playback

Secure video playback

Videos are public by default. Choose private (token) in the video menu to require a JWT for playback. Available from Pro.

Through the API, set visibility: "private" when creating or updating a video, using a read-write API key.

Create a token

As with uploads, generate a JWT on your server. For playback, use your space’s read-only API key and return only the token to the browser.

// server
const jwt = require("jsonwebtoken");

const token = jwt.sign(
  {
    sub: "YOUR_VIDEO_EMBED_ID", // space, collection or embed ID
    exp: Math.floor(Date.now() / 1000) + 3600, // valid for one hour
  },
  "YOUR_READ_ONLY_API_KEY" // full API key copied from the dashboard
);

// return `token` to frontend

sub limits access to a space, collection or video. exp is the expiry time in Unix seconds; the example allows one hour. Expiry is optional, but recommended.

Use the Mave player

Pass the token to the player. Dashboard previews work automatically.

<mave-player embed="YOUR_VIDEO_EMBED_ID" token="YOUR_PLAYBACK_TOKEN"></mave-player>

Use signed URLs with your own player

Use the signed domain with the same media path and append ?token=JWT:

https://space-{space_hash}.signed.video-dns.com/{embed_hash}/playlist.m3u8?token=JWT

HLS playlists include authorized links to the media files.

Hotlink protection is separate: it configures allowed domains through CORS and does not make videos private.