Password protect a static HTML page or site for free

Publish the file to chorus.host with a username and password in the same request. Visitors get the browser's login prompt, and the server checks the password before it sends any file. No account or paid plan; links without an account last 24 hours unless you claim them.

Updated 1 October 2026 · For agents: /guides/password-protect-html-page.md

Publish and lock it in one request

curl -sS https://chorus.host/v1/publish -F file=@report.html \
  -F username=client -F password='choose-a-long-password'

The response has the link (url), "passwordProtected": true, and a claimUrl to keep the page past 24 hours. Send the person the link, and the username and password in a separate message.

For a whole folder, zip it and send -F archive=@site.zip instead of -F file=@..., or repeat -F file=@... once per file. Over 4 MB, publish with curl -fsSL https://chorus.host/publish.py | python3 - ./site first and then add the password with the call below.

Already published? Add the password with the claim token

curl -sS -X PUT "https://chorus.host/v1/sites/$SLUG/password" \
  -H "X-Claim-Token: $TOKEN" -H 'Content-Type: application/json' \
  -d '{"username":"client","password":"choose-a-long-password"}'
# {"success":true}

$SLUG is the site name (navy-twig-20 in https://navy-twig-20.chorus.host) and $TOKEN is the claimToken from the publish response. For a site in your account, send Authorization: Bearer $CHORUS_API_KEY instead of X-Claim-Token.

Check that the password works

We ran these against chorus.host on 1 October 2026 with a site published a few seconds earlier:

curl -s -o /dev/null -w '%{http_code}\n' https://navy-twig-20.chorus.host/
# 401
curl -s -o /dev/null -w '%{http_code}\n' -u client:wrong https://navy-twig-20.chorus.host/
# 401
curl -s -o /dev/null -w '%{http_code}\n' -u client:'choose-a-long-password' https://navy-twig-20.chorus.host/
# 200
curl -sI https://navy-twig-20.chorus.host/ | grep -i -E 'www-authenticate|cache-control'
# cache-control: private, no-store
# www-authenticate: Basic realm="navy-twig-20"

Every file is behind the prompt, not just the HTML: images, CSV files and scripts in the site get the same 401 without the password.

Or drop the file here

Drop a file, a folder or a .zip; when the link appears, the password form is already open below it.

Links last 24 hours. Sign in (free) to keep them.

Let your agent do it

Publish report.html to chorus.host behind a password, username client, and tell me the link and the password separately. Instructions: https://chorus.host/skill.md

Agents connected to the MCP server (claude mcp add --transport http chorus https://chorus.host/mcp) can do it in one tool call: publish_site takes a password argument, {"username": "client", "password": "..."}, and sets it before the site goes live. MCP setup for other clients.

Change it, remove it, or keep the site

Every way to password-protect a static page, compared

Checked 1 October 2026 against each vendor's docs and pricing pages; prices change, so follow the links before relying on them.

MethodWhat a password costsAccount neededWhere the password is checkedWhat it protectsSetup
chorus.host$0No (the claim token is enough)On the server, HTTP Basic Auth; the password is stored as a bcrypt hashEvery file in the siteOne request
StatiCrypt or PageCrypt, plus any host$0Depends on the hostIn the browser: the page is encrypted (StatiCrypt: AES-256, 600,000 PBKDF2 iterations)Only the encrypted HTML; linked images and data files stay publicEncrypt locally, then upload
Cloudflare Access$0 on Zero Trust Free, up to 50 usersYesOn Cloudflare's edge; each person gets an email PIN or signs in with an identity provider, not a shared passwordEverything behind the policyDashboard setup; the Pages toggle covers preview deployments only
Cloudflare Worker with Basic Auth$0 within 100,000 requests a dayYesOn the edge, in code you writeWhatever the Worker servesWrite and deploy the Worker; Cloudflare calls its sample not production-ready
NetlifyPro plan, $20 a monthYesOn the serverThe siteSite settings
VercelNot on Hobby; $20 a month per project on top of ProYesOn the serverThe deploymentProject settings
GitHub PagesNot available; private publishing needs GitHub Enterprise CloudYesn/an/an/a
tiiny.hostFrom the Solo plan, $13 a month billed yearlyYesOn the serverThe projectDashboard
here.now$0 on its free account planYes: its docs say anonymous sites can't have a passwordOn the serverThe siteAPI or dashboard

Where the others are better

Is a JavaScript password prompt enough?

A password checked by JavaScript in the page (if (input === "secret")) protects nothing: view-source shows both the check and the content. Encryption tools like StatiCrypt are different: the page really is encrypted and only decrypts with the right password. But the encrypted file is public, so anyone can download it and try passwords offline as fast as their computer allows. StatiCrypt's README asks for passwords of 16 characters or more for that reason, and files the page links to are not encrypted.

A server-side check (chorus.host, Netlify, Vercel, a Worker) never sends the content without the password, and each guess is a network request. HTTP Basic Auth sends the password with every request, so it's only safe over HTTPS. chorus.host only serves sites over HTTPS: a plain http:// request is redirected first.

Limits

Questions

Can I password protect an HTML page for free?

Yes. curl -sS https://chorus.host/v1/publish -F file=@page.html -F username=client -F password='...' publishes the page behind a login prompt, free and without an account. The link lasts 24 hours unless you claim it.

Is a JavaScript password on an HTML page secure?

Not on its own. A password checked in JavaScript can be read from the page source. Client-side encryption (StatiCrypt, PageCrypt) is stronger but can be attacked offline. A server-side check like HTTP Basic Auth over HTTPS never sends the page without the password.

Does Netlify's or Vercel's free plan include password protection?

No. Netlify's site password needs the Pro plan ($20 a month), and Vercel doesn't offer password protection on Hobby; on Pro it costs $20 a month per protected project. Prices checked 1 October 2026.

Publish to chorus.host with -F username=... -F password=... on the same request. You get the link and a claim token; no account is involved. Send the password separately from the link.

Will Google index a password-protected page?

No. Crawlers get the same 401 response as everyone else, so they never see the content. Sites without an account are also sent X-Robots-Tag: noindex.

Can my AI agent add the password for me?

Yes. Ask it to publish to chorus.host behind a password and point it at https://chorus.host/skill.md, or connect the MCP server at https://chorus.host/mcp, whose publish_site tool takes a password argument.