---
title: "Unlock a password-protected page"
method: POST
path: "/v1/public/pages/{publicId}/unlock"
tags: ["Public Page"]
---

# Unlock a password-protected page

`POST /v1/public/pages/{publicId}/unlock`

Verifies the page password and returns an opaque, short-lived unlock token to present in the X-Public-Unlock header. Tightly rate limited per page and client.

## Path parameters

- `publicId` string, required

## Request body

- PublicPageUnlockRequest
  - `password` string

## Response `200`

Unlock token

- PublicPageUnlockResponse
  - `token` string
  - `expiresIn` integer

## Other responses

- `401` — Wrong password or the page is not protected
- `429` — Rate limit exceeded

## Changes

> 8 revisions in range; 1 not diffed.

- **2026-09-06** `24f693bd6f1f` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/timesheet/apis/timesheet-api/changes/v1/public/pages/:publicId/unlock/post.md)

---

[API](https://skmtc.dev/timesheet/apis/timesheet-api.md) · [All operations](https://skmtc.dev/timesheet/apis/timesheet-api/llms.txt) · [OpenAPI document](https://skmtc.dev/timesheet/apis/timesheet-api/revisions/a3d2f44e7345?raw)
