Videos are public by default. Choose private (token) in the video menu to require a JWT for playback. Available from Pro.
Through the API, set visibility: "private" when creating or updating a video, using a read-write API key.
As with uploads, generate a JWT on your server. For playback, use your space’s read-only API key and return only the token to the browser.
// server
const jwt = require("jsonwebtoken");
const token = jwt.sign(
{
sub: "YOUR_VIDEO_EMBED_ID", // space, collection or embed ID
exp: Math.floor(Date.now() / 1000) + 3600, // valid for one hour
},
"YOUR_READ_ONLY_API_KEY" // full API key copied from the dashboard
);
// return `token` to frontend
sub limits access to a space, collection or video. exp is the expiry time in Unix seconds; the example allows one hour. Expiry is optional, but recommended.
Pass the token to the player. Dashboard previews work automatically.
<mave-player embed="YOUR_VIDEO_EMBED_ID" token="YOUR_PLAYBACK_TOKEN"></mave-player>Use the signed domain with the same media path and append ?token=JWT:
https://space-{space_hash}.signed.video-dns.com/{embed_hash}/playlist.m3u8?token=JWTHLS playlists include authorized links to the media files.
Hotlink protection is separate: it configures allowed domains through CORS and does not make videos private.