Skip to content

Protected Modal

A copy-paste React access screen for a paywall-style preview — content stays mounted and blurred behind a modal prompt. Zero dependencies.

Modal & OverlayCore Blockmodal

Best used for A paywall-style preview where the blurred content itself is part of the pitch.

Content and gate coexist in the DOM at all times — only the modal's visibility changes, which keeps layout shifts to zero on unlock.

// Usage

Minimal setup

<ProtectedModal expectedHash={process.env.NEXT_PUBLIC_KNOCK_HASH}>
  <Dashboard />
</ProtectedModal>
FIG.01Demo code: 4242
Installation

Add this block to your project

Recommended

npx shadcn@latest add @knock-codes/protected-modal

Also installs

  • Knock Codes Core
  • Knock Codes Types
  • useKnockCodes
  • PIN Input
  • Unlock Dialog

These install together as one atomic unit — even a presentational or read-only piece needs the full verification stack (hook, types, core) behind it to actually run.

Files created (10)

  • components/knock-codes/core/hash.ts
  • components/knock-codes/core/verify.ts
  • components/knock-codes/core/session.ts
  • components/knock-codes/core/storage.ts
  • components/knock-codes/react/types.ts
  • components/knock-codes/react/useKnockCodes.ts
  • components/knock-codes/react/KnockCodesContext.tsx
  • components/knock-codes/react/PinInput.tsx
  • components/knock-codes/react/UnlockDialog.tsx
  • components/knock-codes/react/ProtectedModal.tsx
Other ways

GitHub shorthand

npx shadcn@latest add trivedi-vatsal/knock-codes/protected-modal

Copy the files by hand

  1. Open the Code tab in the preview above.
  2. Create each path listed below in your project and paste its contents in.
  3. Do the same for anything listed under “Also installs”, if present.
// Props

API reference

PropTypeDefaultDescription
expectedHashstringSHA-256 hex hash to verify against, for local mode.
verifyVerifyFnCustom async verification function, for server mode.
children *ReactNodeStays mounted, blurred while locked.
labelsKnockCodesLabelsOverrides for every user-facing string.
classNamestringExtra classes on the outer relative container.

Exactly one of expectedHash or verify is required.

Notes

Accessibility

The blurred content is marked aria-hidden and pointer-events-none while locked, so screen readers and keyboard tabbing skip straight past it to the dialog — it's visually present but not reachable, which is the correct behavior for inert background content.

Customization

Best for cases where the protected content's layout should stay stable underneath the prompt — a preview behind a paywall-style modal — rather than collapsing to a bare access-code screen the way Knock Codes does.

Security & Verification

Need a hash? Use the hash generator on Getting Started — computed locally, never sent anywhere.

The honest version

Knock Codes stops casual visitors, search engines, and forwarded links. Local mode does not stop anyone who opens DevTools — the hash ships in your client bundle by design. Server mode (swap one prop) hides the hash from the client; children you already bundled are still in the JavaScript, and a forged session works unless you wire validateSession. A velvet rope, with an optional real lock. Never marketed as more than that.

// Ready-made

Used in these templates

Want the whole screen instead of assembling it yourself? These templates already build on this block.

// Compose with

Blocks that pair well with this one

These combine naturally with this block, whether as a shared shell, a shared session, or a common fallback.