For certain websites, you may not want LastPass to store your credentials, automatically log you on, or do something else. To prevent LastPass from taking specific actions for a specific website, you can add a Never URL.
Types of Never URLs
Never URLs can be applied for sites or whole domains, both of which can have a wildcard at the front or at the end.
Note: Using a wildcard character (*) is only supported for URLs and domains. It is mandatory to always specify a top-level domain (TLD) (for example, .com).
All pages
This type of Never URL is used to disable LastPass for all pages under a domain.
Note: An All pages type Never URL without a subdomain will match every path on the domain and every subdomain as well.
This URL
This type of Never URL is used to disable LastPass only on selected sites of a domain.
Add a Never URL
Note: For LastPass Business users, additional Global Never and Only URLs can be set by an admin, and will be labeled as Enterprise in your list in the Admin Console. Domains set by an admin cannot be removed by users. Additionally, if you try to add a site manually for a URL or domain that is already set as a Global Never URL, you will encounter a message indicating that a policy prohibits it.
Note: Never URLs cannot be edited.
- Log in to LastPass and access your vault by doing either of the following:
- In your web browser toolbar, select and select Vault.
- Go to
https://lastpass.com/login/
and log in with your email address and master password.
- Log in to the LastPass for Desktop app.
- If prompted, complete steps for multifactor authentication (if it is enabled for your account).
- Select Advanced options in the left navigation menu.
Note: The features and tools shown in the Advanced Options menu may vary, depending on your account type.
- Select Autofill settings.
- Select the Never URLs tab, then select Add new.
- In the Add Never URL pop-up window set the following:
- In the URL field, enter the URL of the website.
Note: While specifying one exact IP address is supported (for example, https://192.0.2.0/), specifying an IP address range (for example, https://192.0.2.0-192.0.2.255) or CIDR range (for example, https://192.0.2.0/24) is not supported.
Example:
All pages
example.com
www.example.com
This URL
example.com/site
example.com/*
- Choose from the following Action options:
Never show add site prompt
Prevents prompting the notification to add a website.
Never show generate password prompt
Prevents the in-field generate password icon from appearing in the field.
Never show fill forms prompt
This action is being retired. Use Never do anything instead.
Never autofill
Prevents passwords from autofilling on the site.
Never autofill app
This action is being retired. Use Never do anything instead.
Never show infield icons
Prevents the in-field icons from appearing.
Never do anything
Disables LastPass on a website entirely.
You can also pause or disable LastPass on a website from the in-field menu.
- Select Save.
Note: If the site is launched from the LastPass vault or from the LastPass browser extension, it will ignore the Never autofill (as a Never URL) action and the disabled Autofill in Edit password > Advanced settings.
Results: You have added your Never URLs.
Delete a Never URL
- Select Advanced options in the left navigation menu.
- Select Autofill settings.
- Select the Never URLs tab.
- Select in the row of the URL you would like to delete.
- Select Delete to confirm.
Results: You have deleted a Never URL.
Related Articles
Manage Equivalent Domains
Manage URL Rules