Skip to content
UK web hosting, domain names, email, website security and online services.

Password-protect a website directory Print

  • security, hosting, siteworx
  • 0

Add simple HTTP authentication for a staging or private directory while understanding that it is not a substitute for application permissions.

Applies to: Websites, domains and document roots in SiteWorx

Each website must have the correct domain assignment, document root, DNS destination and certificate. Treat changes to a live primary domain or document root as production changes and take a backup first.

Before you start

  • Sign in to the Customer Portal and open the affected hosting service.
  • Take a current backup before changing website files, databases, DNS or application configuration.

Step-by-step

  1. Choose the exact directory and confirm that protecting it will not also block required assets or application callbacks.
  2. Create a unique access user and generated password through the SiteWorx directory-protection feature.
  3. Enable protection and test from a private browser window before sharing the URL.
  4. Confirm that HTTPS is enabled so the browser does not send credentials over an unencrypted connection.
  5. Store the password in an approved password manager and revoke users when the review or staging work ends.
  6. Remove protection deliberately before production launch and test public health checks, webhooks and scheduled requests.

Confirm the result

  • The intended hostname loads over HTTPS from a private browser session and serves the correct website.
  • Forms, database-driven pages and the administration area work without a new PHP, permission or redirect error.

Common problems

SymptomLikely causeWhat to do
The login page keeps rejecting the details.The wrong email address, an old password, browser autofill or an account-specific lockout is being used.Type the account email manually, use the password-reset process once and avoid repeated attempts that may extend a lockout.
A one-time code is not accepted.The device clock is inaccurate, the code belongs to a different account or an older code was entered.Set the device time automatically, wait for a fresh code and confirm the authenticator entry name before trying again.

When to contact Tudor Internet

Open a ticket through the Customer Portal when the checks above do not resolve the issue, when an action is unavailable for your service, or when continuing could risk data loss or service interruption. Include the following so the request can be investigated efficiently:

  • The affected domain and SiteWorx account
  • The exact error text and time
  • The last change made
  • Relevant log lines with passwords and personal data removed
Do not send passwords, private keys, full payment-card details, one-time authentication codes or unredacted identity documents in an ordinary support reply.

Related articles

Last reviewed: 2026-07-18.


Was this answer helpful?

« Back