Protected URLs: Pages Only You Can Open

Pages that answer 404 to everyone else

Pages only you can open

Protected URLs answer 404 not found to everyone, except the devices, servers and web crawlers you pick. Use them for admin areas, internal documentation, staging pages: for everyone else they simply do not exist.

Where: Servers › My Servers › your server › System › Security › Protected URLs

01 · Protect a URL

  1. Type the full address of a page served by this server, for example https://www.example.com/admin. Everything under it is protected too, like /admin/users. Type only https://www.example.com to protect the whole site.
  2. Under Who may open it, tick what may open it:
    Your devices and WireGuard servers

    Your laptop, your phone, your other servers, by their private address in the WireGuard network.

    Web crawlers

    The Opensolr web crawlers, so a crawl can still index the pages (more).

  3. Click Protect URL. The rule is active on the server right away.

02 · Change or remove one

  • Tick or untick on the row, then Save.
  • Delete makes the URL open to everyone again.

03 · Open it from your device

Your device must reach the server through the tunnel: see Open a protected URL. Sites behind Varnish, HAProxy or Cloudflare: see Behind a proxy.

The list is one list for all your servers: you see every URL you protected, with the server that serves it.

Security section