Password and time controls restrict access to the redirect. They suit staged announcements, temporary partner resources and links that should stop after a deadline, but they do not encrypt the destination.

Plan before publishing

Choose activation for a future start, expiry for a deadline, a human-click cap for limited qualifying redirects, and a password when the secret can be shared separately.

  • Share the password through another channel.
  • Document the time zone.
  • Protect sensitive data at the destination.

Build and test the workflow

A link can activate at 09:00, expire at 17:00 and allow 200 human redirects. Bot, speculative, blocked and password-interstitial requests do not consume that human allowance.

Worked example

Test before activation, wrong password, correct password, after expiry and at the click limit. Also open the final destination directly to decide whether it needs its own authentication.

Measure the right outcome

If access fails, verify time zone, status, expiry and the exact link. Existing passwords are hashed and cannot be displayed later; a successful unlock uses a short-lived signed cookie.

Troubleshooting checklist

  • Correct password fails: test a clean browser.
  • Expiry seems early: check time zone.
  • Cap seems low: compare qualifying human clicks, not all requests.

Product limits and responsible use

A protected redirect cannot revoke downloads, prevent screenshots, identify the recipient or stop sharing of a known destination. Sensitive content still needs authorization at the destination.