File sharing
How to password-protect a file link
A password can keep an ordinary share link from opening for anyone who receives it. Here is how to combine that gate with sensible visibility, expiry, and delivery habits.

When a password-protected link helps
Password protection is useful when a link might be forwarded, copied into the wrong channel, or left in a message history. The recipient can reach the share page, but the file remains behind a password prompt until the correct password is entered.
This is access control, not end-to-end encryption. A share password controls entry to the hosted page; it does not mean the file was encrypted on your device with a key that only the recipient holds. For highly sensitive material, use an encrypted archive or a dedicated end-to-end encrypted transfer system as well.
Create the protected share
- Upload the file or find it in your Studio library.
- Choose Share on the item and open the advanced share controls.
- Choose unlisted or private visibility based on who should discover the link.
- Add a strong, unique password that you have not used for your account.
- Optionally set an expiry date or maximum view count to reduce how long the link remains useful.
- Create the share, copy the link, and test it in a private browser window before sending it.
Choose visibility deliberately
Public shares can be discoverable and indexable, so they are the wrong starting point for material that needs controlled distribution. Unlisted shares stay out of public discovery and search indexing but remain accessible to anyone who has the URL and satisfies any password gate. Private shares apply the strictest share visibility available in the product.
A password adds a second requirement, while expiry and view limits reduce the useful lifetime of the URL. These controls solve different problems and are strongest when combined intentionally.
Send the link and password separately
Do not put the password in the same message as the link when the file matters. Send the link through the normal project channel and send the password through a separate trusted channel, such as a direct message or phone call.
Give the recipient enough context to recognize the file without placing sensitive details in the filename or message preview. After the transfer is complete, remove the share or let a short expiry close it automatically.
Verify and clean up
Open the link while signed out to verify that the password prompt appears. Confirm that a wrong password is rejected and that the correct password opens the intended file. This catches accidental public links before they leave your hands.
Review active links periodically in Studio Shares. Revoke links that are no longer needed, especially links created for one client review, one hiring process, or one temporary delivery.
Frequently asked questions
Does a share password encrypt my file?
No. It gates access to the hosted share page. Use client-side encryption as an additional layer when the file itself requires end-to-end protection.
Should I use public or unlisted visibility?
Use unlisted or private for controlled distribution. Public is intended for content you want people and search engines to discover.
Can the same link also expire?
Yes. A share can combine a password with an expiry date or maximum view count.
Does the recipient need a smpl.gg account?
A recipient can open an accessible share link without creating an account, but must still satisfy the password and other configured controls.