Password Protection
Password Protection is available on Enterprise plans or with the Advanced Deployment Protection add-on for Pro plans
Password Protection requires visitors to enter a pre-defined password before they can access your deployment. You can set the desired password from your project settings when enabling the feature, and update it any time.


The table below outlines key considerations and security implications when using Password Protection for your deployments on Vercel.
| Consideration | Description |
|---|---|
| Environment Configuration | Can be enabled for different environments. See Understanding Deployment Protection by environment |
| Compatibility | Compatible with Vercel Authentication and Trusted IPs |
| Bypass Methods | Can be bypassed using Shareable Links and Protection bypass for Automation, or by callers listed in Trusted Sources |
| Password Persistence | Users only need to enter the password once per deployment, or when the password changes, due to cookie set by the feature being invalidated on password change |
| Password Changes | Users must re-enter a new password if you change the existing one |
| Disabling Protection | All existing deployments become unprotected if you disable the feature |
| Token Scope | JWT tokens set as cookies are valid only for the URL they were set for and can't be reused for different URLs, even if those URLs point to the same deployment |
You can manage Password Protection through the dashboard, API, or Terraform.
From your Vercel dashboard:
- Select the project you want to enable Password Protection for
- Go to Deployment Protection in the sidebar
From the Password Protection section:
- Use the toggle to enable the feature
- Select the deployment environment you want to protect
- Enter a password of your choice
- Finally, select Save
All your existing and future deployments will be protected with a password for the project. The next time you access a deployment, you'll need to enter the password. After you enter it, a cookie is set in your browser for that deployment URL so you don't need to enter the password again.


Enabling Password Protection.
You can manage Password Protection using the Vercel API endpoint to update an existing project with the following body.
| Parameter | Type | Description |
|---|---|---|
deploymentType | string | The scope of protection. Accepted values are prod_deployment_urls_and_all_previews (Standard Protection), all (All Deployments), or preview (Only Preview Deployments) |
password | string | The password visitors must enter |
To enable or update Password Protection, send the passwordProtection object:
{
"passwordProtection": {
"deploymentType": "prod_deployment_urls_and_all_previews",
"password": "your_password_here"
}
}To disable Password Protection, set passwordProtection to null:
{
"passwordProtection": null
}You can configure Password Protection using password_protection in the vercel_project data source in the Vercel Terraform Provider.
Was this helpful?