Most file sharing tools — WeTransfer, Dropbox, Google Drive — charge extra for password-protected links. ShareText includes password protection on every link, free.
Create a share link, add a password, set an expiry, and send it. Recipients see a password prompt before they can access your files.
What you get
Everything included. No paid plan required.
Password on every link
Add a password to any file share. Recipients must enter it before the files are shown.
Always free
No paid plan, no upgrade prompt. Password protection is included in the free tier — always.
Combine with expiry
Set a password and an expiry together. The link deactivates when time runs out, even if the password is known.
Add view limits too
Combine password protection with a view limit. After the set number of opens, the link deactivates.
Up to 10 files per link
Bundle multiple files behind one password-protected link. One link, one password, everything in one place.
No recipient account
Recipients open the link in any browser and enter the password. No sign-in, no app, no account required.
How it works
Upload your files
Add up to 10 files, 15 MB each. You can do this as a guest — no account needed to create a password-protected link.
Set a password
Choose a password for the link. It's applied to the whole bundle, so one password covers every file on the page.
Send link and password separately
Email the link, send the password by text or chat. Splitting them across two channels is what makes the password worth having.
Recipients unlock in the browser
They see a password prompt, enter it once, and the files appear. The unlock lasts for their session — they don't re-enter it on every file.
Why password protection is usually a paid feature
On most consumer file sharing services, password-protected links sit behind the first paid tier. WeTransfer puts them in a subscription. Dropbox reserves them for paid accounts. Google Drive doesn't offer link passwords at all — sharing is governed by Google accounts and domain rules instead.
The reasoning is commercial rather than technical: a password prompt is a small amount of engineering, but it's a reliable trigger for an upgrade because the moment you need it, you usually need it immediately. ShareText includes it on the free tier because a link that anyone who sees it can open isn't really private sharing — it's publishing with an obscure URL.
A password is a second channel, not a stronger link
The security value of a link password comes almost entirely from where you send it. A password pasted into the same email as the link adds nothing — anyone who reads the email has both halves. Sent through a different channel, it means an intercepted or forwarded link is useless on its own.
This matters because links leak in ordinary, undramatic ways. Emails get forwarded to a wider group than intended. URLs get pasted into support tickets, project boards, and group chats where they outlive the conversation. Someone screenshots a message. In each case the link travels; the password, sent separately, usually doesn't.
It also gives you a clean way to revoke access to a person rather than to a link. If someone shouldn't have access any more, you don't need to move the files — you create a new link with a new password and only distribute it to the people who should still have it.
Combining passwords with expiry and view limits
Password protection composes with the other access controls rather than replacing them. A password answers 'who can open this', an expiry answers 'for how long', and a view limit answers 'how many times'. Applying all three to a sensitive document means access ends when any one condition is met.
A practical pattern for something like a signed contract or an export containing personal data: password on, expiry set to 24 hours, view limit set to the number of people who genuinely need it. The recipient gets what they need; the exposure window is measured in hours rather than years; and the link is inert long before anyone gets around to auditing it.
Passwords cannot be recovered, by design — we store a hash, not the password itself. If you lose it, delete the link and create a new one. That's a deliberate trade: a password we could recover for you is a password we could be compelled to hand over.
Frequently asked questions
Is password protection really free?
Yes. No paid plan, no account required to add a password to a link. It is included on every share.
How do I share the password with recipients?
Send it separately from the link — via message, email, or however you prefer. Keeping the link and password in separate channels adds an extra layer of security.
Can I combine a password with an expiry date?
Yes. You can set both a password and an expiry on the same link. The link deactivates when the earlier condition is met.
What if I forget the password?
Passwords cannot be recovered. If you lose the password, delete the link and create a new one.
Do recipients need an account to enter the password?
No. They open the link in any browser, enter the password, and the files appear. No sign-up, no app install.
How many files can I put behind one password?
Up to 10 files per link, with a maximum of 15 MB per file. The password applies to the whole bundle, not to individual files.
Is the password stored securely?
We store a hash of the password, not the password itself. That is also why it cannot be recovered — there is nothing to look up.
Can I password-protect a note as well as files?
Yes. Notes support the same password protection, and can additionally be end-to-end encrypted so that even we cannot read the content.
Add a password to your next file share.
No setup, no account. Ready in under a minute.