Yes, but passwords are typically used as a form of authentication (i.e. something you know) - to prove the identity of the user.
Once a user has authenticated themselves then it is a separate problem to decide what they are authorized to see.
Even really complex keys in links are still a big problem as they are far too easy to pass around - I've seen multiple problems on commercial systems and products where documents didn't require authentication before access and "security" relied on having an obscure key value directly represented in a link.