Skip to main content

How do I password-protect a QR code?

Updated September 14, 2026 · 3 min read · Pro and Business

Open the code, click Edit, expand Rules & Limits on the Content step, type a password into Password Protection and click Update ✓. Anyone who scans then gets a Protected QR Code page and has to enter the password before the content loads. It is a Pro and Business feature and it works on dynamic codes only — a static code is read straight off the paper, so nothing can stand in front of it.

Steps to add a password

  1. Open the code from My QR Codes and click Edit.
  2. On the Content step, expand Rules & Limits.
  3. Find Password Protection. The empty field reads No password; the helper text under it reads Require password to access content.
  4. Type the password. Use the eye icon to check what you typed.
  5. Click Update ✓. The code's page then shows a Protected badge.

One password per code, shared by everyone who scans it. There are no per-person logins, so treat it like a door code: change it when the people who know it change.

What the person scanning sees

The scan lands on a page titled Protected QR Code: "This QR code is password protected. Enter the password to continue." There is one field and an Unlock button. A wrong entry returns "Incorrect password. Please try again."

After unlocking, the visitor continues to the destination or the hosted page as normal. Scans are recorded once the visitor is through, so locked attempts do not inflate your analytics.

Changing or removing the password

Edit the code and go back to Password Protection. On a protected code the field shows Password is set — type to replace:

  • To change it, type the new password and click Update ✓.
  • To remove it, click the Remove password link under the field. A warning appears — Password will be removed when you save — and the code becomes open after you click Update ✓.

Changing or removing the password takes effect on the next scan. Anyone who had already unlocked the code on their phone has to enter the new password the next time they scan it.

What it protects, and what it does not

The password guards the QRCodeStack link that the code encodes. It does not encrypt the destination or restrict it in any other way.

If your destination is a public URL, anyone who already has that URL can open it without the password. Protect the destination itself as well — an unlisted link is not a private one.

Sensible uses: a staff-only price list behind a code on a shop floor, a document you want to hand out at an event rather than publish, or a vCard you do not want harvested. It is not a substitute for authentication on a system that holds personal or payment data.

If your aim is to limit exposure rather than restrict access, scan limits and date schedules may fit better.

Common problems

The Password Protection field is badged PRO

The feature needs Pro or Business. Starter and the free trial see the badge and the note Upgrade to Pro to add password protection.

Scanners are not being asked for the password

Check that you saved with Update ✓, and that you are testing a dynamic code. Also check the phone you are testing on — if it unlocked the code before, it may still be holding that page in its browser cache. Try a private window.

My saved site password is being filled in automatically

This field protects the QR code, not your account, so ignore any browser suggestion and type the password you want scanners to use.

I forgot the password I set

You do not need it. Edit the code and type a new one — the old value is never shown again, but it can always be replaced or removed.

A protected code shows no scans

Scans are counted after the unlock. If nobody is getting through, nothing is recorded.

Frequently asked questions

Can I set different passwords for different people?

No. Each code carries a single password shared by every scanner.

Can I password-protect a static QR code?

No. Static content is read directly from the pattern, so there is no step where a password could be asked for.

Does the password stop the code being scanned at all?

No. The scan works; the content is what waits behind the unlock page.

Do failed attempts count as scans?

No. A scan is recorded once the visitor unlocks the code.

Does changing the password lock out people who already unlocked it?

Yes. A new password invalidates previous unlocks, so everyone enters it again on their next scan.

Still stuck?

Email support@qrcodestack.com with the email on your account and, if it is about one code, its name or short link. A person replies within one business day, usually sooner.