Passwords and access
Settings → Access holds three separate controls, not a ladder. Set none of them and anyone holding the link opens the gallery straight away.
Gallery password
One password that everyone uses. You share it alongside the link.
The Gallery password field starts empty. Type your own, or click the wand to generate a six-character one. The eye shows it, and the copy button puts it on your clipboard. Clearing the field removes the password.
Use it when a gallery might travel further than you would like, or when a client has asked for it. It is simple to explain, and easy for a family to share between them.
Email registration
Visitors must provide an email. No password involved.
Useful when you want to know who has been looking. Nobody checks the address though, so it slows people down rather than keeping them out. The addresses land under Activity → Email Registration.
Client access
A private password for your client, separate from the gallery password. Turning it on makes a six-character one for you. You can type your own instead, or make a new one with the wand.
Your client is not creating an account and has no login. It is a second, more private password that only they get.
Turning on Client access does not stop anyone else opening the gallery. Without a gallery password, someone with the link still gets straight in as a guest, no password asked.
What Client access does is split your visitors in two, and unlock the two settings below.
If the gallery itself must be private, set a gallery password as well. The two work together.
Turning it on reveals:
Client-only chapters. A switch per chapter. A chapter marked client-only shows only to someone who came in through Client access. The guests you gave the gallery password to never see it.
Let clients hide photos. Lets your client hide a photo so guests cannot see it. The photo stays visible to your client, and to you. Everything they hide is listed under Activity → Private Photos.
That last one is a client control, not one of yours. You cannot hide a single photo from your client. If you do not want someone to see a photo, keep it out of a chapter they can reach, or hide the whole chapter under Settings → Sharing.
What your visitor sees
With Client access on, the first screen offers Client access and Guest access. Whichever they pick, the form below asks only for what you have actually set up:
| Your settings | What the visitor is asked for |
|---|---|
| Nothing | Nothing. The gallery opens. |
| Gallery password only | The gallery password |
| Email registration only | Their email |
| Client access only | Client access: the client password. Guest access: nothing. |
| Client access + gallery password | Client access: the client password. Guest access: the gallery password. |
| Any of the above + email registration | The same, with their email as well |
The button reads Enter when a password is involved and Continue when it is just an email.
They are asked once. The gallery remembers them on that device for a week.
Combining them
They stack. A common setup for a wedding is a gallery password for the couple to share with family, plus client access and client-only chapters for the shots only the couple should see.
| Situation | Use |
|---|---|
| Wedding, family portraits, most work | Nothing. An open link is fine. |
| Client asked for privacy | Gallery password |
| You want to see who is viewing | Email registration |
| Sensitive or embargoed work | Gallery password + Client access together |
About the link itself
A gallery's address is built from its name, so yourname.corehue.co/summer-wedding is easy to read and easy enough to guess. Do not treat the link on its own as protection. If a gallery genuinely should not be found, put a password on it.
Too many wrong attempts locks people out
Wrong passwords are limited to fifteen attempts in fifteen minutes, counted per internet connection rather than per person. Everyone on the same connection shares that count.
So a family all trying the password on a wedding gallery can lock each other out between them. They see a message asking them to wait, and it clears on its own after about a quarter of an hour.
If a client reports this, resending the password will not help. Tell them to wait fifteen minutes and try once, carefully. The download PIN has its own limit of twenty attempts in the same fifteen minutes.
Passwords have no rules
CoreHue sets no rules for how long a gallery or client password has to be, or what it has to contain. Assume one becomes public the moment you send it, and never reuse anything that matters elsewhere.
Access and downloads are separate
Access controls who can see the gallery. The download PIN controls who can take the files. The two are separate. An open gallery with a download PIN is a sensible combination for work you are happy to have seen but not freely collected. See Downloads.
Changing it later
The passwords, Email registration, Client access and Let clients hide photos all ride the save bar: they apply when you click Save. The Client-only chapters switches save the moment you flip them.
Adding a password locks out anyone who has not got it, including people who are looking right then. Tell your client before you change anything.