Gated access to a site: password, email code, channel subscription or payment
The site opens only for people you give access to. No server, no .htaccess,
no sign-up for visitors. Every file is protected — pages, images, PDFs.
In the panel, it's the Visibility tab on the site page.
Choose how to gate the site
Password — one secret for everyone that you can read out over the phone. Email code — sign-in by a list of addresses. Subscribers only — the site opens for subscribers of your Telegram/MAX channel. Member sign-up — visitors sign up themselves. Paid access — entry is sold through your own acquiring. You switch modes in the Visibility tab and changes apply at once.
Send the link
The site address stays the same. Only what a person without a pass sees changes: instead of pages, your login screen with your logo and text.
Add limits if needed
An access period and a number of opens. Access closes by itself on the day you set — no need to ask a client to “stop visiting”.
Five ways to gate a site
All five gate the whole site. The difference is who you give access to: one secret for everyone, a named list, your channel's subscribers, everyone who signs up — or those who paid for entry. Each mode has its own page with the details.
Password for the whole site
Start plan or 199 ₽/mo add-onOne secret for everyone. A visitor enters it once and gets the whole site — pages, images, PDFs and any other files.
When it fits. When there are only a few recipients and you talk to them directly: a client, family, a contractor.
Learn more →Email code
Pro plan or 299 ₽/mo add-onNo shared secret. A visitor enters their address, gets a six-digit code by email and signs in. Only people on your list get in.
When it fits. When there are many recipients and the group changes: a course cohort, a department, a list of investors.
Learn more →Channel subscribers only
Pro plan or 299 ₽/mo add-onThe site opens only for subscribers of your Telegram/MAX channels. A visitor taps “Check subscription”, confirms it in the bot and gets in. Your content helps the channel grow.
When it fits. When the site is a bonus for your audience: an expert's handbook, a knowledge base, closed community materials.
Learn more →Member sign-up
Pro plan or 299 ₽/mo add-onNo lists — visitors sign up themselves: email, name, consent to your documents and a code from an email. Want to filter at the door? Turn on request moderation.
When it fits. When you can't collect the audience into a list upfront: an open course, a club, a community.
Learn more →Paid access
Pro plan or 499 ₽/mo add-onA storefront with price and perks, payment through your own acquiring — T-Kassa or YooKassa. The money goes straight to you: Tuqo takes no fee on sales.
When it fits. When your materials are worth money: a paid course, a handbook, a private archive.
Learn more →Which mode to choose
| Password | Email code | Subscribers only | Member sign-up | Paid access | |
|---|---|---|---|---|---|
| Who gets access | Anyone who knows the secret | A named list of addresses | Subscribers of your channels | Anyone who signs up | People who paid |
| What the visitor does | Enters the password | Enters their email and a code from the inbox | Confirms the subscription in a bot | Email, consent and a code from the inbox | The same, plus payment on the bank's form |
| How to revoke access | Change the password — for everyone at once | Delete a line — for one person | The person unsubscribes — automatically | Ban the member | A refund or a ban |
| Plan | Start or 199 ₽/mo add-on | Pro or 299 ₽/mo add-on | Pro or 299 ₽/mo add-on | Pro or 299 ₽/mo add-on | Pro or 499 ₽/mo add-on |
| Choose it when | Few recipients and you're in touch | Many people and the group changes | The site is a bonus for your channel | People come on their own | The materials are worth money |
Access period, your own login screen and stats are available in all five modes. A device limit applies to password, email code and channel subscribers; in Member sign-up and Paid access, the seat limit plays that role. You can switch modes at any time — the site's files aren't touched.
What you can configure
Which plans include it
On any plan, including Free, a mode can be added to one site as a monthly add-on: password 199 ₽/mo, email code 299 ₽/mo (password included), subscribers only 299 ₽/mo, members 299 ₽/mo, paid access 499 ₽/mo (members included). Prices are in rubles.
Downgraded your plan? The lock doesn't come off by itself: the site stays gated, but you can change access settings again only after paying. Removing the lock and opening the site to everyone is always free.
