Add Password Protection to a Dynamic QR Code
Require a shared password before QRLynx opens the QR destination. Change or remove the password later without reprinting the code.
Selected QR Code Type
QRLynx Password Protection adds a shared password gate to eligible dynamic QR codes on Pro, Business, and Enterprise. A scanner sees a QRLynx password page before the destination opens. The account owner can replace or remove the password without reprinting the QR.
The password gate protects the QRLynx redirect, not the destination itself. If someone already knows or receives the direct destination URL, that destination follows its own access rules. Use the destination service's authentication and permissions for confidential files, personal records, or regulated data.
What QRLynx Password Protection does
A practical gate for shared access, with controls that stay editable after printing.
Shared Password Gate
Visitors must enter the same account-defined password before the managed QR route continues.
Change Without Reprinting
Replace the password or remove the gate while keeping the same printed dynamic QR code.
One-Way Password Storage
New passwords are stored as salted PBKDF2 hashes rather than readable password text.
Rate-Limited Attempts
Repeated verification attempts are limited by both the request source and the individual QR code.
Successful Scan Analytics
A qualifying scan is counted after the visitor passes the password gate and reaches the destination flow.
One Account View
Review every password-protected QR and open its password settings from Account Password Protection.
Password gate and destination security solve different jobs
Use the QRLynx gate to control the managed QR route. Use the destination system to protect the content itself.
| Layer | What QRLynx controls | What it does not control |
|---|---|---|
| Printed QR pattern | Contains the managed QRLynx short URL | Does not contain the password or final destination |
| Password page | Checks one shared password before the redirect continues | Does not identify a person or create a user account for the visitor |
| Destination | Stays hidden from the ordinary QR redirect until the password is accepted | Can still open directly if its URL is known and the destination has no access control |
| Analytics | Counts qualifying scans that pass the access gate | Does not show who entered the password or list failed password attempts |
| Password management | Lets the account owner replace or remove the password | Does not reveal or recover the existing password text |
How to create a password-protected QR code in QRLynx
Configure the destination, add the gate, test both outcomes, and keep the printed code manageable.
Choose an eligible dynamic QR type
Sign in to QRLynx and choose a supported standard QR type such as Website, PDF, Multi Link, or Digital Business Card. Password Protection requires the managed dynamic route and is not available for GS1 Digital Link.
Add the destination or content
Enter the final URL or complete the selected QRLynx content type. Confirm that the destination has its own login or permissions when the underlying information needs stronger access control.
Open Password Protection
Open the generator settings, choose Password Protection, and review the Pro plan prompt if the account does not yet include the feature.
Set a password of at least six characters
Enable the feature and enter a password between 6 and 100 characters. Share it with the intended group through a suitable separate channel.
Save and download the dynamic QR
Save the QR so QRLynx stores the password hash and the protected state, then download the code for the intended placement.
Test a wrong and correct password
Scan the downloaded QR and confirm that a wrong password stays on the gate while the correct password continues to the expected destination. Test the printed proof before distribution.
Replace or remove the gate when access changes
Use Account Password Protection or edit the saved QR to set a new password or turn the feature off. The same printed dynamic QR remains usable.
Destination and access plan ready
Create the dynamic QR, then add its password gate
Build the destination first, enable Password Protection in the QR settings, and test both the locked and accepted paths before printing.
Use destination authentication for highly sensitive content
A shared QR password is useful when a known group needs one extra gate before a managed link opens. It is not a replacement for individual accounts, file encryption, revocable per-person credentials, a signed download system, or the security controls required for personal, financial, medical, or regulated information.
Good fits for a shared QR password
Choose this feature when a group can share one secret and the destination does not depend on individual identity.
Staff Reference Page
Add a shared gate before a handbook, schedule, or internal reference page that already follows the organization's access policy.
Client Preview
Limit an early design, catalog, or campaign preview to clients who received the current shared password.
Wholesale Catalog
Place a password gate before a trade-only catalog or price list, then rotate the password when the audience changes.
Private Event Details
Share a venue map, itinerary, or attendee resource with invited guests who know the event password.
Classroom Resource
Gate a teacher resource or answer key for a defined group while keeping student accounts and grades in the school's own system.
Staged Launch
Share pre-launch material with a controlled group, then remove the password when the same dynamic QR becomes public.
Compatibility and limits
The password gate uses the standard QRLynx dynamic redirect path and has a few important boundaries.
| Configuration | Supported? | What to know |
|---|---|---|
| Eligible standard dynamic QR | Yes | The QR must use the managed dynamic route |
| Static QR | No | A directly encoded static destination has no server gate |
| GS1 Digital Link | No | GS1 uses its separate resolver contract and excludes advanced redirect gates |
| Lead Form on the same QR | No | QRLynx requires the owner to choose either Lead Form or Password Protection |
| PDF or hosted QRLynx content | Yes, when the type is eligible and dynamic | The gate protects the QRLynx route, while a separately shared direct content URL follows its own rules |
Add a password gate to your next dynamic QR
Password Protection is included with Pro and higher plans. Create the destination, set the shared password, and test the visitor flow before the code is distributed.
QRLynx Password Protection questions
Exact answers about access, plans, passwords, analytics, and compatibility.
Does a password-protected QR code encrypt the destination content?
No. QRLynx checks the password before its managed redirect continues, but it does not encrypt the destination page or file. If the direct destination URL is known, that service's own authentication and permissions determine whether it opens.
Which QRLynx plans include Password Protection?
Password Protection is included with Pro, Business, and Enterprise. The feature begins on Pro at $14 per month. The free Starter plan and Starter+ do not include the password gate.
Which QR codes can use a password?
Password Protection works on eligible standard QR types saved through the dynamic route, including common URL, PDF, and hosted-content types. Static QR codes cannot use the gate, and QRLynx does not offer it for GS1 Digital Link.
Can I change or remove the password after printing?
Yes. Edit the saved QR, set a new password or turn Password Protection off, and save. The managed short URL and printed QR pattern remain the same.
Can the account owner view a forgotten QR password?
No. New passwords are stored as one-way salted PBKDF2 hashes rather than readable text. An authorized account user can replace the password with a new one, but QRLynx does not reveal the previous password.
What password length does QRLynx accept?
The server accepts passwords from 6 to 100 characters. Use a password that is difficult to guess and distribute it through a channel appropriate for the audience and information involved.
Do failed password attempts appear in QR analytics?
No. QRLynx scan analytics counts qualifying scans after the visitor passes required access gates. It does not provide a failed-attempt log or identify the person who entered a password. Repeated attempts are rate limited.
Can Password Protection and Lead Form run on the same QR?
No. QRLynx treats Password Protection and Lead Form as mutually exclusive on one QR. Choose the shared password gate for restricted access or Lead Form for consent-based contact capture.
Where can I manage all password-protected QR codes?
Open Account Password Protection to see protected QR names, types, scan totals, status, and an Edit Password action. You can also edit an individual saved QR and open its password panel.
Continue with the right access guide
Read the password-protected QR code setup guide for a deeper implementation walkthrough. Use Access Consent when visitors must accept a notice, or Lead Forms when the campaign needs consent-based contact capture instead of a shared password.