SolutionsSecuritySigned links

Your site decideswho watches.

Sign links to private video with your own key — on your backend, by your own access logic: subscription, payment, a logged-in account. At playback, dodocast only checks the signature.

Signing keys

Access on your terms.

01 / KEYS

Your own keys

Create a key in the console. The secret is shown once; each key has a label and a last-used time.

02 / JWT

A plain JWT

HS256, the key ID in the header, the video code and expiry in the payload. Any JWT library will do.

03 / TTL

Valid up to 24 hours

“iat” and “exp” are required and the lifetime is at most a day: a leaked link won’t live long.

04 / SCOPE

One token, one object

A token for one video won’t open another video, playlist or channel. You can only sign your own content.

05 / REVOKE

Revoke within a minute

Links signed with a revoked key stop working within a minute. Several active keys let you rotate without downtime.

06 / OBJECTS

Videos, playlists, air

One key signs links to any of your videos, playlists, broadcasts or channels.

Token

The token goes right in the link path.

The player needs nothing else: it requests renditions, segments and the encryption key under the same prefix by itself.

  • Keys and code samples in Kotlin, Python, Node.js and PHP are in the console: Settings → Signing keys.
  • For a course, the token is issued for the playlist code — it opens that playlist’s lessons.
  • If a link returns 403, the console tells you why: someone else’s content, too long a lifetime, a revoked key or a server clock more than 5 minutes ahead.

Plans. Signed links work wherever direct links do — on Pro and Business.

How to set it up

Three steps in the console.

01

Create a key

Settings → Signing keys: add a label and save the secret right away.

02

Sign on your backend

Issue tokens to the people allowed to watch. Never send the secret to the browser.

03

Give the link to the player

The token goes in the link path; the player does the rest.

JWTHS256kidKotlinPythonNode.jsPHP
Launching soon

Your channel is one upload away.

We're opening dodocast to early partners: media, education, events, in-house TV. Tell us what you want to put on air.

or write to hello@dodocast.com