Who the link is for.
“Make it live” hides a choice. The right gate depends on who is supposed to open the page, not on how finished the design feels.
Three audiences, three shares
Friends and the public. You want a URL you can drop in a chat or a post. Anyone with the link may open it. That is a feature. Hiding it behind a login means the people you hoped would look will not. Use a public link when the page is a portfolio piece, a landing page, or a toy you are happy to have forwarded.
A client, a classmate, or five coworkers. The work is real enough to react to, and not ready for strangers. A short shared code in front of the same URL is the right weight. You send the address and the code together. You can turn the gate off later without uploading the files again, once you decide the page can be public. You can also mint a new code if the old one spread further than you meant.
Named people with private data. A code is not an account. It does not tell you who visited, and anyone who receives it can pass it on. If the page shows one customer’s information, or lets a visitor change someone else’s rows, you need real sign-in. Do not invent that on the night you are only trying to get feedback on a layout.
What a simple gate is good at
A six-digit code, or any short shared secret, answers one question: did the visitor receive the thing I sent on purpose? It is easy to read over a call. It does not require the visitor to create an account on a site they may open once. It keeps a half-finished draft out of a casual search for the title.
It is bad at other jobs. It is not encryption of the files at rest. It is not a record of who looked. It is not a substitute for keeping account tokens out of the page. Treat it as a door on a demo, and you will use it well. Treat it as security for private data, and you will trust it too much.
Decide before the upload
The awkward moment is publishing publicly and only then realizing a client’s draft name, an unreleased price, or a personal photo is on the page. The fix is a question you ask while the files are still local:
- If a stranger opens this tonight, what is the worst thing they see?
- If I only send it to one person, will they need to log in, or will they give up?
- Do I need to know who visited, or do I only need to keep the casually curious out?
Public is the right default when the worst thing a stranger sees is an unfinished visual. Private, with a code you can rotate, is the right default when the page is a draft for a specific room. Accounts are the right default when the rows themselves are private.
You can change your mind after the page is up. Making a public page private, or a private page public, should not require a second afternoon of DNS. The audience can change. The files can stay where they are.