SolutionsSecuritySigned links
Your site decideswho watches.
Sign links to private video with your own key — on your backend, by your own access logic: subscription, payment, a logged-in account. At playback, dodocast only checks the signature.
Access on your terms.
Your own keys
Create a key in the console. The secret is shown once; each key has a label and a last-used time.
A plain JWT
HS256, the key ID in the header, the video code and expiry in the payload. Any JWT library will do.
Valid up to 24 hours
“iat” and “exp” are required and the lifetime is at most a day: a leaked link won’t live long.
One token, one object
A token for one video won’t open another video, playlist or channel. You can only sign your own content.
Revoke within a minute
Links signed with a revoked key stop working within a minute. Several active keys let you rotate without downtime.
Videos, playlists, air
One key signs links to any of your videos, playlists, broadcasts or channels.
The token goes right in the link path.
The player needs nothing else: it requests renditions, segments and the encryption key under the same prefix by itself.
- Keys and code samples in Kotlin, Python, Node.js and PHP are in the console: Settings → Signing keys.
- For a course, the token is issued for the playlist code — it opens that playlist’s lessons.
- If a link returns 403, the console tells you why: someone else’s content, too long a lifetime, a revoked key or a server clock more than 5 minutes ahead.
Plans. Signed links work wherever direct links do — on Pro and Business.
Three steps in the console.
Create a key
Settings → Signing keys: add a label and save the secret right away.
Sign on your backend
Issue tokens to the people allowed to watch. Never send the secret to the browser.
Give the link to the player
The token goes in the link path; the player does the rest.
Your channel is one upload away.
We're opening dodocast to early partners: media, education, events, in-house TV. Tell us what you want to put on air.
or write to hello@dodocast.com