Skip to main content
Protected content is content whose playback is gated behind a short-lived signed streaming URL. When an item is protected, its streaming URL is withheld from feed and content responses until a signed URL is issued. That signed URL carries an expiring token, so playback links can’t be shared or hotlinked indefinitely. Use protected content when you want to limit who can play a video and for how long — for example, subscriber-only or paywalled content.
Protection gates access with an expiring URL (and an optional origin/app allowlist). It is not per-viewer DRM — it does not encrypt the stream or bind playback to a specific device.

How it works

  1. You mark a content item protected at upload or import time (or rely on your organization’s default).
  2. In the feed and content responses, the item’s streamingUrl is withheld (returned as an empty string "") and a protected flag is set to true.
  3. To play the item, a signed streaming URL is issued from the playback-token endpoint. The URL is short-lived and expires at a fixed time.
  4. Before the URL expires, a fresh one is requested so playback is never interrupted.
In the ShortKit SDKs, steps 3 and 4 happen automatically. You only issue signed URLs yourself if you play protected content outside the SDK.

Marking content protected

Set the protected boolean on the Upload or Import request. The field is optional — when you omit it, the item inherits your organization’s default.

Organization default

Your organization has a default playback protected setting that decides whether new content is protected when the protected field is omitted. Set the per-item field to override the default in either direction — true to protect an item in an unprotected-by-default org, or false to leave an item public in a protected-by-default org.
The default is an organization setting. Adjust it in the Admin Portal.

How the feed represents protected content

Protected items appear in the feed like any other content, with two differences:
  • protected is true.
  • streamingUrl is an empty string ("") — the streaming URL is withheld until a signed URL is issued.
Everything else — title, thumbnail, metadata — is present, so protected items render in the feed and browse exactly like public ones.

Playing protected content in the SDK

Protected content plays transparently in the ShortKit SDKs. There is no extra integration on any platform. The SDK detects protected items, issues a signed streaming URL, applies it to the player, and refreshes it before it expires so long-running playback is never interrupted. Protected items are pre-buffered ahead of the swipe, just like public ones, so they play as smoothly as public content.
No additional code. Embed the feed as usual — protected items play automatically.
Signed-URL issuance and refresh are handled entirely inside the SDK. You don’t call the playback-token endpoint, store tokens, or schedule refreshes yourself.

Playing protected content outside the SDK

If you play protected content in a player that isn’t the ShortKit SDK — for example, a custom web player — issue the signed streaming URL yourself with the playback-token endpoint.
The response returns a signed video.url and thumbnail.url, each with an expiresAt timestamp (Unix epoch seconds):
Signed URLs are short-lived. Request a fresh URL before expiresAt to keep playback uninterrupted. See the playback-token endpoint reference for request parameters, the client allowlist, and error codes.

Next steps