PLATFORMS Signal 94
Protect production deployments for free on every plan
Vercel now offers deployment protection for all preview and production URLs at no extra cost on Hobby, Pro, and Enterprise plans, eliminating the need for the $150-per-month Advanced Deployment Protection add-on.
Teams can secure internal tools, private dashboards, and pre-launch sites without paying for an additional add-on. The feature can be set as a team default, so every new project automatically protects all deployments. Deployment Protection Exceptions are also free, allowing specific preview domains to stay public while the rest remain protected.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Vercel Authentication now protects every deployment URL, including production domains, on Hobby, Pro, and Enterprise plans at no extra cost.
Previously, protecting all deployments required the $150-per-month Advanced Deployment Protection add-on.
Users can enable the protection via Security → Deployment Protection → All Deployments and set it as a team default.
THE READ
What the cluster adds up to.
Vercel has changed its deployment protection model by making Vercel Authentication available for all preview and production URLs at no extra cost. Previously, the same level of protection required purchasing the Advanced Deployment Protection add-on priced at $150 per month. The update applies across the Hobby, Pro, and Enterprise plans, removing the plan-based restriction. Users can now protect every deployment URL, including production domains, without upgrading to a paid add-on.
Eliminating the $150-per-month add-on reduces the recurring expense for teams that previously relied on it. Deployment Protection Exceptions, which let specific preview domains stay public, are also free on every plan. This means teams can maintain open preview links while keeping the rest of the project protected without extra fees. Overall operational cost for securing internal tooling and pre-launch sites drops to zero for the protection layer.
Protection only works when visitors sign in to Vercel and have access to the project; otherwise the deployment remains inaccessible. To allow public access, administrators must create exceptions for specific preview domains. The feature does not replace other authentication mechanisms; it is limited to Vercel’s own identity system. If exceptions are overused or misconfigured, deployments that should stay protected could become publicly accessible.
Enabling the protection requires navigating to Security in the project sidebar, selecting Deployment Protection, and choosing All Deployments from the dropdown. Teams can set this as the default for new projects, ensuring consistent protection without manual configuration per project. Administrators should review the Deployment Protection documentation to understand how exceptions interact with their workflow. Because the announcement appears in only one source, engineers should verify the behavior in a staging environment before relying on it for production security.
Written by elseif from the cluster below · checked for specifics the sources never containedTHE CLUSTER
↗