Authenticated Access Control

Private Status Pages

Not every status page should be public. Private status pages give internal teams and enterprise customers visibility without exposing operational details to the world.

When You Need Private Status Pages

Not all status information should be public. Internal services, enterprise customers, and sensitive infrastructure need visibility without public exposure.

Internal Services

Internal APIs, databases, and infrastructure.

Enterprise Customers

Dedicated status for your biggest accounts.

Security-Sensitive

Services you don't want to advertise publicly.

Detailed Views

More granular info than public pages show.

Security Considerations

Private status pages need proper access control:

  • Security through obscurity. An unlisted URL isn't access control — links leak.
  • No brute-force protection. Password forms without rate limiting invite guessing.
  • Static credentials. Password never rotated even when employees leave.
  • Exposing too much. Internal names reveal architecture to attackers.

upti.my Private Status Pages

Straightforward access control that fits every audience:

Password Protection

One shared password, no accounts needed. Verification is rate-limited to block brute-force attempts.

Team Login

Workspace members sign in with their upti.my account.

Per-Page Components

Show only what each audience should see.

Multiple Private Pages

Separate pages for each team or customer, each with its own access control.

Need your identity provider in front of the page? On Enterprise plans we configure SSO for your custom-domain status page via Cloudflare Access — SAML or OIDC with Okta, Microsoft Entra ID, Google, and other providers — so access follows the same rules as the rest of your internal tools.

Getting Started

Set up a private status page for your team or enterprise customers:

  1. 1

    Create Status Page

    Click "New Status Page" in your dashboard. Choose "Private" visibility to require authentication.

  2. 2

    Configure Authentication

    Pick your access mode: password protection with a shared, rate-limited password, or team login for workspace members with upti.my accounts. On Enterprise, our team sets up SSO with your identity provider via Cloudflare Access on your custom domain.

  3. 3

    Add Internal Components

    List your internal services, databases, and infrastructure. Be as detailed as you want since only authorized users will see this.

  4. 4

    Share Access

    Send the password to the right audience, or invite teammates to your workspace. You can rotate the password anytime.

Frequently Asked Questions

Use private status pages for internal teams, enterprise customers who need detailed visibility, or when you monitor services that shouldn't be publicly known. They require authentication to view.

upti.my supports two built-in access modes: password protection, where viewers enter a shared password (no account needed, with rate-limited verification to block brute-force attempts), and team login, where workspace members sign in with their upti.my account. On Enterprise plans, we additionally set up SSO in front of your custom-domain status page via Cloudflare Access, so your users authenticate with your identity provider (SAML or OIDC — Okta, Microsoft Entra ID, Google, and others).

Yes. Create multiple private status pages, each showing only the components relevant to that customer or team. Each has its own access controls.

Absolutely. Private pages often show internal service names, more granular components, and detailed incident information that wouldn't be appropriate for public pages.

Users visit the status page URL and authenticate via your configured method. With password protection, they enter the shared password. With team login, workspace members sign in to their upti.my account. With Enterprise SSO, they are redirected to your identity provider and land on the page once authenticated.

Related Topics

Run reliability as one connected workflow

Detect failures early, route alerts clearly, coordinate incidents, and keep status updates in sync from one system.