});
// Optionally rotate password or disable link
await updateLink(linkId, {
password: generateNewPassword(),
});
}Access Analytics
Track who successfully accessed your protected content:
- Successful unlocks: How many people entered correct password
- Failed attempts: Detect potential unauthorized access
- Geographic location: See where access attempts come from
- Device information: Monitor unusual device patterns
Remove Password Protection
Make a protected link public by removing the password:
curl -X PATCH https://api.sniplink.co/v1/workspaces/{workspaceId}/links/{linkId} \
-H "X-API-Key: snip_live_your_api_key_here" \
-H "Content-Type: application/json" \
-d '{
"password": null
}'Security Considerations
1. Rate Limiting
SnipLink automatically protects against brute-force attacks:
- 5 failed attempts per minute โ 1-minute lockout
- 30 failed attempts per hour โ 1-hour lockout
2. Password Storage
3. Session Management
After successful password entry:
- Session cookie valid for 24 hours
- User won't be prompted again within that window
- Clearing cookies requires re-authentication
4. Additional Security Layers
Combine password protection with other security features:
await createProtectedLink({
url: 039;https://example.com/sensitive-data',
password: 039;StrongPassword123!039;,
expiresAt: 039;2026-12-31T23:59:59Z039;, // Auto-expire
maxClicks: 100, // Limit total clicks
allowedDomains: [039;company.com039;], // Restrict to specific domains
geoRestrictions: [039;US039;, 039;CA039;], // Geographic restrictions
});Common Mistakes to Avoid
Defeats the purpose of two-factor access
Compromise of one link affects all others
Long-lived passwords increase risk of compromise
Posting passwords in public Slack channels or forums
Next Steps
- Add expiration: Use Link Expiration tutorial for time-sensitive content
- Track engagement: Build Analytics Dashboard to monitor access
- Automate delivery: Use Webhooks for real-time notifications
Need Enterprise Security?
Enterprise plans include SSO, advanced access controls, and audit logs.
Loading contact information