DocuGate

How do I password protect a Docusaurus site?

Docusaurus has no login of its own. The four ways to put a password or sign-in in front of a Docusaurus site, and what each one costs.

By ·

The short answer

Docusaurus has no built-in password or login, because it builds a static site that whatever hosts it serves to anyone. To protect it, put a gate in front of the files: your host's password protection, an identity proxy such as Cloudflare Access or oauth2-proxy, or a platform that serves the markdown behind a sign-in.

The short answer

npm run build in Docusaurus produces a folder of HTML, CSS and JavaScript. There is no server in that folder and so no point at which it can ask who you are. The password has to come from whatever serves those files, or from something placed in front of them. There are four common ways to do that.

Why a client-side check is not enough

It is tempting to add a password prompt in a React component. The problem is that the page content is already in the files the browser downloaded. Anyone can open the network tab, or fetch the HTML directly, and read it. A real gate refuses to send the content at all.

The options

OptionHow it worksCostTrade-off
Host password protection (Netlify, Vercel and others)The host asks for a password or a team sign-in before serving the deploymentCheck your host's plan; it is often on a paid tierOne shared password, or readers need an account on the host
Cloudflare AccessYour domain runs through Cloudflare, which asks readers to sign in with email or an identity provider before passing the request onFree tier for small teams, as of October 2026; check current limitsNeeds your domain on Cloudflare
oauth2-proxyA small server sits in front of the static files and requires a Google, GitHub or other OAuth sign-inFree software; you run the serverYou maintain the server and its configuration
A platform that gates the markdownThe platform reads your markdown and only sends a page to a reader who passes its checkVaries; DocuGate Pro is $5/moYou leave Docusaurus's theme and plugins behind

Steps for the proxy route

Cloudflare Access is the usual choice for a team already using Cloudflare.

  1. Deploy the Docusaurus build as you do now, on a custom domain.
  2. Move the domain's DNS to Cloudflare and make sure the record is proxied.
  3. In Cloudflare Zero Trust, add a self-hosted application for the domain.
  4. Write a policy: the email addresses or the email domain allowed in.
  5. Open the site in a private window and confirm you are asked to sign in.

Make sure the original deployment URL from your host is not reachable on its own, or readers can go around the proxy.

The platform route

If most of your Docusaurus content is plain markdown, a platform can serve it without the build. DocuGate reads a docs folder from a GitHub repository: folders become sidebar groups, the first # heading becomes the title, and index.md becomes the landing page. Each space is Public, Repo access (anyone who can open the repository on GitHub) or Allowlist (named GitHub logins or email addresses). Allowlisted readers without GitHub can sign in with Google. The check runs on the server, before any markdown is read.

The cost is the theme and plugins. Pages written as .mdx or relying on React components will not carry over. See access control and pricing.

Questions people also ask

Is there a Docusaurus plugin that adds a password?

There are community plugins that hide pages behind a password prompt in the browser, but the built HTML and JavaScript are still downloaded by anyone who asks for them. A check that runs in the reader's browser is one the reader controls, so treat these as a curtain, not a lock.

Which option is cheapest?

Cloudflare Access and oauth2-proxy cost nothing in money, but take setup and some infrastructure knowledge. Host protection is the least work if your host includes it on your plan. Check the current plan before you rely on it.

Can I protect only some pages of a Docusaurus site?

With a proxy, yes, by writing rules per path. With host password protection it is usually the whole deployment. Splitting public and private docs into two deployments is often simpler.

Will DocuGate render my Docusaurus site as it is?

No. DocuGate reads the .md files in a folder and builds the navigation from the folders. It does not run Docusaurus, so React components, MDX files and Docusaurus plugins are not rendered.

Read next

Get started with DocuGate, free.