How people use it
A photographer delivers a shoot
The gallery is open for a week and the password goes to the client in a messenger. The open limit keeps the link within the family, not in a group chat.
A designer shows a mockup
The client views it by link; search engines can't find it. Extend the period as revisions go on, so access doesn't cut off mid-review.
A studio hands over work
The acceptance demo lives at the production address but opens only for people with the password. Once the work is signed off, remove the lock in one click.
Course materials
Access by the list of students. Someone leaves — delete the line; no need to send a new password to the whole group.
A handbook for subscribers
An expert opens a knowledge base to channel subscribers. To read, subscribe: every reader grows the audience.
Documents for a client
The contract and estimate live on a site, not in a chat thread. The log shows whether the recipient opened them.
Internal handbooks
Policies and price lists for your team: the site lives at a normal address, but search engines don't find it and outsiders can't open it.
How it works
The check runs before a file is served
The lock sits in the serving layer and covers every request, not just HTML. A stranger can't open a direct link to an image or PDF — otherwise the protection would be decorative.
One argon2 check per sign-in, then a cookie
The password is checked once; after that, the visitor browses with a signed service cookie. A gallery page with fifty files doesn't turn into fifty password checks.
A cookie for your host only
The pass is issued strictly for your site's address and doesn't travel to other sites on the platform. No analytics and no visitor profiles — it's a pass, not an account.
Brute force hits a limit
Five wrong passwords from one IP address on one site within 15 minutes, and the form shuts off. An email code is valid for ten minutes and burns after three wrong entries.
Step-by-step guides
These walkthroughs are on the Russian site for now. AI agents can set up the password, email code, subscriber and member modes over MCP and the REST API.
Gated access: frequently asked questions
Do I need a server or a backend? +
No. This is static hosting: the password check lives in Tuqo's serving layer, so you need no .htaccess, nginx or server code. The Free plan doesn't include gated access, but you can add it to one site as an add-on (a password from 199 ₽/mo); the Start plan includes the password.
Are images and PDFs protected, or only pages? +
All files. The check runs before any file is served, so a stranger can't open a direct link to an image or document. That matters: those files are usually the reason for the lock in the first place.
Will a gated site show up in search? +
No. A gated site serves search engines a separate robots.txt that blocks crawling, and the login screen is marked noindex and returns a 401 status — the password page isn't indexed.
What does a visitor without a password see? +
Your login screen: the logo, title and description you set, plus an input field. If you leave them empty, there is neutral text, and the page still looks finished rather than like a site error. The login screen's built-in labels follow the site's language, English or Russian: Tuqo detects it on each publish (Cyrillic in the title tag of index.html means Russian, otherwise the lang attribute of the html tag decides), or you fix it in the site's settings. Your own title and description can be in any language.
How secure is it? +
The password is stored as an argon2 hash; after sign-in, the visitor browses with a signed cookie for your host only. Brute force is capped: five wrong attempts from one IP address on one site within 15 minutes. An email code is valid for ten minutes and burns after three wrong entries.
Can I gate a site for a while and then open it? +
Yes, that is a normal scenario. The logo, title and description of the login screen survive removing the lock, so you don't set up the design again. The password, however, is deleted for good when you remove the lock, and the access period and open counter reset: when you gate the site again, you set a new password and send it out again.
What happens when the access period ends? +
The site stops opening, and visitors see an “access expired” screen. The files stay in place: it's the entry that closes, not the deploy. If access was granted for more than two days, you get a reminder a day before it ends — short access “for the evening” doesn't need one.
Does a gated site count toward plan limits? +
Yes, just like a regular one: the files stay where they are, only access to them is closed.
Can an AI agent set up gated access? +
Yes. Over MCP or the REST API, an agent sets a password, manages the address list, sets the access period and open limit, and designs the login screen — the same set of actions as in the panel.
A site only your people can see
Password, email code, channel subscription or payment, plus access periods and open limits — no server and no extra setup.