Protection gates access with an expiring URL (and an optional origin/app allowlist). It is not per-viewer DRM — it does not encrypt the stream or bind playback to a specific device.
How it works
- You mark a content item protected at upload or import time (or rely on your organization’s default).
- In the feed and content responses, the item’s
streamingUrlis withheld (returned as an empty string"") and aprotectedflag is set totrue. - To play the item, a signed streaming URL is issued from the playback-token endpoint. The URL is short-lived and expires at a fixed time.
- Before the URL expires, a fresh one is requested so playback is never interrupted.
Marking content protected
Set theprotected boolean on the Upload or Import request. The field is optional — when you omit it, the item inherits your organization’s default.
- Upload
- Import
Organization default
Your organization has a default playback protected setting that decides whether new content is protected when theprotected field is omitted. Set the per-item field to override the default in either direction — true to protect an item in an unprotected-by-default org, or false to leave an item public in a protected-by-default org.
The default is an organization setting. Adjust it in the Admin Portal.
How the feed represents protected content
Protected items appear in the feed like any other content, with two differences:protectedistrue.streamingUrlis an empty string ("") — the streaming URL is withheld until a signed URL is issued.
Playing protected content in the SDK
Protected content plays transparently in the ShortKit SDKs. There is no extra integration on any platform. The SDK detects protected items, issues a signed streaming URL, applies it to the player, and refreshes it before it expires so long-running playback is never interrupted. Protected items are pre-buffered ahead of the swipe, just like public ones, so they play as smoothly as public content.- iOS
- Android
- Flutter
- React Native
No additional code. Embed the feed as usual — protected items play automatically.
Signed-URL issuance and refresh are handled entirely inside the SDK. You don’t call the playback-token endpoint, store tokens, or schedule refreshes yourself.
Playing protected content outside the SDK
If you play protected content in a player that isn’t the ShortKit SDK — for example, a custom web player — issue the signed streaming URL yourself with the playback-token endpoint.video.url and thumbnail.url, each with an expiresAt timestamp (Unix epoch seconds):
expiresAt to keep playback uninterrupted. See the playback-token endpoint reference for request parameters, the client allowlist, and error codes.
Next steps
- Create a playback token — issue a signed streaming URL for playback outside the SDK.
- The content object — the
protectedandstreamingUrlfields in full. - Content types — every feed item type and its fields.
- Embedding a feed — set up the SDK feed that plays protected items automatically.