How to create a QR code with a password
Password-gated QR codes keep private links, internal wikis, and paid content locked to the people you actually want scanning. This guide walks through the setup, from picking a gating method to testing the prompt on real phones.
Key Takeaways
- The QR code encodes a URL, not the password itself — protection sits on the landing page, not inside the image.
- Shared-passphrase gates work best for one-off events; account logins fit recurring internal use like team wikis or client portals.
- Dynamic QR codes let you rotate the destination or revoke access without reprinting anything, which matters if a password ever leaks.
- Always test the flow on both iOS and Android before printing — some in-app browsers handle password prompts differently than Safari or Chrome.
Imagine you're a wedding planner and you printed a QR code on the back of every save-the-date, expecting only invited guests to scan it. Within a week the link has been screenshotted, texted to a group chat, and shared on a family Facebook thread. The RSVP form filled up with names nobody recognized. Sounds frustrating, right? That kind of accidental leak is exactly what a password layer prevents — the code still scans for anyone with a phone, but the content behind it stays locked until the visitor types the right phrase.

The same problem shows up in HR portals, paid workshop replays, investor decks, and anything else you'd rather not post to the open web. According to Egress Email Security, QR codes appeared in 12.4% of phishing attacks in 2023 (a tactic known as quishing), so users are increasingly cautious about where a scan leads them. Adding a password does two useful things at once: it filters out anyone who shouldn't see the content, and it signals to legitimate scanners that whatever's behind the code is worth guarding.
The important detail is that the QR code itself doesn't hold the password. QR codes are just images that encode a URL or a bit of text — anyone with a scanner can read what's inside them. The protection lives on the destination page, which is where you configure the login prompt, the shared passphrase, or the token check.
Step-by-step setup
There are three common ways to add a password to a QR code, and the right one depends on how many people need access and how often. Below is the setup for each, followed by the parts of the workflow that apply no matter which method you choose.
Step 1: Pick your gating method
For a small guest list or a single event, a shared passphrase page is the simplest option — one password, everyone who needs it gets the same phrase. For an ongoing internal resource, use an existing tool your team already logs into (Notion, Google Drive with restricted sharing, a private WordPress page, or a Dropbox link with password enabled). For paid content or gated downloads, a service like Gumroad, Podia, or a membership plugin handles both payment and the password in one flow.
Step 2: Build the protected landing page
Create the page that will sit behind the code. If you're using Google Drive, upload the file and choose "Restricted" sharing, then copy the share link. On WordPress, open any page or post, find the Visibility setting in the sidebar, switch it from Public to Password Protected, and set the phrase. Dropbox users can right-click a file, choose Share, then toggle "Password" under link settings. Whichever tool you use, open the resulting URL in an incognito window and confirm the password prompt actually appears before moving on.
Step 3: Generate the QR code from that URL
Head to the free QR code generator and paste in the protected URL. Choose a dynamic code if you might rotate the password later — dynamic codes let you swap the destination URL without reprinting the image, which is useful if a password leaks or you move the file to a new host. Static codes are fine for one-time use where the link will never change.
Step 4: Deliver the password separately
Never print the password next to the QR code. That defeats the whole point — anyone who photographs the flyer gets both halves. Send the password through a different channel: an email, a text message, a printed insert handed out at check-in, or a slide shown only to attendees in the room. The split delivery is what keeps the gate meaningful.
Step 5: Test on real devices
Scan the code with an iPhone using the native camera, then with an Android using Google Lens, then once more from a scanner app. Some third-party scanners open links inside their own embedded browser, which occasionally breaks password fields on WordPress or Dropbox. If that happens, most scanners have a "Open in Safari/Chrome" button — note that step in whatever instructions you send along with the code.
Tips for password-protected codes
A few small adjustments make the difference between a gate that actually protects your content and one that frustrates real users into giving up. These come from watching hundreds of these setups go live.
Use passphrases like "silverfox-april" instead of "Password123" — they're easier to type on a phone keyboard and much harder to guess than short passwords.
Add a short line of text under the printed code that reads "You'll be asked for a password after scanning" so visitors don't assume the code is broken when the prompt appears.
Rotate the password after big events — if 200 people scanned your workshop replay code, assume the phrase is now semi-public and change it before the next cohort.
For sensitive material (medical records, legal documents, HR files), skip the shared-passphrase approach entirely and use per-user logins through a proper identity provider. Read our notes on how to check if a QR code is safe before publishing anything regulated.
If you're gating a PDF, consider using a PDF QR code that points to a password-locked file rather than embedding the password in a landing page — one less hop for the visitor.
Frequently Asked Questions
Can I put the password directly inside the QR code?
Technically yes — you can encode text like "Password: silverfox" into a QR code — but it offers no real protection, because anyone who scans the code sees the password immediately. The password has to live on the destination page, not inside the code itself.
Do password-protected QR codes still work offline?
The scanning step works offline (the phone reads the encoded URL from the image), but the password prompt requires an internet connection because it lives on the landing page. If your venue has weak signal, warn attendees in advance or provide WiFi.
What happens if someone shares the password?
With a static code, you'd need to reprint everything to change the destination. With a dynamic code, you can update the URL or password in your dashboard and every existing printed code instantly points to the new gate. That's the main reason to choose dynamic for anything sensitive — see our static vs dynamic comparison for the full breakdown.
Is a password-protected QR code the same as an encrypted QR code?
No. Encryption scrambles the data inside the code so a normal scanner can't read it — those require special decoding apps and are rare outside enterprise use. A password-protected code uses a normal QR image; the security sits on the web page it opens.
Can I password-protect a WiFi QR code?
WiFi QR codes already contain the network password inside the code itself, so anyone who scans gets the credentials. If you want to control who joins, use a guest network with rotating passwords or a captive portal instead. Our WiFi QR code guide covers the trade-offs.
Related Guides
Ready to create your QR code?
Generate custom QR codes in seconds - free and easy to use.
Create Free QR Code →