← Notes

Where to put your door code (and where not to)

25 August 2026 · 3 min read

Most hosts share their entry code the same way: it goes in the booking message, or a WhatsApp, or it is printed in the welcome folder, and it stays the same for years.

That is understandable. It is also worth ten minutes of thought, because a door code is not like a WiFi password. A WiFi password gets you the internet. A door code gets you into a building, and if it is paired with a name and a set of dates, it tells someone exactly when that building is occupied — and by whom.

Put those three facts in one place and you have written a fairly complete set of instructions for someone with bad intentions.

The problem with a permanent code

If your keypad code has not changed since you bought the property, then everyone who has ever stayed still has it. So does everyone they forwarded the arrival email to. So does the cleaner who left last spring, and the handyman who did the bathroom.

None of those people are likely to use it. That is not the point. The point is that the number of people holding a working key to your property only ever goes up, and you have no record of who they are.

The same applies to a guidebook link that shows the code to anyone who opens it. Links get forwarded, screenshotted and left in group chats. A link is not a secret.

Three ways to handle it

Change the code between guests. The strongest option, and the most work unless you have a smart lock that can do it for you. If you do have one, this is the answer and everything below is academic.

Put the code behind a check. The guest confirms something only a real booking would know — the surname on the reservation and the arrival date — and the code appears. A forwarded link is then worth nothing on its own.

Release the code on a timer. No typing for the guest at all. The entry details simply appear a set time before check-in and lock again after check-out. Someone opening the link in February sees nothing.

The second and third can be combined, and that combination is where we landed as a default: the guest confirms their booking, and it only works around their dates.

What we do in QuietStay

Every guidebook has an entry-details setting with three choices, and the host picks:

Attempts are rate-limited and logged either way, so a script cannot sit there trying surnames.

We changed the default deliberately. Convenience is a reasonable thing for a host to choose, but it should be a choice someone makes on purpose, not the setting they happened to get.

Three things worth doing today

Do not reuse one code across several properties. It is the single most common mistake in a small portfolio, and it converts one leak into several. If you manage six places and they all open with the same four digits, that is one number away from a bad month.

Do not put the code in the property title, the listing photos, or a public review reply. It happens more than you would think.

Check what your cleaner and maintenance people have. They usually need permanent access, which is fine — but it should be a different code from the guest one, so you can change one without disrupting the other.

And the boring one

Whoever you use — us, a competitor, a spreadsheet — ask them where the code is stored and who can read it. It is a fair question and the answer should be specific.

If a supplier cannot tell you plainly, that is information too.

QuietStay turns your listing into a guest guidebook with a concierge that answers questions like these, so they stop reaching your phone. Start free.