Lock It Down: Password-Protected Links for Creators
Zippy's new password-protected links put a password in front of any short link — perfect for private drops, paid resources, and close-friends-only content. And they still open the native app.


⚡ Zippy: some links aren't for everyone. put a password on it and only the people you tell can get in. i'll guard the door.
Not everything you share should be open to the whole internet. The early drop for your paid members. The Notion doc you only want your client to see. The link you post in a close-friends story and really don't want screenshotted into the group chat. Until now, a short link was a short link — anyone with it walked right in.
Today that changes. Meet password-protected links.
What it does
Put a password on any Zippy link. When someone opens it, instead of going straight through, they see a small "This link is locked" screen and have to type the password first. Get it right, and Zippy sends them on — springing the native app just like always. Get it wrong, and they stay at the door.
The destination is never revealed until the password is correct. Not the URL, not a preview — nothing. Even the link-preview card that platforms build when you paste a link shows the lock screen, not your secret destination. Nothing leaks.
Why creators actually want this
- Paid or members-only drops. Share the link publicly, hand the password to the people who paid. One link, gated access.
- Client & collaborator hand-offs. Send a work-in-progress without it floating around the open web.
- Close-friends content. A link that's just for your inner circle — with a password only they know.
- Soft launches. Post the link early, unlock it (with the password, or by removing it) when you're ready.
We never see your real password
Here's the part we care about most: Zippy never stores your actual password. We keep only a one-way scrambled version of it (a hash). The password you type lives only in the moment you set it — after that, even we can't read it back.
When a visitor enters a password to unlock the link, Zippy scrambles what they typed the exact same way and compares the two. Match, they're in. The real password is never transmitted, never stored, never logged. (The trade-off: there's no "show my password." Forget it? Just set a new one — takes two seconds.)
It still opens the real app
This is Zippy, so the whole point still holds: once a visitor unlocks the link, the destination opens the native app where there is one — the real Instagram app, the real TikTok app, straight out of the in-app browser — not some sad web tab. The password is a door in front of the same native-app magic, not a replacement for it.
It also composes with everything else: your UTM campaign tags and your geo & device routing all work behind the gate. Password first, then Zippy figures out the right destination and tags it.
How to turn it on
On the web dashboard: in the ZIP form (or any link's editor), open Password protection, tick Require a password, and type one. Want to change it later? Type a new one. Want to open the link back up? Untick the box and save.
In the mobile app: open a link's detail screen, find the Password section, flip the switch, type a password, hit save. Remove it the same way — switch off, save.
Changes are instant, and the short link itself never changes — so anything you've already shared keeps working. It just starts (or stops) asking for the password.
The gist
Password-protected links are available on Hero and up — the docs cover how the unlock is remembered per device, and the changelog has the day it landed. One password turns any Zippy link into a private door — for your paid drops, your clients, or your close friends — while still opening the real app on the other side. Lock it down. ⚡
Ready? Start zipping →