September 26, 2026
Web Build

Building a Branded Client Portal Without Webflow Logins

Ben Leonard's business ran on Pixieset, Google Drive and Square. Here's how I pulled all of it onto his own site as one branded client portal, with Supabase and Cloudflare R2 standing in for the logins Webflow took away.

Field Notes
no. 06
$1.35
a month to store about 100 GB of films and photos across seven clients on R2. Downloads cost nothing.
3 days
from generic third-party deliveries spread across different tools to one branded portal on one domain, for Ben and his clients.
0
new apps he had to learn. He runs the whole thing from a page on his own website.

Ben Leonard shoots photos and films for athletes, apparel brands and gyms here in Bellingham under BL Motion Media. It's a real business with real clients, and he's almost never sitting still. He's traveling, shooting or editing.

The whole business ran on other people's platforms. His files went out through Pixieset and Google Drive, and the bill went through Square. It all worked, but every client got a handful of links that looked nothing alike, and none of them looked like him. I wanted to pull all of it onto his own site: one login to watch the film, grab the photos and pay, without adding one more app or one more hour to his week.

There was one catch. Webflow switched off User Accounts on every site on January 29, 2026. They didn't move it to a higher plan. It's just gone, so there's no native login to build on.

((Webflow's own notice says it's leaning on "vetted app partners" instead.)) Pixieset didn't have real logins either. Each gallery gets a password, and that's the whole security model. So whatever I built, the login was on me.

I almost talked myself out of it

My first round of research ended with me deciding not to build a portal at all. The plugins I looked at hid pages with JavaScript, none of them stored video, and most of them wanted a monthly fee on top of his Webflow plan. It looked like a lot of money for a login that still couldn't hold his films.

Then I slept on it and got annoyed at my own answer. "Not a great option" and "no option" are different things, and I'd written it like the second one. So I went back and ranked everything instead of ruling it out: Memberstack, Outseta, Assembly, plain Webflow page passwords, and building it myself.

My requirements were pretty specific. It had to be branded and on his own domain. It had to be cheap. Square had to stay. And he couldn't have to learn another piece of software. None of the client portal apps I checked took Square, and the good ones charged extra to take their own branding off.

The stack

The site stays on Webflow. Logins run on Supabase. Files live in Cloudflare R2. The Pay button is a Square link. All of it sits on two pages of his site: /clients for his clients, and /studio for him.

  • Webflow for the site and both pages.
  • Supabase for accounts, plus one small server function that holds the storage keys so they never touch a browser.
  • Cloudflare R2 for the films and photos.
  • Square for the payment link.
Why R2 and not the cheaper one

I compared R2 with Backblaze B2. B2 is cheaper to store, about $6.95 a terabyte against R2's $15. But R2 charges nothing for downloads, ever, and for someone handing out multi-gig files that matters more than the storage price. At his size the difference was a few dollars a month.

He has roughly 100 GB across seven clients. R2 gives you the first 10 GB free and charges a cent and a half per GB after that, so storage runs him about $1.35 a month.

How I built it

1. Make the bucket private. Nothing in it is public, so nobody can guess a URL and pull a client's footage. I also locked it so only his domain can talk to it.

2. Put a middleman in front of it. A Supabase Edge Function sits between the site and the storage. It checks who's signed in, finds the files that belong to them, and hands back a download link that expires in 12 hours. Forward that link to a friend next week and it won't open.

3. Wall off every client. Supabase's row level security is what actually keeps each client's files separate. Even if someone digs through the page code, the database only returns rows for the account that's signed in. This is the part a JavaScript-only plugin can't give you.

4. Build the client page. /clients is a login, then their project. The main film sits at the top, the full set underneath with the file count and size, and they can filter films from stills, open anything full screen, and download one file or all of it. The balance sits right next to the work with a Pay button that opens Square. If nothing's owed, the button doesn't show up.

5. Build the owner page. This is the one I cared about most. On /studio he adds a client with an email and a generated temporary password he can copy and send, types in the project and the balance, pastes the Square link, and drags the files in. Deleting a file there deletes it from storage too, so he's never paying to keep something nobody can see.

6. Deal with big files. Cloudflare's own web uploader tops out around 315 MB a file, which is nothing for a film. So uploads get cut into 64 MB pieces, three go up at a time, and any piece that fails tries again on its own.

7. Test it with a fake client. I made a demo account and ran the whole visit on desktop and on my phone: log in, play, download, pay. Then I ran it again after every change.

What bit me

Password resets. Supabase's built-in email only sends to people on your own Supabase team. So every reset I tested worked perfectly, because I was on the team, and it would have failed silently for every real client. Hook up your own email sender before anyone real gets an account. I'm setting his up with Resend.

((Supabase says it plainly in its email docs. I just hadn't read that page yet.)) Free projects fall asleep. A free Supabase project pauses after a week with no activity. That's fine for a side project and bad for a portal a client might open once a month. Plan for a keep-alive or the paid tier.

The 90 days. These are delivery copies, not his archive. He keeps the masters on his own drives, and sets come down 90 days after delivery so storage stays around that 100 GB. Right now that's a habit, not something the site does on its own. That's next on my list.

The page that matters

His clients will see the portal a handful of times a year. He's going to be in /studio every week. So that's the page that had to be easy, and if it wasn't, he'd be back on Pixieset by spring.

If you want to see the whole build, the BL Motion case study has the screens. And if you're an athlete or a brand in the Northwest who needs someone behind the camera, go look at Ben's work at blmotion.com.

TLDR
  • Ben's business ran on Pixieset, Google Drive and Square. Now it runs on his own site.
  • Webflow shut off native logins on January 29, 2026, so the login is on you.
  • A private R2 bucket, Supabase logins and one small function that signs expiring links gets you a real portal for a couple dollars a month.
  • The owner side matters more than the client side. If it's a pain to use, he'll stop using it.
  • Test password resets with an email address that isn't yours.

More field notes

Got a project? Bring it.

MESSAGE ME!