Skip to main content

Passwords and access

Settings → Access holds three separate controls, not a ladder. Set none of them and anyone holding the link opens the gallery straight away.

One password that everyone uses. You share it alongside the link.

The Gallery password field starts empty. Type your own, or click the wand to generate a six-character one. The eye shows it, and the copy button puts it on your clipboard. Clearing the field removes the password.

Use it when a gallery might travel further than you would like, or when a client has asked for it. It is simple to explain, and easy for a family to share between them.

Email registration​

Visitors must provide an email. No password involved.

Useful when you want to know who has been looking. Nobody checks the address though, so it slows people down rather than keeping them out. The addresses land under Activity → Email Registration.

Client access​

A private password for your client, separate from the gallery password. Turning it on makes a six-character one for you. You can type your own instead, or make a new one with the wand.

Your client is not creating an account and has no login. It is a second, more private password that only they get.

Client access on its own does not lock the gallery

Turning on Client access does not stop anyone else opening the gallery. Without a gallery password, someone with the link still gets straight in as a guest, no password asked.

What Client access does is split your visitors in two, and unlock the two settings below.

If the gallery itself must be private, set a gallery password as well. The two work together.

Turning it on reveals:

Client-only chapters. A switch per chapter. A chapter marked client-only shows only to someone who came in through Client access. The guests you gave the gallery password to never see it.

Let clients hide photos. Lets your client hide a photo so guests cannot see it. The photo stays visible to your client, and to you. Everything they hide is listed under Activity → Private Photos.

That last one is a client control, not one of yours. You cannot hide a single photo from your client. If you do not want someone to see a photo, keep it out of a chapter they can reach, or hide the whole chapter under Settings → Sharing.

What your visitor sees​

With Client access on, the first screen offers Client access and Guest access. Whichever they pick, the form below asks only for what you have actually set up:

Your settingsWhat the visitor is asked for
NothingNothing. The gallery opens.
Gallery password onlyThe gallery password
Email registration onlyTheir email
Client access onlyClient access: the client password. Guest access: nothing.
Client access + gallery passwordClient access: the client password. Guest access: the gallery password.
Any of the above + email registrationThe same, with their email as well

The button reads Enter when a password is involved and Continue when it is just an email.

They are asked once. The gallery remembers them on that device for a week.

Combining them​

They stack. A common setup for a wedding is a gallery password for the couple to share with family, plus client access and client-only chapters for the shots only the couple should see.

SituationUse
Wedding, family portraits, most workNothing. An open link is fine.
Client asked for privacyGallery password
You want to see who is viewingEmail registration
Sensitive or embargoed workGallery password + Client access together

A gallery's address is built from its name, so yourname.corehue.co/summer-wedding is easy to read and easy enough to guess. Do not treat the link on its own as protection. If a gallery genuinely should not be found, put a password on it.

Too many wrong attempts locks people out​

Wrong passwords are limited to fifteen attempts in fifteen minutes, counted per internet connection rather than per person. Everyone on the same connection shares that count.

So a family all trying the password on a wedding gallery can lock each other out between them. They see a message asking them to wait, and it clears on its own after about a quarter of an hour.

If a client reports this, resending the password will not help. Tell them to wait fifteen minutes and try once, carefully. The download PIN has its own limit of twenty attempts in the same fifteen minutes.

Passwords have no rules​

CoreHue sets no rules for how long a gallery or client password has to be, or what it has to contain. Assume one becomes public the moment you send it, and never reuse anything that matters elsewhere.

Access and downloads are separate​

Access controls who can see the gallery. The download PIN controls who can take the files. The two are separate. An open gallery with a download PIN is a sensible combination for work you are happy to have seen but not freely collected. See Downloads.

Changing it later​

The passwords, Email registration, Client access and Let clients hide photos all ride the save bar: they apply when you click Save. The Client-only chapters switches save the moment you flip them.

Adding a password locks out anyone who has not got it, including people who are looking right then. Tell your client before you change anything.