Passwords, email/OTP and access restrictions
All these settings are available when creating a link in the corresponding additional blocks and subsequently in the link card → «Settings». Save each modified form.
Link password
Specify a non-blank password of up to 256 characters. The password cannot consist only of spaces. Give it to the recipient in a separate, convenient way. When opened, the link will show the form; the correct password allows you to continue checking and clicking on the link. An incorrect password should not open the target URL.
To change, enter a new password and save. To remove protection, use the «Remove password» flag. The field does not show the previously saved password. Do not use your account password here.
Access via email and one-time code
Enable email/OTP and, if necessary, set allowed emails or domains. The visitor enters the address, receives a six-digit code and confirms it. The code is valid for 10 minutes; Up to five entry attempts are allowed. The number of code requests for one link is limited to ten per minute.
List examples: person@example.com, @example.com, *.example.com. Separate values with commas, semicolons, or line breaks. The list is limited to 2048 characters. An empty list does not set domain restrictions: confirmation of the entered email is required, but not affiliation with a specific organization.
If there is no letter, check your email, Spam folder and allowed list. After requesting a new code, use the current email. Do not publish the code you receive: it is intended to confirm the recipient's access.
Allowed referrers
Referrer - browser information about the source of the click on the link. You can add a host name, origin, or a subdomain mask to the list: for example, partner.example, https://partner.example, *.trusted.example. The separators are the same as for the email list; maximum length is 2048 characters.
If the restriction is enabled, direct opening from the address bar, app, or QR may fail to pass the referrer and result in a denial. The source site or browser itself may also be hiding it. To check, follow the link from a truly authorized page. Referrer is not a reliable proof of identity; for specific people access, use a password or email/OTP.
Preview and warning
The preview page lets visitors review a link before continuing. The warning page asks for an additional confirmation. You can enable either mode alone or combine them with other restrictions. Continuing does not bypass the remaining access checks.
Use a new private window to test the entire access flow: the current session may already remember some confirmations. Use the simulator when it is sufficient, instead of increasing a click limit merely to run repeated tests. Password and OTP access still need to be checked with a real visit.