Add a password to your QR code link
A QR code printed on a poster, a menu, or a handout is public the moment it goes up: anyone with a phone can scan it. Most of the time that's the whole point. Sometimes it isn't, and the destination behind the code should only open for people who were actually given a reason to be there. Reticle's dynamic links can require a password before they redirect, as part of Reticle Pro.
How it works
A dynamic QR code doesn't encode your destination directly, it encodes a short Reticle link
(open-qr.link/a1b2c3) that redirects to wherever you've pointed it. Normally a
scan resolves instantly. Turn on password protection and that same scan lands on a small page
asking for a password first. Enter the right one and the redirect continues exactly as before,
and that visit counts as a scan. Enter the wrong one and the page re-shows with an error, uncounted.
Because the gate lives on the link itself rather than in the code, nothing about the printed QR code changes. You can turn protection on, off, or swap the password at any time without touching whatever you've already printed, mailed, or handed out.
Step 1: use a dynamic link
Password protection is a dynamic-link feature, so you'll need one to protect. If you're starting from scratch, build your QR code as usual on the generator and choose Create dynamic link before you generate it (sign in takes a few seconds, and dynamic links themselves are free). Setting the password in the next step is part of Reticle Pro. Already have a dynamic link you want to lock down? Skip ahead, this works on any existing one.
Step 2: turn it on from My codes
Open My codes, switch to the Dynamic tab, and select the link. In the detail pane you'll find a Password protection row showing "Off, click to add." Click it, type a password, and save. The row flips to "On," and every future scan of that link now asks for it first. Changing your mind later, whether that's a new password or removing it entirely, is the same row.
Step 3: what your visitors see
Scanning a protected link opens a plain page with one field and no branding tricks: enter the password, submit, and (if correct) land on your destination. There's a deliberate limit worth knowing about before you rely on this: Reticle doesn't set a cookie or remember a device, so every single scan re-prompts, even the same phone scanning twice in a row. That's a tradeoff in favor of simplicity: no session to manage, nothing stored on the visitor's side, and no weirdness around a password that "sticks" on one device but not another.
If someone starts guessing, the link locks itself out for a few minutes after enough wrong attempts in a row, so a printed code sitting in a public place can't be brute-forced by a bored passerby. None of those failed guesses show up in your scan counts either, your stats stay clean.
What it's good for (and what it isn't)
One thing to understand first: this isn't real security, it's closer to a lock on a bike than a vault at a bank. Whoever you give the password to can just as easily text it to someone else, so don't use this to protect anything that truly needs to stay private, like financial details or sensitive personal information.
Where it works well is for stuff that's out in public but not meant for just anyone who walks by: an RSVP page for a private party, a house listing shared only with buyers your agent has already spoken to, a beta version of an app you're testing with a small group, or handouts for a class limited to the people who actually showed up. The QR code itself still has to be posted somewhere public, on a flyer, a printed card, a listing page. The password just stops a random stranger who scans it out of curiosity from reaching the same page as the people you actually gave it to.
It only works on regular dynamic links right now, the kind that redirect to a web page. Dynamic vCard contact links don't support it yet, since those show a contact card and offer a file download, and protecting both without asking for the password twice would need a login system Reticle hasn't built.
A note on how it's stored
Reticle never stores the password you set, only a salted hash of it, the same one-way approach a password manager uses. There's no way for Reticle, or anyone with access to the database, to look up the original password from what's saved. If you forget it, there's no "recover" option, only "remove it and set a new one."
Frequently asked questions
Is password protection a paid feature?
Setting a password is part of Reticle Pro ($12 a month or $99 a year, see the pricing page). Removing a password you already set works on any plan, and an existing password keeps protecting the link even if Pro lapses.
Does password protection work on every dynamic link?
It works on redirect links and on file links (the Pro kind that serves an uploaded PDF or image). It isn't available on dynamic vCard contact links, since those serve a contact page and a downloadable vCard file that would need a login session to avoid asking for the password twice.
Will people have to enter the password every time they scan, or just once?
Every time. Reticle doesn't set a cookie or remember a device, so each new scan shows the password page again, even from the same phone a minute later. That's deliberate: no session to manage and nothing stored on the visitor's end.
What happens if someone guesses the password wrong a bunch of times?
After too many wrong attempts in a short window, the link locks and returns an error page for a few minutes, even to someone who then enters the correct password. Wrong attempts also never count as scans, so a string of guesses won't skew your scan stats.
Does adding a password change the printed QR code?
No. The code still points at the same short link, so nothing you've already printed or handed out needs to change. Turning the password on or off, or changing it, all happen afterward from My codes.
Can I see or recover a password I set earlier?
No. Reticle stores a salted hash of the password, not the password itself, so even Reticle can't look it up. If you forget it, remove it and set a new one from the same Password protection row.
Make a dynamic QR code, then open My codes and add a password from the Dynamic tab. Password protection is part of Reticle Pro.