Password-protecting a bio link: what the gate actually covers

Someone wants to put a media kit or a limited-time offer behind a password on a bio link page, and before building it they need to know something the vendor’s marketing page will not tell them: does the lock actually stop a person who has the underlying URL, or does it just hide a link from a page that anyone could otherwise browse.

The bio-link password gate is not one feature

Three mechanisms get lumped together under the word “gate,” and they operate at three different layers. Linktree’s Code Lock sits on a single link. Linktree’s Profile Lock sits over an entire Linktree profile. Beacons’ Media Kit password option sits on one specific page, the media kit, not on the general link-in-bio page. Each vendor documents its own mechanism differently, and none of the three documents map cleanly onto the other two.

This is not a ranking of Linktree against Beacons, and it makes no claim about which tool locks content “better.” That kind of cross-vendor verdict is outside what this piece sets out to do. The goal here is narrower: read what each vendor’s own help documentation says its lock covers, and be explicit about what that documentation leaves unanswered.

What Linktree’s Code Lock actually gates

Per Linktree’s help article on Code Lock, enabling the feature on a link requires visitors to enter a 4-digit numeric code before they can access the content behind that link. The article specifies that only a 4-digit numerical value can be used, and that Code Lock is a feature starting on the Pro plan. To set it up, a creator selects the lock icon under a link in the Links page, chooses the Code option, and enters the 4-digit code visitors will need.

The mechanism, as documented, is scoped to one link on the page. It is not a lock over the whole Linktree, and it does not describe locking the destination URL itself, the page or file the link points to once a visitor gets past the code.

Whether the destination URL sitting behind a Code Lock is reachable by guessing it or requesting it directly, without going through the Linktree page at all, is [EVIDENCE NEEDED: a Linktree document or test confirming whether the destination page itself checks for anything, or whether it is a plain URL that will load for anyone who has it]. Linktree’s own article does not address this, and the honest position is not to guess at an answer the vendor has not published.

What Linktree’s Profile Lock actually gates

  • Per Linktree’s help article on Profile Lock, the feature is documented as a beta (“This feature is currently in development and isn’t available to all Linkers just yet”) and is available on the Starter, Pro and Premium plans.
  • Instead of locking one link, Profile Lock puts a single access gate over the entire Linktree. The article states that no links, social icons, or description render until the visitor meets the condition the creator set.
  • Linktree documents three lock types for Profile Lock: Password, where visitors enter a password the creator set; Code, a 4-digit code; and Subscribe, where a visitor enters an email address to unlock, which the creator captures as a lead.
  • The article states the cookie behavior directly: once a visitor unlocks a Profile Lock, Linktree stores a cookie in their browser so they are not asked again for 30 days. That is a client-side convenience for returning visitors. It is not, by itself, evidence of how the underlying access check works on the server.
  • The downgrade behavior is also documented: if the creator downgrades to the Free plan, the Profile Lock is removed and the Linktree becomes public again, with no lock screen standing between a visitor and the content.
  • Whether a Profile-Locked Linktree is excluded from search engine indexing is [EVIDENCE NEEDED: Linktree’s documentation describes what a visitor sees on the lock screen, not what a search crawler is served or whether the page carries a noindex directive].

What Beacons’ Media Kit password lock actually gates

Beacons documents its media kit access controls in a help article on Media Kit Permissions. That article lists five locking options for the media kit page: Unlocked, where anyone with the link can view it; Email, where a visitor unlocks by submitting an address that gets stored under the creator’s collected emails; Brand Deal Offer, where a visitor unlocks by submitting a brand deal request; Password, a custom password the creator sets and shares at their own discretion; and Approved access, where only accounts the creator has approved can see the locked parts of the media kit, with new requests routed to the creator’s email.

The Password option is documented specifically for the media kit page, not for Beacons’ general link-in-bio page. This piece makes no claim that Beacons offers a password lock on the broader bio-link page, because no vendor document reviewed here says that it does. If a reader wants a password on the main bio-link page rather than the media kit specifically, that is a separate feature question the Media Kit Permissions article does not answer.

Whether the Password option on the media kit blocks a direct request to that page’s URL, or only removes it from whatever navigation would otherwise surface it, is [EVIDENCE NEEDED: the help article describes the act of unlocking, not the access control mechanism sitting behind it].

The question none of these help articles answer

Every one of these three mechanisms is documented from the visitor’s point of view: enter this code, this password, this email, and you see the content. None of the three articles say what technical layer is doing the blocking, and that distinction matters, because “invisible to a search engine” and “unreachable by URL” are not the same guarantee.

Google’s own Search Central documentation on the robots meta tag explains the general shape of the problem, independent of any bio-link vendor. A noindex directive tells search engines not to show a given page in search results. That is what the directive controls: whether the page appears in Google Search. Google’s documentation frames it as an indexing and serving instruction, not as an access restriction, and a page can carry a noindex directive while still being fully reachable by anyone who requests its URL directly.

None of the three vendor help articles examined for this post state whether their lock feature applies a noindex directive, checks access on the server before any content is returned, or is a client-side script that hides content after the page has loaded. Each is a materially different guarantee, and the honest answer to “does this actually stop a search engine or a guessed URL” is that the vendor documentation simply does not say.

The one diagnostic a reader can run without waiting on any vendor is to open the specific locked link or profile in an incognito browser window, with no stored cookie and no prior session, and check whether the destination URL loads without being asked for the password or code. That test will not answer the search-indexing half of the question, but it answers the direct-access half, and it costs two minutes.

Try followed for coverage that stays inside what the vendor actually documents

followed tracks the social media tools market with claims sourced to the vendor’s own page, dated, and never assumed. If a tool changes what a lock covers, or documents a layer it previously left silent, that is the kind of change worth watching. Read the rest of the coverage on the followed blog.

FAQ

Does a password gate on a bio-link page stop the underlying content from being indexed by Google?

Not automatically, and none of the vendor documentation reviewed here says one way or the other. Google’s own documentation treats noindex, which controls search result appearance, and access blocking, which controls whether a page can be reached at all, as two different things. Since none of Linktree’s or Beacons’ help articles state whether their lock applies a noindex directive, the honest answer is that this is unverified by the vendors and should not be assumed to mean the content is hidden from search.

What is the difference between Linktree’s Code Lock and Profile Lock?

Code Lock gates one specific link on a Linktree page and requires visitors to enter a 4-digit code, and it starts on the Pro plan. Profile Lock, a beta feature on Starter, Pro and Premium plans, gates the entire Linktree so nothing renders, no links, icons, or description, until the visitor satisfies a Password, Code, or Subscribe condition, per Linktree’s own documentation.

Can I password-protect my whole Beacons link-in-bio page, or only the media kit?

The password lock option documented in Beacons’ Media Kit Permissions article is scoped to the media kit page specifically. No vendor documentation found for this post describes a password lock on Beacons’ general link-in-bio page, so that claim should not be assumed to exist.

If someone already has the direct URL to my locked link or page, can they skip the password?

This is exactly the question the vendor help articles reviewed here leave open. None of them state whether the destination behind a lock checks access on the server or relies on the lock screen alone. The only way to know for a specific account is to test the direct URL yourself, in a browser with no stored cookie, and see what loads.

Sources

Scroll to Top