Links that expire, cap out, or ask for a password
Sep 2, 2026 · 4 min read
Most short links should be permanent and open, and the default is exactly that. But three optional settings — an expiry date, a click limit, and a password — turn a link into something with a shape, and each solves a problem the others do not. Knowing which is which saves you from reaching for the wrong one.
An expiry date stops the link working after a day you choose. It fits anything with a calendar attached: a registration window that closes, a limited-time offer you do not want circulating in January, a document that is only current until the next version ships. The useful property is that it fails closed. You do not have to remember to go back and delete it, which is the step everybody skips, and the link cannot outlive the thing it points at just because nobody tidied up.
A click limit does the same job but counts instead of watching the calendar. It suits a capped invitation, a first-come allocation, a download you agreed to share a fixed number of times. It is genuinely useful in one situation people underuse it for: as a tripwire. Set a limit noticeably above what you expect, and if the link stops working you have learned that it travelled much further than you planned — which is worth knowing before it becomes somebody else's discovery.
A password puts an unlock step in front of the destination. The address can then be posted somewhere public while the content behind it stays restricted, which is the shape you want for a client preview, an internal document, or a file shared with one group at an event. Passwords are 4 to 64 characters.
Now the important part, because these features are easy to over-trust. None of them is security. A password gate is a speed bump, not an access control system: it is one shared secret with no accounts behind it, so it cannot tell one person from another, cannot be revoked for a single individual, and cannot survive being forwarded. The moment your password reaches somebody it was not meant for, the link is open, and you will not know.
The other limit matters just as much. All three settings protect the short link, not the destination. If your file is publicly reachable at its original address, anybody who has that address walks straight past every gate you set here. Expiry, limits and passwords control one door; they do not lock the room. Anything genuinely confidential needs restricting where it actually lives.
They also stack, and stacking is where the interesting configurations are. An expiry plus a click limit is a link that closes at whichever boundary arrives first, which is a good default for a time-boxed allocation. A password plus an expiry is a preview that both gates and cleans up after itself.
Two practical habits. First, expiry and limits are settings on the link, not on the destination — so a link that has expired can be reopened by moving the date, and you have not lost the click history in the meantime. Second, tell people the boundary exists. A link that stops working with no explanation reads as broken and generates a message you have to answer; the same link with "closes Friday" written next to it reads as intended. Most of the support cost of these features is created by not mentioning them.