← All guides

HTTP protection

Restrict access to an HTTP URL

Choose the HTTP control suitable for a demo, pre-production, or application reserved for a known group.

HTTP · CIDR / Password / OIDC6 min
01

Define the exposure level

A webhook endpoint may need to remain public whereas a team preview can be restricted.

02

Choose a control

Use a CIDR list, password, or identity provider depending on your context.

03

Test with a separate session

Verify that an unauthorized visitor receives the expected access behavior.

04

Review requests

Inspector helps distinguish expected integration calls from regular visits.

Need another starting point?

Open documentation