# Password-protecting a gallery

> Password-protect a client gallery in CoreHue with one switch. CoreHue generates a 6-character password you can keep, change or copy to send to your client.

Source: https://help.corehue.co/docs/gallery-sharing/password-protecting-a-gallery/

A gallery password is the simplest way to keep a gallery private. Everyone who opens the link needs the same password, so it's easy to explain and easy for a couple to pass on to family.

## Turn on a gallery password

1. Open the gallery and go to **Settings → Access**.
2. Turn on **Gallery password** ("Require visitors to enter a password to view this gallery.").
3. CoreHue fills in a 6-character password for you. Keep it, or type your own.
4. Click **Save**.

Beside the password are three small buttons: the eye shows or hides it, **Copy password** puts it on your clipboard, and **Generate password** (the wand) makes a new random one.

If you turn the switch on and leave the field empty, you'll see "Enter a gallery password or turn off password protection." when you save.

## Send the password to your client

The easiest way is to tick **Gallery password** under **Include in email** when you share the gallery. It appears in a box inside the email, right under your message. See [Sharing a gallery by email](/docs/gallery-sharing/sharing-a-gallery-by-email).

You'll also find it, with a copy button, in the **Share** dialog in the gallery header. See [Sharing a gallery link or on social media](/docs/gallery-sharing/sharing-a-gallery-link).

## Change or remove the password

- **To change it,** type a new one (or click the wand) and click **Save**.
- **To remove it,** turn off **Gallery password** and click **Save**. The gallery opens without a password again.

Changing or adding a password affects your client straight away, so let them know before you do it. Anyone without the new password is asked for it.

## What your client sees

Your client opens the link and sees your cover image with a small form: **Gallery password**, an **Enter** button and, if you've also turned on email registration, an email field. They type the password, press **Enter**, and the gallery opens. They won't be asked again on that device for 7 days.

A wrong password shows "Invalid password. Please try again." After several wrong tries, the gallery pauses attempts for about 15 minutes, and your client sees a "Too many attempts" message that says how long to wait. The pause applies to everyone on the same internet connection, so a family all guessing at once can lock each other out. If that happens, resending the password won't help. Ask them to wait until the pause ends, then copy and paste the password.

## Picking a good password

CoreHue doesn't set rules for length or characters, so the generated 6-character password is a sensible default. A few tips:

- **Make it easy to type on a phone.** Most clients open galleries on their phone.
- **Keep it separate from passwords that matter.** Assume it's shared the moment you send it.
- **Use a different password for each gallery.** If one leaks, the others stay safe.

## Frequently asked questions

### Is the gallery password case sensitive?

Yes. A gallery password has to match exactly, capitals included, so asking your client to copy and paste it rather than retype it avoids most problems.

### Can my client reset the password themselves?

No. Clients can't reset a gallery password themselves, because the password belongs to the gallery, not to an account. If they lose it, resend it from the **Share** dialog.

### Does a gallery password stop downloads?

Only for people who don't have it. A gallery password stops anyone without the password from opening the gallery at all. Once someone's in, downloads depend on your download settings. To control downloads separately, use a download PIN. See [Using a download PIN](/docs/gallery-downloads/download-pin).

### What's the difference between the gallery password and the client password?

The gallery password is shared by everyone who opens the gallery. The client password comes with **Client access** and is just for your client, and shows them anything you've kept for them. See [Giving your client private access](/docs/gallery-sharing/client-access-and-private-passwords).
